Skip to content
View jatansg's full-sized avatar
πŸ‘‹
πŸ‘‹

Block or report jatansg

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
jatansg/README.md

Javine Tan (@jatansg) | Strategic CS, Enterprise Accounts & Product Architecture Portfolio

Welcome to my technical product-build portfolio.

I build enterprise-grade prototypes that connect customer success, revenue workflows, compliance governance, data privacy, cloud architecture, and B2B/B2B2C platform design across ASEAN.

These projects are live product architecture prototypes built to demonstrate how commercial strategy, regulated workflows, user experience, and technical systems can come together in working MVPs and product architecture prototypes.

🌐 m0-0n.com β€” Privacy-First B2B2C Optical Commerce & ASEAN Governance

A live B2B2C optical commerce MVP combining eyewear e-commerce, family prescription profile management, saved prescription checkout, optometrist-assisted verification, non-diagnostic vision screening, consent controls, audit trails, anonymised distributor demand forecasting, and ASEAN governance tracking across 10 markets.

Built to explore how optical retail can evolve into a trusted, data-conscious, and compliance-ready digital ecosystem.

Live demo: https://m0-0n.com

πŸ›‘οΈ m0-0n.com β€” Regional Compliance & Data Residency Architecture

This architectural blueprint outlines the data segregation and compliance boundaries enforced to safely isolate protected health information (PHI) and personal records across regional ASEAN territories.

Operational Domain Architecture & Security Treatment Compliance Objective Enforced
Personal Identity Data (PII) Isolated within encrypted, region-specific cloud datastores. Encryption keys remain segregated from global analytics tiers. Enforces strict Singapore PDPA and cross-border geographic sovereignty rules.
Prescription Records (PHI) Hashed at rest using military-grade AES-256 protocols with individual cryptographic seed salts. Guarantees robust protection over sensitive healthcare records.
Regional Analytics Loop Aggregated, stripped of unique identifiers, and converted into statistical demand metrics before border transit. Prevents unauthorized international transmission of identifiable data.
Consent & Audit Logging Tamper-proof, append-only ledger entries record every consent activation and doctor-verification step. Provides complete, audit-ready forensic visibility for regulatory inquiries.

πŸ” Cryptographic Isolation & Tokenization Model

To ensure complete boundary separation, the platform decouples business transactions from sensitive user identities:

  • Pseudonymized Data Vaults: User identities are automatically replaced with randomized UUID tracking keys at the database ingestion tier.
  • Asymmetric Security Management: Cryptographic operations occur strictly within automated Hardware Security Modules (HSMs), preventing internal administrative teams or infrastructure observers from viewing raw unencrypted records.

⚑ LovTurbo Labs β€” High-Performance Cloud Architecture & Pipeline Optimisation Prototype

An enterprise-grade cloud architecture prototype exploring real-time synchronisation pipelines, caching distribution networks, latency reduction workflows, and operational performance visibility.

Built to demonstrate how infrastructure thinking, performance optimisation, and product UX can be translated into a working technical sandbox.

Live demo: https://lovturbo.com

⚑ lovturbo.com β€” System Architecture & Latency Optimization Pipeline

This section outlines the high-performance data engineering and content distribution blueprint engineered to eliminate synchronization bottlenecks and reduce end-to-end user latency.

πŸ”€ Data Flow Pipeline

Client ──► Anycast CDN ──► Intelligent Cache ──► Ingestion Engine ──► Datastore

πŸ”„ Data Synchronization Mechanics

  • Event-Driven Ingestion: Employs a non-blocking asynchronous event loop structure to process incoming payloads without queue blocking, maintaining operational consistency under high-concurrency loads.
  • Optimized Payload Serialization: Utilizes compact binary formatting models over standard text serialization to reduce transport packet volumes and accelerate wire-speed network transmission.

🌐 Distributed Edge Network & Caching Strategy

  • Geographic Proximity Routing: Leverages an Anycast-routed Content Delivery Network (CDN) framework to terminate TCP connections at local regional edge nodes, stripping out propagation delays across ASEAN markets.
  • Multi-Tiered Cache Invalidation: Employs an aggressive edge-caching model with deterministic, event-based cache purging to serve high-volume static components instantaneously while preserving database resources.

πŸ“‰ Latency Reduction Workflows

  • Micro-Batch Stream Pipeline: Ingested telemetry strings run through structured micro-batch processing workers before database commit steps, flattening expensive IO storage bottlenecks.
  • Connection Multiplexing Layer: Stabilizes communication channels between internal network dependencies by reusing persistent, long-lived sockets, removing the recurrent latency penalties of cryptographic connection handshakes.

