Fractional CTO for difficult technical work.

I work with founders and technology leaders across AU and APAC.

I help teams get stalled products shipped, make sound architecture decisions, and prepare for technical diligence. I also help teams work out where AI is useful, where ordinary software is better, and how to test what they put into production.

A production review in practice

Review pull request #849 — atlas-platform
/reviewhttps://github.com/atlas-platform/pull/849
Thought for 1s
Code Review — PR #849

Fetching the diff to classify the tier.

Trusted by

HarvestStack
Mist
PayChoice
Balmer Agency
10x Banking
KPMG
JP Morgan
Deutsche Bank
Morgan Stanley
Citi
Credit Suisse
Merrill Lynch
CBA
NAB
Westpac
Prudential
London Stock Exchange
Lloyds Bank
HarvestStack
Mist
PayChoice
Balmer Agency
10x Banking
KPMG
JP Morgan
Deutsche Bank
Morgan Stanley
Citi
Credit Suisse
Merrill Lynch
CBA
NAB
Westpac
Prudential
London Stock Exchange
Lloyds Bank

When does a fractional CTO make sense?

Your platform has been in build for months and hasn't shipped. You suspect the problem isn't the team, but you're not sure what it is.

Your architecture made sense at MVP. Now it's slowing everything down, and you're not sure whether to fix it or start over.

You're heading into a raise and your technical story needs to be airtight. You can't afford for diligence to surface things you didn't know about.

Something went wrong. Security incident, data issue, compliance gap. You need someone who's been here before.

You need senior technical leadership and hands-on capability, but a full-time CTO isn't the right move yet.

Your team is writing code faster with AI tools, but review, testing, and security have not kept pace. You need a delivery process designed for the way the team now works.

Thread in #founders

What I find when I look

Technical Assessment — Vela

Code, infrastructure, product, team & compliance · July 2026

13 areas assessed

150+ findings

3 Critical
6 High
4 Medium
CriticalDatabase security
CriticalTest coverage
CriticalInfrastructure
HighFeature completeness
HighSecurity integration
HighTeam & knowledge risk
HighPayment processing
HighEngineering documentation
HighDependency vulnerabilities
MediumCost at scale
MediumCompliance endpoints
MediumPrivacy enforcement
MediumRegulatory readiness
Not production-readySignificant gap between designed and integrated protections

How I can help.

AI is useful when it solves the right problem.

LLMs are good at working with unstructured information, classifying text, and handling tasks that are too expensive to do by hand. They are a poor substitute for ordinary code when the rules are known and the answer needs to be predictable.

Getting a demo working is usually straightforward. Production needs clear success criteria, representative evals, user feedback, and deterministic checks around the parts that cannot be trusted to behave the same way every time.

Pull requests11
7 Open·1,247 Closed
LabelReviewsSort
feat(HAR-1247): order consolidation for multi-supplier deliveriesauto-merge-eligible
#1247·opened just now· 3
feat(HAR-1246): bulk invoice export with configurable date rangesneeds-review
#1246·opened 12s ago· 14
fix(HAR-1245): correct pagination offset on order history viewauto-merge-eligible
#1245·opened 34s ago· 1
feat(HAR-1244): multi-currency pricing for international suppliersneeds-review
#1244·opened 1m ago· 27
chore(deps): bump @testing-library/react from 14.2 to 15.0auto-merge-eligible
#1243·opened 2m ago· 2
feat(HAR-1242): weekly delivery digest email for buyersneeds-review
#1242·opened 3m ago· 8
fix(HAR-1241): resolve race condition in checkout on low stockauto-merge-eligible
#1241·opened 4m ago· 5

Review according to risk

A small, familiar change should move quickly. Authentication, payments, and data access need more scrutiny. Automated review can sort changes by risk and give human reviewers the context they need.

Run security continuously

Deterministic scanners catch known problems well. LLM review can look for less obvious issues across authentication, data flow, and permissions. Findings go into the team's normal issue tracker and are checked by a person before work begins.

Write the rules down

Coding conventions, architecture decisions, and security requirements belong in the repository. People and coding agents can then work from the same rules, while CI checks the parts that can be tested deterministically.

