FRACTIONAL PRINCIPAL ARCHITECT · every claim on this page is real

I make software production-grade - including software built with AI.

For founders, CTOs, and engineering leaders shipping B2B SaaS, payments, or AI-assisted products.

AI made shipping code cheap. It didn't make shipping products safe. I'm the architect teams bring in a few days a week so that velocity doesn't turn into breaches, outages, and cloud bills.

The problem

// why fractional, why now

Your team ships faster than ever. Your security, architecture, and operational discipline don't.

The failures land later - as incidents, licensing problems, and invoices. My job is to make sure they don't land at all.

Ways to work with me

// remote · worldwide · Israel-based
ongoing · 1-3 days/week

Fractional principal architect

Your senior-most technical voice, part-time.

  • Architecture & technical decision ownership
  • Security posture and tenant-isolation review
  • Payment flows and money-path design
  • Cloud cost and infrastructure strategy
  • Written decision log - institutional memory as a deliverable

Monthly retainer, sized by days/week

Fits: teams of 2-20 engineers shipping fast without a principal-level architect on staff.

Relevant evidence: security flaws stopped before launch · cloud spend cut 84% →
fixed scope · 1-2 weeks

Production-readiness review

A structured audit of what you're about to ship.

  • Authorization boundaries & tenant isolation
  • Money paths: idempotency, refunds, webhooks
  • Deploy reversibility & rollback planning
  • Secret handling & supply-chain exposure
  • Findings ranked by blast radius - with fixes, not just a report

Fixed price, quoted on repo count & scope

Fits: pre-launch, pre-fundraise, or post-incident.

Relevant evidence: a payment release stopped before every refund could fail →
fixed scope · 1 week

AI-assisted engineering audit

How your team actually uses AI coding tools - and what that's exposing.

  • Secret handling in agent sessions & logs
  • Supply-chain policy: pinning, scripts, provenance
  • Agent guardrails & permission boundaries
  • Review discipline that verifies instead of trusts
  • A written, machine-followable policy your team keeps

Fixed price, one week, one deliverable

Fits: any team where AI writes a meaningful share of the code.

Relevant evidence: AI-agent policy created after a real credential leak →
  1. 01
    Start with the failure mode

    A 30-minute risk review gives us the product, the release, and the decision that matters most.

  2. 02
    Scope a decision, not a vague retainer

    Choose the smallest engagement that resolves the highest-risk unknown.

  3. 03
    Leave with usable proof

    Prioritized findings, a decision log, and a clear next move stay with your team.

Evidence, not adjectives

// selected engineering outcomes, 2014 - today
Security · multi-tenant SaaS

Found a cross-tenant data-access flaw in review - before launch, not after a breach

Caught in a pre-implementation review, not an incident. Stopped feature work, audited the entire platform for the same class of flaw, closed the process gap that allowed it - then fixed the code.

closed pre-launch · full-platform audit shipped
Cloud · cost
-84%

Cut AWS spend without collapsing the architecture

~$10K/year saved at pilot scale. Wrote the non-negotiable invariants first: no monolith collapse, every service boundary preserved, and a documented one-weekend path back to Kubernetes.

production cutover 2026-06 · running since
Payments · reliability
100%

Blocked my own release over a defect that would have failed every refund

A live end-to-end test showed the provider contract differed from what the docs implied. Declared NO-GO on my own evidence, fixed it, and proved exactly-once refund semantics under replay before shipping.

replay-tested on live provider · shipped
AI-era engineering · security

Wrote the AI-agent security rulebook - after a real incident, not in theory

An AI coding agent leaked credentials into a session log. I wrote a machine-followable secret-handling and supply-chain policy, propagated it into every agent session, and wired an automated leak check into the deploy pipeline.

enforced in CI · held since
AI-era engineering · quality
46

Real defects fixed in one pass - every AI finding hand-verified first

Six review agents fanned out across a seven-repo feature. 48 raw candidates, each confirmed by direct code read; one killed as a false positive. 46 fixes across 11 reviewed PRs, deployed together.

