Skip to content
View Hiprax's full-sized avatar

Block or report Hiprax

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Hiprax/README.md
Hiprax: a full-stack development, DevOps and security studio building scalable, secure web applications. Available for new work.

Hiprax

A full-stack, DevOps & security studio  ·  AI products and the infrastructure that keeps them running  ·  7 open-source packages

Website npm packages Email

Divider

~/about

Hiprax started long before invoices and contracts. It began with three friends wired on curiosity, breaking systems, rebuilding them, and refusing to accept a surface-level understanding of anything.

That curiosity turned into skill, and the skill into discipline. The mindset never changed.

We build web applications end to end — database and cloud infrastructure through to the last pixel of the interface. Across 10+ years of engineering (the studio itself has been trading since 2020) we've shipped under real pressure, the kind where "almost good" gets someone paged at 4am. No shortcuts. No hand-holding frameworks. No blind dependency on AI. Just engineers who understand what they build, top to bottom.

Every client we've worked with has chosen to work with us again. Not by chance.

~/how-we-work

How a brief becomes production at Hiprax: five stages — Brief (an engineer reads it, not a salesperson), Architect (schema, threat model and the deploy shape before any feature code), Build (small PRs, tests that fail for real reasons, CI green or it waits), Harden (OWASP pass, authorization review, secret audit, rate limits, headers), and Ship (one compose stack, one port, TLS on the host).

Two things about that pipeline are worth saying out loud.

The threat model comes before the feature code. Retrofitting auth and authorization onto a shipped product is how most breaches start. We'd rather spend a day on it in week one than a month on it after someone finds the hole.

Everything ships as one self-contained stack. One compose file, one root .env, one port bound to the loopback interface, and an Nginx on the host holding the certificate. It runs identically on a laptop and on a bare VPS, which means "works on my machine" stops being a sentence anyone says.

~/what-we-do

Service What we deliver
Web development Full-stack apps on the MERN stack and Next.js: real-time features, REST and GraphQL APIs, and database design that scales.
DevOps & cloud CI/CD pipelines, Docker and Kubernetes, AWS, GCP and Azure, infrastructure as code, and hardened Linux servers.
Security Security audits, penetration testing, secure code review, auth and encryption, and compliance guidance.
Technical consulting Architecture reviews, technology selection, performance optimization, and team mentoring.

~/team

Three senior engineers. No juniors to babysit, no account manager to route around — you talk to the person writing the code.

Sajad Khanmirzaei
Founder & CEO

Full-stack · DevOps
@Sajadlance
Saeed Mirzade
Full-stack & AI Engineer

MERN · React Native
@saeedmirzade
Ashkan Gholizade
Back-end & Security

APIs · Hardening
@AshkanGholizadeh

~/work

A few of the products we've shipped. Most are under NDA, so these are the shapes rather than the client names.

Project What it does Stack
AI Print-on-Demand Studio Generate original artwork from a prompt, refine it in a full in-browser design editor, then order it on real products. MERN · Fabric.js · Socket.io · GenAI
AI Political Transparency Aggregates political news and fact-checks live speech in real time, with a conversational AI for civic questions. MERN · WebSocket / SSE · AI
Omnichannel AI Sales A subscription CRM where businesses train custom AI agents that run SMS and voice outreach and close deals on their own. MERN · Stripe · AI
Conversational AI Ordering Human-like voice AI that answers restaurant calls and takes orders through natural conversation. Python · TensorFlow · Transformers · FastAPI
Financial Fraud Prevention Real-time verification so people can tell a genuine bank contact from an impersonation scam. Node · React · REST
Vending Ops Platform Fleet operations end to end: inventory, dispatch, route optimization, per-machine financial reporting, subscription billing. MERN · Stripe
The full list — the 23 we can name

AI Company Showcase & Marketing Website · AI Market Intelligence Suite · AI Print-on-Demand Design Studio · AI-Powered Investment Signal Platform · AI-Powered Political Transparency Platform · Advanced HTTP Parameter Pollution Shield · Conversational AI Ordering System · Dynamic Audio Visualization Engine · Enterprise Admin Dashboard UI Kit · Enterprise-Grade Encryption Library · Financial Fraud Prevention Platform · Full-Stack Image Processing & Delivery System · Full-Stack Ticketing & Support Management System · Government Document Automation Suite · Omnichannel AI Sales Engagement Platform · Peer-to-Peer Storage Marketplace · Production-Grade Structured Logging Toolkit for Node.js · React SEO Management Hook · Real Estate Auction Intelligence System · Real-Time Penny Auction Platform · Social Engagement Rewards Platform · Stereoscopic 3D Streaming System · Vending Machine Operations Platform

Five of them are open source; you can read every line further down. The rest live at hiprax.com.

