An AI-native GRC platform. On top, a practitioner reference across twelve frameworks. Underneath, an engine that grades an AI system against ISO 42001, NIST AI RMF and India DPDP. Governance reviews are usually prose, so two readers get two answers. This one reproduces: same input, same verdict, every run. And it reports worked controls apart from empty skeletons, because a heading with nothing behind it is not a control.
A buyer sends a security questionnaire and someone loses a week answering it from memory. Constat AI answers from the company's approved evidence instead. It publishes a trust page so the questions a buyer can answer for themselves never reach a person, drafts what is left with a citation to a versioned, approved source, and where nothing supports an answer it refuses, names the gap, and routes it to whoever owns it. The refusing is the part that matters.
Status
Live
Built with
Python · deterministic gates that run after the model
The site and its gates, four views. The demo runs on a sample evidence pack and says so on screen.
constat.dhruvshahi.com
03Marketplace
ArtistNextDoor
A live marketplace where event organisers book performing artists: singers, DJs, dancers, magicians, comedians. Artists build profiles and get paid, with real payment, refund and policy flows behind the bookings. I shipped work across its frontend and backend.
A pet wellness app for India, built with a co-founder. A rules engine scores symptoms on the device first, then the model adds context. The local verdict is computed before the model runs and travels with the response, so the app can always say what it decided without the model. Anything not real is labelled on the screen.
Status
Web app live · Android app in internal testing on Play
Pravaha means flow, and it reads two: the water India pumps and the air it breathes. Groundwater from CGWB records, air from Central Pollution Control Board stations. Every figure carries its source and its age, and when a feed cannot be verified the layer refuses to draw rather than show you a number that looks current. Carbon accounting sits alongside, sourced line by line. Turning that accounting into credits is a direction I am researching, not something built.
The built site, five views. The India panel is the concept instrument and says so on screen.
pravaha · live air
That is what I have built.This is where I have worked.
02
Experience
Four years on both sides of the same problem. Long enough in the room where the rules get enforced to know which ones survive contact with a real system, and close enough to the build to make the enforcing itself the software.
Senior GRC Engineer at Workstreet
·India
A compliance and trust engineering firm in the US. I build the systems that do the compliance work, rather than doing it by hand and calling that a process.
AI governance
Evidence automation
Multi agent review
Prompt engineering
Control mapping
Evidence lifecycle
21 to 7
days to map one framework onto another
4 days to 5 minutes
to author a set of custom tests
70%
of security questionnaire answers drafted for review
196
controls in the framework I assess against
320
assessment objectives worked at full depth
Built a generator that maps assessment objectives onto client specific tests, so the expert reviews the output instead of typing it.
Designed review boards where separate agents check, cross check and challenge every verdict before it reaches a human gate.
Analysed 161 candidate tests across 73 assessment objectives to find which ones genuinely stood alone.
Caught a weekly vulnerability count moving from 371 to 953 before the external assessor raised it.
Cyber Security Consultant at Ernst and Young
·Bengaluru
Three years of assessments and remediation across enterprise estates. Promoted out of the associate grade after 14 months.
Third party risk management
Vendor risk
Gap assessments
Cloud security
Application security
30+
enterprise applications assessed before deployment
50+
critical cloud misconfigurations closed
20+
third party risk assessments
95%
of security defects closed on time
14
months to promotion from associate
Reviewed authentication, encryption and authorisation on applications before they shipped, with source code review alongside the testing teams.
Found and closed exposed storage, permissive access policies, unencrypted databases and missing multi factor authentication across two clouds.
Secured container workloads and put security checks inside the infrastructure pipelines rather than after them.
Delivered the PCI DSS v3.2.1 to v4.0 transition assessment and its remediation roadmap.
Certifications and education
ISO 27001:2022 Lead AuditorISO
PCI DSS v4.0 Lead ImplementerPCI SSC
AZ-900 Azure FundamentalsMicrosoft
ITIL v4Axelos
B.Tech, Computer Science EngineeringVellore Institute of Technology, 2018 to 2022, CGPA 8.08 of 10
03
Skills
Six rooms I work in. The governance is certified, assessed or graded by the engine above. The rest came from shipping my own products, where there is nobody to hand the writing, the design, the ad account or the automation to, so you learn them or the thing does not launch.
AI, day to dayThe tools the work actually runs on
Claude
ChatGPT
Gemini
Perplexity
Antigravity
Wispr Flow
Cursor
Granola
Sybil
GovernanceAssessed, implemented or graded by the engine
27KISO 27001
PCIPCI DSS
42KISO 42001
RMFNIST AI RMF
DPDPIndia DPDP
171SP 800-171
CMMCCMMC L2
SOC2SOC 2
CSFNIST CSF
27017ISO 27017
HIPAAHIPAA
FEDFedRAMP
GDPRGDPR
EngineeringWhat the products are built with
TypeScript
React
Next.js
Vite
Node.js
Expo
Playwright
AutomationWork that runs without me
n8n
Make
Claude routines
Marketing and growthDemand, not just delivery
Meta ads
Google Ads
LEADLead generation
PMMProduct marketing
SMMSocial media
DMDigital marketing
Content and designMaking the thing look like something
Higgsfield
KIEKIE AI API
Canva
Adobe
Figma
Notion
04
About
I came up through cyber consulting and moved toward the code. Now I build the instruments that regulated work usually does by hand.
Now
Senior engineer, US compliance platforms
Building and evaluating systems where the rules are the product.
Before
Cyber consulting, EY
Assessments and remediation across enterprise estates.
Client work stays confidential. Everything shown on this page is personal work.
Certifications
ISO 27001:2022 Lead Auditor · PCI DSS v4.0 Lead Implementer · AZ-900
Base
Bengaluru and Delhi NCR
Focus
GRC engineering and applied AI for regulated products
05
Building next
Everything above this line is finished and open. Everything below it is not, and says so. It is here because the useful conversations tend to start before a thing is built rather than after.
FinOS
in progress
A personal finance operating system: it values a portfolio against real fund and stock prices daily, and a scheduled analyst writes cited insight over the result.
A SaaS product's obligations move underneath it. Control Room works out which security and regulatory requirements apply as they change, shows the risk that opens up when they do, and names the controls that answer it. One screen, instead of five spreadsheets and a call.
A content engine that runs on a schedule and learns. It reads the niche, watches what the competition is doing, generates the work, scores it, and keeps whatever actually performed. Built to launch one product, then found to work for any of them.
A munim in the pocket of someone who owns a few trucks. Say the trip out loud, in Hindi or in English, and it keeps the books: what the load paid, what it cost to run, and who has still not settled. The chasing happens over WhatsApp, because that is where the money conversation already is.
Asli means genuine. India has the players and no dependable way for one of them to prove it: trials are run by whoever says they are running them, and nothing a player does is recorded anywhere they own. So the organiser is verified before the listing goes up, the registration is built for minors, and the attendance certificate can still be checked years later. Talent should not need a contact to be seen.