Backend systems where the consequences are real. Healthcare, regulated industries, the trust substrate for AI agents. Former 101st Airborne (Purple Heart). MBA.
📍 Rio Rancho, NM · dnakitare.github.io · LinkedIn
Senior Software Engineer at Carefeed. I own the backend integration architecture across 9+ external EHR and healthcare platforms (Epic, PointClickCare, MatrixCare): data exchange, webhook infrastructure, PDF/OCR pipelines for hundreds of facilities, and the identity and auth layer behind a multi-tenant SaaS platform. I inherited a four-year backlog of 27,000+ failed uploads, fixed the root cause, and shipped the cleanup tooling that brought integrity back above 99%. PHP and Laravel are my primary production stack.
Before Carefeed: API and integration infrastructure at legal-tech (nQ Zebraworks) and behavioral-health (Sensible Care) SaaS. Seven years of shipping production backends where a wrong record is a real-world problem, not a failed unit test.
laravel-outbox — Transactional outbox for Laravel. Domain events are persisted atomically with the data that produced them, so a committed write and its event can never disagree.
This is where my side work concentrates: the infrastructure around an LLM, not the model itself. The LLM is the easy part. The interesting work is everything around it.
imara — Runtime governance proxy for the Model Context Protocol. Intercepts every tool call, evaluates it against YAML policy (allow, deny, rate-limit, escalate), and records every decision to a tamper-evident, SHA-256 hash-chained audit log (genesis-anchored, with truncation detection). Published on npm. Composes with Mavryn.
mavryn — MCP gateway. Proxies many upstream MCP servers behind a single endpoint, with tool namespacing, semantic search across tools, policy, and a hash-chained audit trail. Where Imara governs one server's calls, Mavryn routes across many. They are two layers of the same stack.
prior-auth-assistant — A HIPAA-shaped reference architecture for healthcare AI. Postgres row-level security, field-level PHI encryption, HMAC-chained audit, prompt-injection hardening, and magic-byte upload validation wrapped around a Claude OCR and extraction pipeline. 99 tests, CI against SQLite and Postgres.
aether — AI-agent runtime with hardware-level isolation via Firecracker microVMs. A single-region control plane: in-process scheduler (bin-packing, spread, best-fit placement), multi-tenant RBAC, PostgreSQL state, and Kubernetes and Terraform deployment. Beta.
PhotoPare — Privacy-first iOS app built on Apple's Vision framework: duplicate, blur, and screenshot cleanup, fully on-device, no tracking. On the App Store with a one-time unlock.
Former 11B infantryman, U.S. Army 101st Airborne Division (Combat Infantry Badge, Purple Heart, Afghanistan). MBA, Temple University (Fox). BA, Pomona College.
Open to senior backend engineering roles, with staff-level scope at the right fit. I do my best work owning a system end to end in production, where a wrong record costs somebody something. Remote (US), based in New Mexico, working Eastern hours. Reach me at dnakitare@gmail.com or via dnakitare.github.io.
Latest writing: I broke my own audit log, a postmortem of breaking verification of my own tamper-evident audit chain in Imara 0.2.0, and the migration design it still owes.




