Case Studies

Flagship Projects

Systems I designed and shipped end to end: self-hosted AI platforms, agents that run real operations, verification tooling and data infrastructure. Each case study carries its architecture flow.

Built a self-hosted AI stack that routes, logs, and heals without cloud dependency.

Sovereign AI Platforms

#01

Overview

To ensure operational continuity in air-gapped environments, I architected a sovereign multi-model AI platform. I designed a GitOps control plane using Ansible to orchestrate fleet configuration and automated registry synchronization. The solution included a centralized gateway routing 55 distinct models across a hosted inference provider and local failover nodes. To address agentic risks, I engineered five middleware engines for edge isolation and memory management. Additionally, I implemented a decentralized log ingestion layer using DHTs and magnet links for immutable audit trails. This approach established a single source of truth for infrastructure state while mitigating execution risks in isolated deployments.

AnsibleGitOpsLiteLLMDistributed Hash TablesPythonDockerPostgreSQLrclone

Highlights

  1. Gateway routing 55 distinct models
  2. 5 middleware engines for agentic security
  3. Decentralized logging via DHT architecture

Self-hosted agentic workflows drive supply chain and communication ops with deterministic outcomes.

Agentic Automation

#02

Overview

I architected a sovereign agentic automation engine to replace manual, brittle workflows in enterprise operations. The system deploys a 15-agent swarm on Nomad, governed by a ratified handshake protocol that enforces lease-board governance across diverse LLMs. This ensures fleet-wide integrity: no agent acts without verified coordination, and no unbacked programs execute. I consolidated 65+ unversioned scripts into a managed, secret-scoured repository to support this infrastructure. One pipeline ingests unstructured communication, extracts technical signals, and triggers structured briefs in under 30 seconds. Another automates triage across multiple inboxes. The architecture extends to spatial reasoning, fusing LiDAR point-cloud data with LLM context windows for environmental navigation. All components are self-hosted, auditable, and operate without external cloud dependencies.

NomadCrewAIPythonGitOpsObsidianLLM OrchestrationLiDAR Processinggit-crypt

Highlights

  1. Orchestrated 15-agent swarm on Nomad with ratified handshake protocol
  2. Consolidated 65+ scripts into managed repository with secret hygiene
  3. Spatially-aware orchestration fusing LiDAR data with LLM context

Architected a production-grade demo eliminating supply chain distortion across five distributors using Temporal sagas.

Data Systems

#03

Overview

I designed an autonomous continuous replenishment system to demonstrate how probabilistic forecasting and deterministic optimization eliminate the bullwhip effect. The architecture combines Temporal.io sagas for durable orchestration, TFT-based demand forecasting, and OR-Tools MILP for safety-stock allocation across a five-distributor vendor-managed inventory network. I delivered an interactive demo guide with persona-specific dashboards and allocation logic, giving stakeholders hands-on evidence that autonomous replenishment could run without human intervention. The system proved that ML predictions, when coupled with rigorous optimization and failure-aware workflow orchestration, could stabilize upstream orders despite downstream volatility.

Temporal.ioOR-ToolsTFTPythonAzureDockerFastAPI

Highlights

  1. 5-distributor VMI network with bullwhip elimination
  2. Temporal sagas for durable replenishment workflows
  3. OR-Tools MILP allocation with TFT forecasting

Eliminating false positives in security audits through logic-gated deterministic classification.

Security Engineering Methodology

#04

Overview

B2B technical due diligence demanded auditable evidence linking code vulnerabilities to business risk exposure, yet conventional SAST tools generated unactionable noise. I architected a deterministic pipeline that gates LLM synthesis behind strict boolean preconditions—only confirmed findings advance to risk scoring. The system runs production-hardened on ARM64, integrating secret scanning with compliance-grade reporting. By binding every output to verifiable logic paths, the design eliminates false-positive fatigue while preserving full traceability for regulatory review.

PythonDockerSASTLLM OrchestrationCompliance AutomationARM64

Highlights

  1. Deployed production-hardened auditor on ARM64 infrastructure
  2. Logic-gated LLM synthesis with deterministic preconditions
  3. Integrated SAST and secret scanning for compliance reporting

A single knowledge base serving both human researchers and autonomous AI agents.

Agentic Automation

#05

Overview

Knowledge bases fail when humans and AI agents compete for the same interface. I architected AgentWiki as a multi-tenant SaaS with strict RBAC, where humans interact through a React 19 UI while agents authenticate via an MCP server and CLI. Deployed on Cloudflare Workers for edge-native latency, the platform treats agents as first-class users with scoped programmatic access. The architecture separates concerns: the React layer optimizes for human cognition, the MCP layer for machine parsing. Live deployment validates the dual-interface model—one codebase, two interaction modes, zero interface conflict.

