Primevora Logo
primevora.
PT Primevora Teknologi IndonesiaGedung Jaya Lt. 5, Thamrin, Jakarta Pusat
Consult Principal Engineers→
Field Implementations

High-Stakes Architecture In Production

Real-world institutional deployments delivering uncompromising security and high throughput.

Vulnerability Assessment
Cybersecurity & AuditSEC-VULN-01
Tier-1 Financial EnterpriseRecurring Quarterly Cycle

Vulnerability Assessment

Continuous Vulnerability Assessment & Risk Prioritization
The Challenge

Continuous automated scanner noise floods engineering backlogs with raw, unverified CVE alerts lacking business context, verified exploitability, or clear SLA prioritization.

The Engineering Solution

A recurring quarterly cycle of asset discovery, authenticated vulnerability scanning, and manual false-positive triage, mapping findings to CVSS 4.0 severity rankings and guaranteed patch SLAs.

Technical Architecture Breakdown
1. Asset Discovery & Scope Baseline

Enumerate external and internal assets, shadow IT, and exposed services to establish an authoritative scope baseline.

2. Authenticated Scanning Stack

Credentialed and uncredentialed scans across host nodes, containers, and web applications using industry-standard scanner stacks.

3. Triage & False-Positive Review

Manual offensive validation of every automated scanner finding, eliminating false positives before reaching the risk register.

4. CVSS 4.0 Risk Prioritization

Confirmed findings ranked by CVSS 4.0 severity and business exposure, mapped directly to actionable SLA remediation tiers.

CVSS 4.0— Risk-prioritized remediation queue
Request Technical Blueprint
Penetration Testing & VAPT
Cybersecurity & AuditSEC-PENT-02
Bank BTN / Undisclosed Financial InstitutionCompleted in 6 Weeks

Penetration Testing & VAPT

Securing Digital Trust via Strategic VAPT Realignment
The Challenge

Bank BTN handles highly sensitive financial records and transactions. Sophisticated threat actors target critical API layers, web/mobile app logic, and core banking infrastructure.

The Engineering Solution

Full-Spectrum Hybrid VAPT employing automated and manual offensive audits (Blackbox, Greybox, Whitebox) split into Offensive Red Team exploit testing and Defensive Blue Team SOC threat mitigation.

Technical Architecture Breakdown
1. Web Attack Surface

Scan and exploit target endpoints using OWASP-aligned techniques including authorization bypass, race conditions, and business logic flaws.

2. Mobile Attack Surface

Static and dynamic analysis of application sessions, rooted device local storage checks, cryptographic flaws, and reverse engineering obfuscation.

3. Core Infrastructure

Domain scans, port enumeration, SSL/TLS configuration weaknesses, and outdated services verification on core banking hosts.

4. Compliance & Controls

NIST SP 800-115 and OWASP framework alignment, regulatory validation, executive risk reporting, and re-test verification.

Zero— Critical findings left unremediated
Request Technical Blueprint
High-Volume RADIUS & DNS Optimization
Telecom & InfrastructureRAD-DNS-04
Timor TelecomCompleted in 4 Weeks

High-Volume RADIUS & DNS Optimization

High-Volume RADIUS Optimization and DNS Securing
The Challenge

Scaling high-volume mobile telecom billing systems. Production database suffered lock contention and memory exhaustion under 15,000+ requests per second during peak mobile traffic.

The Engineering Solution

Re-engineered data pipelines with single flock-protected log parsers, fgets() stream reading, batched 500-row inserts, and hardened DNSSEC/ACL controls sustaining 75,000 queries per second.

Technical Architecture Breakdown
1. Single Parser Under flock

Collapsed ten overlapping log parsers into one flock-protected process, eliminating duplicate reads and lock contention.

2. Stream-Based Log Reading

Replaced full-file fread() loads with fgets() streaming, holding pipeline memory usage at 14.8 GB of 94.4 GB RAM without swap exhaustion.

3. Batched Writes & Retention

One INSERT per log line became 500-row batches on a 14-day retention cycle with nightly cleanup, holding MySQL CPU at 1.5%.

4. Secure DNS Redesign

Resilient DNS configurations with DNSSEC, precise ACL controls, and structural mitigation against DDoS amplification up to 75,000 QPS.

42 ms— Response time down from 120ms (75k req/s)
Request Technical Blueprint
Fair Usage Policy (FUP) & Billing Automation
Telecom & InfrastructureRAD-FUP-07
Timor TelecomCompleted in 2 Weeks

Fair Usage Policy (FUP) & Billing Automation

Fair Usage Policy Enforcement on RADIUS Dashboard
The Challenge

Carrier needed automated Fair Usage Policy (FUP) threshold enforcement integrated directly into their live FreeRADIUS AAA stack without interrupting active subscriber data sessions.

The Engineering Solution

Engineered FreeRADIUS python3 policy module evaluating quota balances against each accounting update and issuing RADIUS CoA (Change of Authorization) requests to throttle bandwidth dynamically.

Technical Architecture Breakdown
1. FUP Policy Engine

fup_policy.py running under the FreeRADIUS python3 module, evaluating quota_mb and fup_threshold against each accounting update.