πŸ›‘οΈ AIMM Dev β€” AI Model Aggregator & Multi-LLM Orchestration Sandbox

An AI model aggregation prototype exploring multi-LLM routing, prompt orchestration, payload handling, token usage visibility, fallback logic, and secure API gateway behaviours.

Built to demonstrate applied AI workflow design and enterprise orchestration patterns.

Live demo: https://aimm.dev/

πŸ” ChainRecover β€” Security Workflow & Digital Asset Recovery Simulation

A cybersecurity workflow prototype simulating digital asset recovery journeys, verification milestones, case intake, evidence tracking, and mobile-responsive recovery-status flows.

Built as a security infrastructure case study to explore trust, auditability, user guidance, and structured incident-response UX.

Live demo: https://orecover.com

🍜 SGFoodCourt β€” Singapore Coffee Shop Multi-Vendor Management Prototype

A Singapore-focused foodcourt and coffee shop operations prototype built to simulate multi-vendor stall management, customer ordering journeys, menu visibility, and merchant-side workflow coordination.

The build explores how traditional neighbourhood F&B environments can be translated into a digital operating layer, supporting stall discovery, product/menu browsing, vendor participation, order flow visibility, and basic management logic.

Built as a product architecture sandbox to demonstrate local-market UX thinking, multi-tenant platform design, and operational workflow mapping for Singapore’s foodcourt and coffee shop ecosystem.

Live demo: https://blingfen.com/

πŸ“± dylmn.shop β€” Singapore Lucky Mobile Numbers Storefront Prototype

A Singapore-focused digital storefront prototype for lucky, memorable, and premium-style mobile numbers.

The build explores niche e-commerce flows around number discovery, product listing, customer enquiry, and culturally relevant buying behaviour linked to auspicious or easy-to-remember mobile numbers.

Built as a product architecture sandbox to demonstrate local-market commerce thinking, lightweight marketplace design, product listing UX, and conversion-focused customer journey mapping.

Live demo: https://dylmn.shop/

πŸ’Ό founddao.com β€” Compensation Intelligence & Salary Estimation Prototype

A compensation intelligence and salary estimation prototype built to explore how professionals can benchmark role value, compensation expectations, seniority positioning, and market-fit signals through a clean self-service experience.

The build simulates a LinkedIn-style salary discovery workflow, combining role-based inputs, market benchmarking concepts, professional positioning, and data-informed career decision support.

Built as a product architecture sandbox to demonstrate HRTech product thinking, career intelligence UX, compensation benchmarking flows, and marketplace-style professional data experiences.

Live demo: https://founddao.com/

πŸƒβ€β™€οΈ Run0n β€” AI-Powered Running Performance Commerce & Distributor Intelligence Prototype

A mobile-first B2B2C running performance commerce prototype combining treadmill bio-burn calibration, multi-profile household tracking, nutrition and recovery insights, simulated voice authentication, simulated eKYC, consent controls, partner-safe analytics, product recommendations, and distributor demand forecasting.

The build explores how consumer training behaviour can become consent-approved aggregate demand intelligence for gyms, wellness retailers, wholesalers, and ASEAN distributors, while keeping identity, privacy, and profile-level consent central to the experience.

Built as a product architecture sandbox to demonstrate AI-native workflow design, privacy-aware B2B2C commerce thinking, subscription packaging, and regional distributor planning logic.

Live demo: https://run0n.com/

πŸƒβ€β™€οΈ run0n.com β€” Product-Led Growth (PLG) & Wholesale Intelligence Workflow

This section details the telemetry aggregation frameworks and architectural boundaries engineered to transform real-time consumer training habits into scalable B2B distributor planning metrics.

πŸ”€ Telemetry Flow Pipeline

Biometric Edge ──► Calibration Engine ──► Aggregation Tier ──► Demand Intelligence Core

πŸ“Š Telemetry Aggregation Framework

  • De-Identified Data Pipeline: Strips out sensitive user biomarkers and localized biometric strings directly at the edge layer, transmitting only normalized, structural fitness data packets to the cloud processing core.
  • Deterministic Calibration Analysis: Feeds multi-profile activity data logs through a localized aggregation index to isolate true demand habits from transient user anomalies.