~/stack

Layer Tools
Frontend React · TypeScript · Next.js · Tailwind · Three.js
Backend Node · Express · Python · FastAPI · Django
Data MongoDB · Redis · PostgreSQL · MySQL · Elasticsearch
Infra Linux · Docker · Kubernetes · Nginx · AWS · Cloudflare · GitHub Actions
Applied AI RAG · agents · OpenAI · LangChain · Hugging Face · PyTorch · Whisper / voice
Security OWASP · OAuth / JWT · AES-GCM · Argon2id · TLS · pentesting

Vue, Svelte, Angular, Flask, PHP, and Laravel are in the toolbox too, when a project already lives there.

~/open-source

We build for developers as well as clients. Seven packages on npm — four under the @hiprax scope, three unscoped — all MIT, around 11,600 downloads in the last year. @hiprax/crypto and @hiprax/logger publish straight from CI through npm's OIDC trusted publishing, so no token ever sits on a laptop.

Good engineering should strengthen the ecosystem instead of extracting from it. These are free, and they stay free.

Package What it gives you
@hiprax/crypto
npm version downloads per year source
AES-256-GCM authenticated encryption with Argon2id key derivation, file streaming, and constant-time comparison. Zero runtime dependencies.
hppx
npm version downloads per year source
HTTP Parameter Pollution shield for Express: blocks prototype pollution, null-byte injection, and DoS vectors with nested whitelists.
pixel-serve-server
npm version downloads per year source
Sharp-powered image middleware: on-the-fly AVIF and WebP conversion, resizing, strict path validation, smart caching.
pixel-serve-client
npm version downloads per year source
The React half of Pixel Serve: multi-format srcset, lazy loading, a skeleton loader, SSR-safe fallbacks.
@hiprax/use-seo
npm version downloads per year source
One React hook for titles, Open Graph, Twitter Cards, hreflang, and JSON-LD. SSR-safe and fully tested.
@hiprax/logger
npm version downloads per year source
Winston-based structured logging with daily rotation, verified IANA timezones, and an Express middleware that masks secrets automatically.
@hiprax/errors
npm version downloads per year source
Modular error handling for Express: structured, typed error classes and consistent API responses.

Also on the shelf: h-vault — a zero-knowledge, self-hostable password manager and encrypted notebook. AES-256-GCM happens in the browser; the server only ever sees ciphertext.

~/clients

"The best full-stack team I have ever met in my working career, and even better individuals. Thank you Hiprax for your work and amazing results for us."

Ovidio Gomez
"It is hard to find devs who actually care about the backend security as much as the front-end design. Hiprax is the real deal. They spotted a vulnerability we did not even know we had and patched it without making a fuss."

Elena Rodriguez
"We were in a huge bind after our previous developer left us hanging right before launch. Hiprax stepped in and cleaned up the code in three days. They literally saved our launch week."

Marcus Thorne

Those are all three we've published, names as given. We don't dress them up with stock photos or invented job titles.

~/work-with-us

It can be imagined? It can be built.
It's complex? Even better.
It's impossible? Let's make it happen.

Have something complex, security-critical, or a little impossible in mind? That's our favourite kind of brief.

How to start. Email dev@hiprax.com with three things: the problem, the stack you're on, and the deadline you're working against.

Who reads it. An engineer, not a salesperson. You'll get an honest read on how we'd build it and whether we're the right team for it. If we're not, we'll tell you, and usually point you at who is.

Currently available for new work.

dev@hiprax.com See the full portfolio at hiprax.com

Divider

Three hand-written SVGs and a few live npm badges. No stats cards, no streak counters, no snake.
Every animation is CSS and respects prefers-reduced-motion.
Tell us what you're building: dev@hiprax.com

Popular repositories Loading

  1. pixel-serve-client pixel-serve-client Public

    The Pixel Serve component is a powerful and flexible React component designed to handle dynamic image rendering with support for multiple formats, lazy loading, and additional customization options.

    TypeScript 2

  2. pixel-serve-server pixel-serve-server Public

    A robust Node.js utility for handling and processing images. This package provides features like resizing, format conversion and etc.

    TypeScript 2

  3. errors errors Public

    A modular error handling solution for Express.js applications.

    TypeScript 2

  4. crypto crypto Public

    High-security encryption/decryption library using AES-256-GCM and Argon2id

    TypeScript 2

  5. hppx hppx Public

    Superior HTTP Parameter Pollution protection middleware with modern TypeScript, robust sanitizer, and extensive tests.

    TypeScript 2

  6. logger logger Public

    Fully typed Winston-based logger with rotation, timezone support, and Express middleware

    TypeScript 2