2. Quota Schema & Balances

Three synchronized tables (fup_policy, subscribers, quota_balance) carrying twelve core columns and foreign key constraints.

3. CoA Throttling

coa_trigger.sh issuing CoA-Requests with Cisco-AVPair QuotaThrottled-IN/OUT, moving sessions onto throttled QoS without dropping users.

4. Host-by-Host Verification

Automated dual-host verification pass: zero missing tables, zero missing columns, and FUP_ENABLED validation across all carrier nodes.

Zero Drops— Dynamic QoS switching without disconnecting subscribers
Request Technical Blueprint
Agentic AI: Sprechengate
Agentic AI & Web3AI-AGNT-05
SprechengateDeployment Completed

Agentic AI: Sprechengate

Scaling Global Language Proficiency Predictions via MAPN
The Challenge

IELTS, TOEFL, Goethe, and JLPT exam mock scoring was bottlenecked by manual human evaluation ($25/test) with a 72-hour turnaround time and severe grading inconsistency.

The Engineering Solution

A Multi-Agent Predictor Network (MAPN) that ingests speaking and writing payloads, normalizes international accents, cross-audits rubrics, and generates custom study plans instantly.

Technical Architecture Breakdown
1. Gateway Router

Ingests speaking audio and essay payloads, normalizes regional accents, and routes packages to specialized linguistic agents.

2. Linguistic Evaluators

Anglo-Metrics (fluency & lexical depth), Teutonic-CEFR (German morphology), and Kanji-Syntax (JLPT context) score content.

3. Calibration Auditor

Cross-checks evaluation scores recursively against verified official examiner rubrics to prevent hallucinations.

4. Tailored Study Plans

Growth agents analyze sectional breakdowns to generate customized lesson roadmaps and pinpoint remediation exercises.

72h → 0— Manual grading latency eliminated entirely
Request Technical Blueprint
Yunabite — Agentic Web3 Extension
Agentic AI & Web3AGNT-W3-06
Superteam (Solana Ecosystem Grant)Fully Developed & Deployed

Yunabite — Agentic Web3 Extension

AI Vision Oracle & Solana On-Chain Escrow Protocol
The Challenge

While DePIN protocols successfully tokenize movement, nutrition tracking remains manual and prone to falsification. Users lack verifiable, on-chain HealthFi rewards automation.

The Engineering Solution

Connecting Web2 AI computer-vision scanning to Solana via the Solana Agent Kit. Yunabite autonomous agent parses meal macros and executes on-chain ledger actions, cNFT minting, and escrow settlement.

Technical Architecture Breakdown
1. AI Vision Oracle

Ingests smartphone camera photos to extract macronutrients, calorie densities, and food groups automatically.

2. Solana Agent Kit Integration

Autonomous LLM-driven agent connecting Web2 vision models directly to Solana smart contracts.

3. cNFT Streak Achievements

Mints and airdrops compressed NFTs (cNFTs) on Solana for verified healthy habit streaks with minimal gas fees.

4. Stake-to-Health Escrow

Smart contract locking USDC where the Yunabite Agent acts as an objective arbiter releasing rewards or executing penalty slashes.

Live on Stores— App Store & Google Play production releases
Request Technical Blueprint
ZebTokens — Wholesale LLM API Gateway
Agentic AI & Web3AI-ZEB-08
AI Developers & Enterprise RuntimesLive Production Infrastructure

ZebTokens — Wholesale LLM API Gateway

Unified LLM API at Wholesale Rates ($0.11 per $1 Credit)
The Challenge

Developers and enterprise AI agents face exorbitant retail token markups, fragmented vendor billing (OpenAI, Anthropic, Google, xAI), and rate limits that throttle high-throughput production workloads.

The Engineering Solution

A unified OpenAI-standard proxy gateway routing requests across 34+ flagship models at wholesale rates ($0.11 per $1 credit) with zero monthly subscription commitments, credits that never expire, and sub-millisecond billing.

Technical Architecture Breakdown
1. Wholesale Arbitrage Pricing

Pre-purchased institutional token volumes pass up to ~89%–94% cost savings directly to builders with flexible top-ups starting at $2.75.

2. 34+ Flagship Models on One Key

Access Claude Sonnet 5, GPT-4o, DeepSeek V3, Gemini 2.0, and Grok 2 through a single drop-in OpenAI-compatible endpoint.

3. Enterprise-Grade Telemetry Core

Zero-buffering reverse proxy architecture sustaining 1,248+ req/min with a median p50 latency of 412ms and 99.98% 30-day uptime.

4. Drop-in OpenAI Standard

Swap base_url and api_key in existing codebases with zero refactoring. Native streaming, tool calling, and structured outputs supported.

$0.11— Per $1 USD credit (~89% savings)
Request Technical Blueprint
Confidential Verification

Request Redacted Architectural Case Dossiers

Due to strict bank-grade bilateral non-disclosure agreements, certain proprietary penetration testing reports and high-throughput architectural benchmarks are shared exclusively under bilateral mutual NDA.

Initiate Mutual NDA Scoping →