Automated security review
Web · Mobile · API · Cloud · Infra
34 agents · 4 tracks
Queued3
SEC-44

API rate limiting & abuse prevention

APIcritical
api-security-agent
SEC-43

Third-party dependency vulnerabilities

Infra
dependency-scanner
SEC-42

Mobile data storage & encryption

Mobile
mobile-security-agent
In Progress3
SEC-4111/14

Authentication & session management

APIcritical
api-security-agent
SEC-406/9

Cloud storage permissions audit

Cloudcritical
cloud-security-agent
SEC-395/5

Browser security headers & CSP

Web
web-security-agent
In Review2
SEC-385/5

Secrets & credential management

Infra
secrets-scanner
SEC-3712/12

User data exposure on endpoints

APIcritical
api-security-agent
Done3
SEC-36

Network access control policies

Cloud
cloud-security-agent
SEC-35

Frontend authentication flows

Web
web-security-agent
SEC-34

Infrastructure access & IAM review

Infracritical
infra-security-agent

In practice

A production bug affecting 40% of users went from confirmed finding to a merge-ready fix in under an hour.

AI helped investigate the bug and implement the fix. Tests, architecture review, security checks, and CI still ran. The speed came from making the review loop efficient, not from skipping it.

fix(HAR-1247): app visibility broken for subset of users on shared accountsReady to merge
auto-merge-eligible
All checks have passed · 4 skipped, 9 successful
Branch Name / check-branch-namein 2s
Security Scan / CodeQLin 52s
CodeRabbit / code-reviewin 3m
Architecture Review / arch-reviewin 6m
E2E API Tests / api-suitein 3m 12s
Playwright E2E · shard 1/4in 4m 08s
Playwright E2E · shard 2/4in 3m 55s
Playwright E2E · shard 3/4in 4m 21s
Playwright E2E · shard 4/4in 3m 47s
Merge pull request

Outcomes

I joined a fintech startup one week before an investor presentation, audited the platform, and helped the founder explain the technical plan. The company secured its investment.

For a farm-to-plate startup, I built the first product and formed the engineering team. That team now supports 300% more customers and 500% more suppliers without growing its headcount.

I took over a SaaS migration that had been stalled for three years, got it delivered, and prepared the engineering manager to lead the function before handing over to a permanent CTO.

For a $60M Banking-as-a-Service programme, I mobilised a team of 20 in 12 weeks and delivered a live platform covering core banking, BPAY, NPP, Direct Entry, and electronic KYC.

I rebuilt a global SaaS platform used across five countries, designed its ISO 27001 and GDPR-aligned architecture, and delivered a Royal Commission data system that processed more than 100,000 customer records.

I audited two pre-launch startups and found more than 150 issues across product, infrastructure, security, and code. The findings gave both founders the evidence they needed to change development partners.

What clients say.

"We had a week to an investor presentation and needed a seasoned CTO in the room. Shariq got across our entire stack in hours and ran the session. We got funded. Three years on, he's still the first person I call when things get complicated."

John Crutchley
John Crutchley
Founder & CEO, Mist Financial

"Shariq genuinely thinks in terms of business cost and outcomes and not just engineering. Every decision is made with delivery efficiency in mind. That mindset is vanishingly rare."

Sascha Rust
Sascha Rust
Co-Founder & Director, HarvestStack

"We'd been stuck on the same migration for three years. Shariq got it moving, grew the engineering manager into a leader, and handed off to a permanent CTO. Clean exit."

Tanith Buda
Tanith Buda
CEO, PayChoice

"When I thought I had lost everything, Shariq provided the strategic advice and direction I needed to move forward and deliver complex platform builds. Highly recommend."

Sarah Balmer
Sarah Balmer
Owner, Balmer Agency

About Shariq

Shariq Khwaja

I've been building and fixing software systems for 25 years. Starting on Unix, C, and shell scripts, working through trading systems, core banking, enterprise SaaS, and now startup and scaleup technology.

The thread through all of it: I'm most useful when the stakes are high and the situation is messy. Stalled delivery, fragile architecture, teams that need restructuring, platforms that should have launched months ago. That's where I do my best work.

Over the last three years, that's become the core of what I do: coming in when things are broken, finding what's actually wrong, fixing it, and leaving behind something better than I found.

Recently, much of that work has involved helping teams use AI in software delivery. I start with the simplest useful change, measure whether it helps, and keep tests, security checks, and human review around anything probabilistic.

Based in Melbourne. Working across AU and APAC.

If that sounds like what you need, let's talk.

Let's talk.

We talk for 30 minutes. No pitch. If there's a fit, I'll tell you what I'd do.

Currently taking one new engagementAU / APACMelbourne