Dhaka · UTC+6
I build AI systems — and I secure what I build.
I am Engr Mejba Ahmed. I founded xCyberSecurity.io and Ramlit Limited, and I still write the code and run the engagements myself. AI products, automation, and the security work that keeps them standing — one engineer, accountable from the first commit to the retest.
What I build
AI systems, shipped by the engineer who designed them.
The gap between the prototype that impressed everyone and the version that survives real traffic is the job. That is the half I am hired for.
AI development
Products with a model in the loop, built to run in production rather than to demo well.
- AI websites and software
- AI mobile apps
- AI integrations
- AI agents
Vibe coding
AI-assisted delivery at speed, with an engineer reviewing every line that ships.
- Development and MVP
- Troubleshooting and improvements
- Deployments and DevOps
- AI technology consulting
Specialties
Specific tools and workflows, when you already know which one you need.
- AI chatbots
- AI automation
- n8n AI automation
- AI blog automation
What I remove
The ordinary things are what I go after first.
A forgotten admin panel. A dependency two years behind. A backup that was never restored. That is the list I work down before anything exotic.
It is unglamorous work and it is where the risk actually lives.
An attack surface nobody is counting.
Every subdomain, admin panel, API and forgotten staging box that answers on the public internet, listed and assigned an owner. You cannot defend a host you did not know you had.
Access that outlived the person who needed it.
Every account, key and token traced to a human or a service. The ones that should not exist are removed; the rest get scoped down to what they actually do.
A dependency chain untouched since launch.
Your stack read against published advisories and ranked by whether the vulnerable path is reachable from your code — not by severity score alone. A raw scanner report is not a findings list until someone has done that.
A recovery plan that has never been run.
A restore performed, timed, and written down. Until someone has restored it, a backup is a hypothesis.
How to work with me
Four ways in. All of them start with scope in writing.
Nothing begins before you have a document saying what I will build or test, what I will not, and what you hold at the end. Price follows scope, never the other way round.
Build · start here
AI build sprint
A defined feature, integration or MVP, taken from nothing to something running. Two weeks or more, because less than that is not a scope.
- A written spec before any code
- Working software in your repository
- Deployment, environments and rollback
- A handover document you can act on
- Not included: Not an open-ended staff augmentation
- Not included: Design work quoted separately
Secure · start here
Scoped review
The smallest way in. One system you already run, gone through end to end.
- External surface and access review
- Dependency and configuration audit
- Written findings, ranked by exploitability
- A call where I walk you through it
- Not included: Not a full penetration test
- Not included: Remediation work is separate
Time-boxed
Penetration test
A defined target, a defined window, and a written attempt to break it — including a record of what did not work.
- Scope and rules of engagement agreed first
- Findings with reproduction steps
- A retest of your fixes, included
- A summary your board can read
- Not included: Not continuous testing
- Not included: Source-code review only if scoped in
Ongoing
Build & secure retainer
Monthly, for teams shipping often enough that a point-in-time test stops describing the system not long after it is written — and who want the same person on both sides of it.
- Monthly review of what changed
- Architecture advice before you build it
- A named contact when something goes wrong
- One month notice, either way
- Not included: Not a 24/7 monitored SOC
- Not included: Not an on-call rota
Method
How the work actually runs.
This is not a framework diagram. It is the order I do things in, and the commitment attached to each one.
-
Scope
We agree in writing what is in, what is out, and what evidence I may gather. Rules of engagement before tooling.
You approve the scope document before I touch anything.
-
Map
I build the inventory before I test it: hosts, services, versions, entry points, and who owns each one.
The inventory is yours even if you stop the engagement here.
-
Test
Manual work against the map, with tooling where tooling genuinely helps. Every attempt is logged, including the ones that fail.
No destructive testing without a separate written go-ahead.
-
Report
Findings ranked by what they actually reach, each with reproduction steps and a fix — written for the person who has to apply it, not for a filing cabinet.
Nothing reaches the report that I cannot reproduce.
-
Retest
You fix, I check. The engagement is not finished until the fixes are verified against the original findings.
One retest is included. It is not an upsell.
Where the work happens
The proof is three companies and a day job you can open in another tab.
Client work stays private, so there are no logos and no testimonials on this page. What is here instead is three companies I run and one job I hold — all of it live, all of it public.
Founder & CEO
xCyberSecurity.io
The security practice. Testing, hardening, and response for teams that ship software.
www.xcybersecurity.io (opens in a new tab)Founder & CEO
Ramlit Limited
Software engineering and cloud delivery. Where the engineers come from when a job is bigger than one person.
www.ramlit.com (opens in a new tab)Founder & CEO
ColorPark.io
Design agency for brand, product UI, and marketing. The team that makes the things other people have to use.
www.colorpark.io (opens in a new tab)Day job
ElectronicFirst.com FZ LLC
A digital commerce platform. Day job, and the reason production scale is not theoretical to me.
Deputy Head of Software Development · 2017 to presentwww.electronicfirst.com (opens in a new tab)Before you ask
The reasons people hesitate.
These are the questions I actually get asked, answered the way I answer them on a call.
What does it cost?
Scope first, then a number. A scoped review is the smallest commitment, and the one I usually point people at first. If you are asking for more than you need, I will say so before you pay for it.
Will testing take our systems down?
Not without your written permission. Anything destructive is a separate agreement with its own window and its own sign-off. Everything else runs inside agreed rate limits, and I stop the moment you ask me to.
Who sees the findings?
You, and the people you name. I will sign your NDA or bring my own. I do not publish client work and I do not turn engagements into case studies — which is also why there are no client logos on this page.
Do you do the work yourself?
Yes. On larger engagements I bring in engineers from Ramlit Limited, and I stay the technical owner: I review every commit and every finding, and I remain the person you talk to.
What happens after the report?
Your choice. I hand over the findings and step back, or I stay on retainer and help you work through them. Either way the retest is included and the report is yours to circulate internally.
Who owns what you build?
You do. Repository, infrastructure and credentials are transferred at handover, and the scope document says so before any code is written.
Next step
Tell me what you are worried about.
One paragraph is enough. Name the system, and what would hurt most if it broke. If it is a fit I will come back with a scope; if it is not, I will say so and point you somewhere better.
Prefer not to fill in a form?
Message me directly. It reaches me, not a shared inbox.