TypeScriptReact 19Cloudflare WorkersMCPRBACMulti-tenancyEdge Functions

Highlights

  1. Deployed live multi-tenant SaaS with RBAC and agent CLI access
  2. Built on React 19 and Cloudflare Workers for edge performance
  3. MCP server enables programmatic agent workflows alongside human UI

Self-hosted infrastructure matching cloud latency for industrial process variable snapshots.

Sovereign AI Platforms

#06

Overview

Industrial control systems generate 50,000 live process variables that engineers must freeze, analyze, and restore. Existing tools introduced unacceptable latency and data sovereignty risks. I architected a distributed FastAPI backend that interfaces with EPICS control networks, parallelizing snapshot creation across workers and caching hot paths in Redis. WebSocket streaming pushes state updates to operators in real time, while a persistent job queue ensures reliable state management. The system now captures 40,000+ variable states in under five seconds without leaving the facility network, demonstrating that rigorously engineered self-hosted infrastructure can handle massive throughput without vendor lock-in.

FastAPIPostgreSQLRedisWebSocketsEPICSDistributed Systems

Highlights

  1. <5s snapshot creation for 40K+ process variables
  2. 50K PVs handled via WebSocket streaming
  3. Redis caching with persistent job queues

Automated coverage-guided fuzzing pipeline for native bindings

Rigor & Verification

#07

Overview

I engineered a reproducible fuzzing pipeline to systematically stress native addon interfaces. The workflow utilized AddressSanitizer (ASAN) to monitor execution and track coverage metrics. I designed specialized harnesses that generated targeted inputs to explore complex state transitions. The system automated the triage process by isolating unique execution paths and generating reproducible test cases. This approach established a robust framework for continuous validation, ensuring that the method could reliably surface edge cases without manual intervention. The resulting infrastructure provided a scalable template for integrating dynamic analysis into the development lifecycle.

AddressSanitizerlibFuzzerNode.js N-APIC++PythonLLVM

Highlights

  1. Coverage-guided fuzzing harnesses for native interfaces
  2. Automated triage workflow with reproducible test cases
  3. Continuous validation pipeline for dynamic analysis

Simulating balanced ternary arithmetic to reduce circuit complexity and engineering rigorous protocol toolkits.

Research

#08

Overview

I investigated whether non-binary computation could reduce the transistor count and energy cost of AI inference. I built Python simulations of balanced ternary logic, implementing a half-adder model to document theoretical efficiency bounds for specialized accelerator designs. In parallel, I developed a protocol toolkit in Zig featuring canonical transaction encoding, signing-hash generation, and signature verification. This toolkit achieved live RPC conformance and deterministic serialization for a declared protocol subset, validated through five quality gates including cross-implementation parity. Both efforts reinforce a focus on verifiable, low-level systems that apply formal rigor to next-generation computing architectures.

PythonZigBalanced Ternary LogicCircuit SimulationDeterministic SerializationCanonical EncodingFormal Methods

Highlights

  1. Balanced ternary half-adder simulation with documented LLM efficiency gains
  2. Zig protocol toolkit: deterministic serialization and live RPC conformance
  3. Five quality gates including cross-implementation parity and testnet verification

Open-source orchestration framework unifying multi-vendor network estates under single policy governance.

Sovereign AI Platforms

#09

Overview

Enterprise networks fragment into silos when vendor tools do not interoperate. I engineered PDSNO to resolve this: a Python-based orchestration framework that abstracts disparate vendor APIs into a unified policy and audit plane. The architecture treats each vendor domain as a stateful endpoint, normalizing telemetry streams to a central control layer. I implemented policy reconciliation engines and distributed audit log aggregation, delivering a self-hosted platform that achieves Phase 6D completion. The system is validated by 62 passing unit tests, ensuring consistent policy propagation and queryable audit trails across heterogeneous infrastructure without vendor lock-in.

Pythonsoftware-defined-networkingnetwork-orchestrationpolicy-engineaudit-loggingdistributed-systems

Highlights

  1. Phase 6D completion with 62 passing unit tests
  2. Vendor-agnostic control layer with normalized telemetry
  3. Unified policy and audit plane for multi-vendor environments

Proactive desktop recall without cloud exposure, built on local OCR and vector search.

Agentic Automation

#10

Overview

I needed a mechanism to recall screen context without exposing sensitive data to external APIs. I engineered a KDE-based assistant that captures screen activity and processes it through a rigorous local pipeline. The solution performs optical character recognition and applies immediate redaction based on exclusion lists before any data is indexed. The scrubbed context is then routed to a self-hosted gateway and stored in a local vector store. This architecture ensures that while I can query my activity history for intelligent retrieval, raw sensitive information never leaves the host machine, guaranteeing strict data sovereignty.

