Abdullah «RaQI» · Independent security engineer

I build the systems institutions depend on — and break them before anyone else does.

Authorized red-team. Air-gapped, bank-grade networks. Infrastructure I run on my own hardware. From the threat model to the last pixel — every layer, held to the same standard. I'm Abdullah. They call me RaQI.

14K+
users served
11
buildings networked
300
cameras
8
security layers
2
institutions

What I do

A rare range — every layer to the same standard

  • 01

    Security & red-team

    I find the way in under written scope, then hand you findings you can act on — not a report that rots in a drawer. Web, network, infrastructure.

  • 02

    Infrastructure & networks

    Air-gapped, segmented, bank-grade networks. Zero-trust by default. Self-hosted. One of them runs 14,000 users across 11 buildings.

  • 03

    AI systems

    Models and computer vision on your own metal. No vendor lock-in. Nothing leaves the building.

  • 04

    Web & interfaces

    Fast, accessible, bilingual. Code written by hand. No bloat, no frameworks I don't need.

Selected work

Systems institutions run on

  • Flagship · 2026

    Unified university system

    A full digital transformation for a university college: one Wi-Fi 7 network (78 APs, 11 buildings) replacing 28 fragmented lines, a 300-camera surveillance layer on an air-gapped VLAN, eight layers of bank-grade security, and a self-hosted open-source stack — funded by its own subscription model. Client confidential.

  • Security · 2026

    University web platform — secured

    An authorized security audit, threat assessment, and Arabic-first rebuild for a college's platform. Hardening, performance, visibility. Client confidential.

    • Web Security
    • Audit
    • Hardening
    • RTL
  • Open source

    harden — web security posture auditor

    A defensive CLI that grades any site's HTTP security posture A–F — headers, cookies, information disclosure — with the exact fix for each gap. Dependency-free. The code is public; read it.

  • Open source

    synthetic-data — realistic data, zero real PII

    Generates realistic test and training data without touching real PII. Deterministic by seed, bilingual, dependency-free.

  • My own

    Telegram bot factory

    My own framework for shipping Telegram bots fast — automation and integrations at scale.

    • Automation
    • APIs
    • Python

How I work

Offensive skill, governed by a strict line

Institutions trust me with their networks for one reason beyond skill: discipline.

  • Authorized only

    No offensive testing without written scope from the owner. No exceptions.

  • Confidential

    A client's weaknesses never leave the room.

  • Responsible disclosure

    Findings go to the owner first, with fixes.

  • Defensive intent

    I break things to make them harder to break.

«RaQI» means refined — done to a high standard. That's the bar for everything I build.

I'm Abdullah, known as RaQI. An independent engineer in Iraq. I work the whole stack — the threat model, the cabling, the AI on the server, the type on the page.

My edge isn't one specialty. It's owning every layer at the same level — hardware to interface. Whatever the job, I push for the strongest result.

Contact

Let's build something that holds.

For authorized security work, infrastructure, or collaboration.