48 → 46 confirmed · 1 false positive killed
Payments · compliance

Restructured payments so the company never holds other people's money

Designed out a money-transmitter licensing exposure across IL/EU/US before writing code - restaurant as merchant of record, platform fee separate. Read the provider's full API documentation page by page; one buried error code invalidated the refund-retry design.

licensing exposure designed out
Legacy modernization · team leadership
+60%

Modernized a national telecom's legacy mobile systems

Led a six-developer team migrating legacy Java applications to Kotlin with modern architecture patterns - improving application efficiency by up to 60% across products used on Android, iOS, and smart-TV platforms.

delivered as team lead · national telecom
Automation · growth engineering

Built automation that multiplied client business exposure

Designed Python automation and business-growth systems for consulting clients - increasing profile exposure and interactions by up to 800%, built on the same reliability discipline as everything else here.

delivered via consulting practice

Track record

// three ways I've shipped software for a decade
venture · founder & architect

Brasserio

A restaurant reservation & operations SaaS: ten Python microservices on AWS, event-driven workflows, payments, GitOps delivery, and staff apps from a single Kotlin Multiplatform codebase - designed, built, and operated by one architect.

2app stores, live
3platforms, 1 codebase
7languages, incl. RTL
leadership · mobile team lead

National telecom products

Led a six-developer team delivering consumer mobile and smart-TV applications for a national telecom - owning delivery lifecycle, technical reviews, mentoring, and architecture modernization across Kotlin, Swift, and Java stacks.

6developers led
+60%efficiency gain
5yras lead
consulting · since 2014

DevYouUp practice

Backend, mobile, web, cloud, and automation systems delivered across industries - selecting the stack for the product, not the trend, and recruiting and mentoring remote teams when delivery demanded it.

national telecomfintechhealth techEdTechAdTechcybersecurityB2B / SaaSrestaurant tech

Experience & training

// the full timeline lives on LinkedIn

Roles

2024 - now
Founder & Software Architect - BrasserioCloud-native restaurant-tech SaaS, solo-built and operated
2020-2025
Mobile Team Lead - EntrypointSix-developer team, national-telecom mobile & smart-TV products
2017-2020
Senior Applications Developer - EntrypointKotlin/Swift/Java, STB development with international partners
2015-2017
Full-Stack Developer - EasySaleB2B sales & BI apps integrated with SAP Business One
2014 - now
Founder - DevYouUpArchitecture & development services across 8 industries

Training & certification

cert.
Software Architecture - DevOps ExpertsCertified software architect
cert.
Mobile & Web Development - John BryceProfessional development programs
B.A.
Psychology - Ramat Gan UniversityUseful daily: mentoring, incident calm, and reading the room
lang.
Hebrew & EnglishBilingual proficiency - RTL products shipped

Questions teams ask before release

// specific answers for specific risks
Does AI-generated code still need a production-readiness review?

Yes. AI can accelerate implementation, but it does not prove authorization boundaries, payment behaviour, rollback safety, or secret handling in production.

How do you check a payments release before it goes live?

Test against the live provider contract, exercise retries and refunds, and prove the intended idempotency and rollback behaviour before release.

What does a fractional principal architect do?

Owns architecture and high-risk technical decisions a few days a week, with a written decision log that stays with the team.

What should I bring to a 30-minute risk review?

The product, the release you are considering, the team size, and the decision or failure mode that concerns you most.

NEXT STEP

Tell me what you're shipping. I'll tell you what will break.

A 30-minute call is enough to know whether I can help. If I can't, I'll say so - the same way I declare NO-GO on my own releases.

Two quick details help me point you to the right starting point.

I will reply within one business day.

Book a 30-minute risk review → oraneventzur@devyouup.com LinkedIn ↗

Prefer async? Email works. I respond within one business day, Israel time (GMT+3).