Skip to content
HANNIBYTE · INDEPENDENT CONSULTANCY
Backend Engineering · Application Security · AI Integration

Three disciplines.
One consultant.

Backend and AI engineering, with security at the core. I design backends that don't break, audit systems before attackers do, and ship AI features that hold up under scrutiny.

01 / SERVICES

What I do, precisely.

Most consultants pick one lane. I work where backend engineering, security, and AI intersect — because that's where modern systems actually break.

// Security

Application Security

I find what an attacker would find — first. OWASP assessments, secure API design reviews, and penetration testing for systems that can't afford to leak.

  • OWASP Top 10 & SAMM assessments
  • Secure API design (OAuth2 · JWT · RBAC)
  • Penetration testing & threat modeling
  • Compliance audits (GDPR · ISO 27002)
// Backend

Backend Engineering

Production-grade backends built to be maintained — not just shipped. Python-first, with the boring infra that keeps systems running long after launch.

  • FastAPI · Flask · Django
  • Clean architecture & event-driven systems
  • Containerization
  • Production observability (Datadog)
// AI

AI Integration

AI features wired into existing systems — without the prompt-engineering theatre. LLM integrations, RAG pipelines, and tooling that earns a place in production.

  • LLM integrations (Claude · Mistral)
  • AI-powered security tooling
  • RAG pipelines & evaluation
  • AI-augmented dev workflows (MCP · Claude Code)
03 / STACK

Picked for the problem, not the resume.

Tools are choices, not religion. I lean Python-first for backend and security work, with the rest of the stack picked to fit the system's constraints.

The Stack below is what I reach for first — equally happy to inherit a stack or design one.

Backend & APIs
PythonFastAPIFlaskDjangoPydanticSQLAlchemy · AlembicOAuth2 · JWT
Data, Queues & Streaming
PostgreSQLRedisRedpanda · KafkaFastStreamCelery
Infra & DevOps
DockerDatadogAWS (S3 · RDS · CDK)GitHub ActionsCI/CD
Security
OWASP Top 10OWASP SAMMBurp SuitePentestingSAST · DASTGDPR · ISO 27002
AI
Claude APIMistral.aiMCPRAGScikit-learn
Frontend (when needed)
TypeScriptReactNext.jsTailwind
04 / WORKING TOGETHER

How an engagement runs.

Fixed scope. Fixed duration. One measurable outcome. No retainers that quietly become salaries.

  1. 01

    Diagnose, before prescribing.

    A free 60-minute call. I'll walk through your setup with you, hear what your team's wrestling with, and give you a straight answer.

  2. 02

    Scope one measurable outcome.

    Engagements run two weeks to six months with a single defined deliverable: an audit report, a shipped service, a feature integrated. Pricing is fixed up front. Scope changes go through a new contract, not a surprise invoice.

  3. 03

    Build it with your team, not for them.

    Everything ships with documentation, runbooks, threat models, and pairing time along the way. The bar is: the day after I leave, your team can operate, debug, and extend what we built. No black boxes, no me-shaped holes.

  4. 04

    Stay reachable for 90 days.

    For three months after delivery I'm available — questions, post-mortems, the inevitable "what did you mean on line 247." Async support, no hourly billing. New work goes through a fresh engagement.

05 / ABOUT

Built by the same hands.

You brief the engineer who ships the code.

I'm Souhail Harrathi — a backend engineer and security analyst working independently from Brussels. Four years shipping production systems end-to-end for SaaS, agritech, and IoT teams: APIs and infrastructure, observability, security audits, incident response.

Request the full résumé →

06 / PROJECTS

Built. Shipped. Maintained.

A few recent engagements.

  1. Full Stack Engineer · SaaS · Freelance · Dec 2025 → present

    iMapper

    3D-scanning SaaS for kitchen fitters, architects, and interior designers. Profiled and optimised REST APIs (N+1 fixes, versioned caching), consolidated tooling under a single pyproject.toml, hardened Celery with structured logging, drove the OWASP Top 10 / SAMM audit, and built Datadog observability with Slack alerting now used daily to catch regressions.

    • Python
    • Flask
    • Celery
    • PostgreSQL
    • AWS (S3 · RDS · CDK)
    • Datadog
    • Stripe
    • React
    • TypeScript
  2. Python Backend Engineer · Agritech · Feb → Aug 2024 · Paris

    Elzei Consulting

    Backend services for a data platform. Built FastAPI services with event-driven sync via Redpanda + FastStream, applied SOLID / KISS / YAGNI throughout, containerised the stack, and shipped GitLab CI/CD pipelines for a DevOps-driven Agile team.

    • FastAPI
    • SQLAlchemy
    • PostgreSQL
    • Redpanda
    • FastStream
    • Docker
    • GitLab CI
  3. Personal project · Microservices + IoT · 2024 → ongoing

    Tilthwave

    Smart-agriculture platform integrating IoT sensors, real-time streaming, and clean architecture. Three FastAPI services (streamer, API, flow runner), a broker sandbox + sensor mocker for resilience testing, RBAC, and a React/Next.js dashboard for live monitoring of temperature, humidity, and irrigation status.

    • FastAPI
    • Pydantic
    • Redpanda
    • FastStream
    • Docker
    • React
    • Next.js
    • TypeScript
    • Tailwind
  4. Python Backend Engineer · Freelance · Jan 2022 → Jan 2023

    Spotimist

    Migrated a legacy Django application to a scalable Django REST Framework architecture. Mapped legacy data models onto clean REST endpoints, added role-based access control, and hardened API security and performance through careful reviews and refactoring.

    • Django
    • Django REST Framework
    • PostgreSQL
    • GitLab

Want more detail on any of these? Email me and I'll share a fuller breakdown.

— Let's talk —

Got a system
that needs thinking?

contact@hannibyte.com →

Brussels · Belgium · BE 1032.289.638