PythonKDE/PlasmaOCRQdrantRAGPrivacy Engineering

Highlights

  1. Local OCR and redaction pipeline with configurable exclusion lists
  2. Self-hosted Qdrant gateway for zero-cloud vector search
  3. Active deployment since 2026-09 with 85% completion confidence

Built pipelines that extract structured signals from public market data to rank opportunities.

Data Systems

#11

Overview

I needed a system to cut through noise in public work marketplaces—endless postings with opaque pricing. I built a scraper that structures unstructured listings, extracts rate indicators, and ranks leads by expected hourly value. A daily digest surfaces the top opportunities without manual review. Separately, I deployed a read-only analytics dashboard for prediction markets, visualizing liquidity patterns to support disciplined decision-making. Both systems enforce execution discipline: data flows in, signals generate, but human judgment remains the final gate.

PythonPostgreSQLRedisJavaScriptRechartscronweb-scraping

Highlights

  1. Daily digest ranks leads by computed hourly rate
  2. Read-only dashboard visualizes prediction market liquidity
  3. Pipeline runs on cron with zero manual intervention

Production-grade self-hosted services with hardware-integrated automation and zero manual certificate management.

Sovereign AI Platforms

#12

Overview

To eliminate reliance on external schedulers and optimize media workflows, I engineered a self-hosted productivity stack. I deployed a Cal.com instance backed by PostgreSQL, securing traffic with automated TLS termination via Caddy on a virtual machine. Concurrently, I migrated a media streaming stack to a Proxmox LXC environment for enhanced resource isolation. To bridge physical and digital operations, I configured an 18-key macro pad using OpenDeck. This device now manages fleet status and media controls directly, integrating custom plugins updated via GitOps to display live system statistics.

Docker ComposeCaddyPostgreSQLProxmox LXCOpenDeckGitOps

Highlights

  1. Deployed Cal.com with automated TLS via Caddy reverse proxy
  2. Media workload migrated to LXC with verified uptime continuity
  3. 18-key OpenDeck profile with 3 context layers and GitOps-driven configs

Architected a self-hosted data pipeline to ingest, index, and route enterprise-scale vectors without external dependencies.

Data Systems

#13

Overview

To support product features without surrendering data sovereignty, I designed a self-hosted pipeline for large-scale semantic search. I engineered an ETL workflow that ingested over one million rows from a national open-data corpus, transforming and indexing the data into a local Qdrant cluster. To operationalize this asset, I implemented synchronized vector routing logic that optimized data paths for retrieval across the unified product suite. This infrastructure establishes a sovereign foundation for RAG workflows, ensuring that all indexing and inference operations remain within a controlled environment.

PythonQdrantVector EmbeddingsETL PipelineData Synchronization

Highlights

  1. Indexed 1M+ rows into a self-hosted Qdrant cluster
  2. Synchronized vector routing for unified product suite
  3. Zero external API dependencies for retrieval path

Architected a TypeScript plugin integrating self-hosted payment orchestration into Medusa v2, unifying 50+ payment methods under a single interface.

Data Systems

#14

Overview

E-commerce architectures often face vendor lock-in and fragmented integration logic when managing multiple payment providers. I designed and implemented a TypeScript plugin that integrates a self-hosted payment orchestrator into the Medusa v2 framework. The solution abstracts the complexity of disparate gateway APIs, providing a standardized interface for the full transaction lifecycle: authorization, capture, refunds, and webhook synchronization. By enforcing idempotency and state reconciliation within the plugin, the architecture ensures data sovereignty and rigorous consistency for financial operations. Published as an npm package, this module enables production deployments to scale checkout capabilities across global networks without modifying core application logic.

TypeScriptMedusa.js v2Payment OrchestrationWebhook SynchronizationIdempotency ControlAPI Integration

Highlights

  1. Published npm package integrating self-hosted orchestration with Medusa v2
  2. Unifies 50+ payment methods through a single standardized interface
  3. Full lifecycle support: authorization, capture, refunds, and webhook sync

Sovereign Terminal

Sovereign Ecosystem

Sovereign research hub for industrial-academic inquiry into autonomous AI governance and swarm frameworks.

Sovereign Sync

Active Link

"Broadcasting from the Sovereign Systems Lab."

© 2026 Abhishek Khaparde • Sovereign AI Ecosystems

Non-Commercial Research
These projects represent my independent, non-commercial academic research at IIT Kanpur. These are distinct from my professional employment. All technical architectures discussed are academic design frameworks and do not represent the proprietary intellectual property, commercial methodologies, or official positions of my employer or any past professional affiliations.