πŸ’Ό B2B Monetization & Distributor Intelligence Loop

  • Predictive Wholesale Planning: Compiles anonymous user engagement habits into unified market signals, allowing wholesale networks to anticipate inventory cycles without revealing identity parameters.
  • Consent-Driven Value Mapping: Restricts corporate access boundaries to aggregate operational performance indexes, ensuring raw consumer identities remain secure behind localized authorization walls.

πŸ—οΈ Cloud Infrastructure & Orchestration Overview

This repository includes a production-ready, sanitized cloud architecture blueprint designed with a security-first approach to infrastructure management. By separating environment definitions and utilizing immutable infrastructure practices, the setup eliminates common compliance and security configuration risks.

πŸ›‘οΈ Infrastructure as Code (IaC) with Terraform

Located in the /terraform directory, the configuration builds an isolated network footprint on AWS using industry-standard security principles:

  • Network Isolation: provisions a dedicated Amazon VPC (10.0.0.0/16) to decouple core application workloads from default networks.
  • Tiered Subnets: maps out structured public subnets (10.0.1.0/24) inside strict availability zones to enforce clean routing boundaries.
  • Minimalist Security Posture: enforces a strict AWS Security Group that blocks non-essential protocol access, allowing entry only via encrypted HTTPS (Port 443) while dropping high-risk open-port configurations.

☸️ Container Orchestration with Kubernetes

Located in the /k8s directory, the manifest defines an immutable pod specification designed to maintain highly resilient runtime application instances:

  • Resource Governance: sets explicit CPU/Memory request and limit metrics (256Mi/250m minimums up to 512Mi/500m maximums) to prevent container resource exhaustion and stabilize cluster node footprints.
  • Strict Runtime Security: locks down container privilege boundaries natively within the Kubernetes engine:
    • Disables root privileges (runAsNonRoot: true with a designated non-uid-0 user account).
    • Mounting structures run on a static, immutable filesystem layer (readOnlyRootFilesystem: true).
    • Explicitly drops system runtime execution elevations (allowPrivilegeEscalation: false).

πŸ—ΊοΈ System Network Architecture Description

This section details the micro-segmentation, traffic flow topology, and perimeter security layers implemented across the production environment footprint.

                  [ INTERNET ]
                       β”‚  
                       β–Ό (Port 443 | HTTPS)
           β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
           β”‚  AWS Security Group   β”‚ (Denies non-443/ingress traffic)
           β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                       β”‚
                       β–Ό (Forwarded to Cluster Boundary)
           β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
           β”‚    Public Subnet      β”‚ (10.0.1.0/24 inside AWS VPC)
           β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚
           β”‚ β”‚ Kubernetes Pod    β”‚ β”‚ (Privilege-escalation disabled)
           β”‚ β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ β”‚
           β”‚ β”‚ β”‚ Nginx Core    β”‚ β”‚ β”‚ (Runs as Non-Root UID 10001)
           β”‚ β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚ β”‚
           β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚
           β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

1. Perimeter Defensive Layer & Ingress Boundary

Traffic ingress follows a strict, zero-trust perimeter model:

  • Protocol Restraints: The stateless external network boundary terminates all incoming consumer connections directly at the AWS Security Group interface, dropping any traffic not explicitly mapped to TCP Port 443 (HTTPS).
  • Distributed DoS Mitigation: By dropping raw arbitrary handshakes, the firewall layer insulates internal container engines from high-volume Layer 4 connection floods.

2. Network Topology & VPC Segmentation

Workloads execute within a micro-segmented network fabric topology:

  • Address Spacing: Infrastructure workloads reside in a software-defined Virtual Private Cloud (VPC) spanning a /16 CIDR block (10.0.0.0/16), creating 65,536 private IP addresses to eliminate multi-tenant network bleeding.
  • Zonal Subnetting: Virtual network routing paths isolate edge computing layers inside a public subnet wrapper (10.0.1.0/24), ensuring deterministic routing tables and strict segregation from internal database or storage grids.

3. Intra-Pod Runtime Security & Workload Containment

Once a payload traverses the edge routing tier, secure compute boundaries protect execution frames inside the Kubernetes pod:

  • Filesystem Inmutability: The target web application container leverages an ephemeral Linux kernel configuration where the root system partition is mounted as read-only (readOnlyRootFilesystem: true). Malicious payloads cannot execute automated file writes or runtime configuration injections to persist within the environment.
  • UID Context Isolation: The execution daemon explicitly drops the default root administrative namespace context, running under an unprivileged user identity space (runAsUser: 10001). Even in a theoretical container breakout event, the underlying host kernel remains safe from privilege escalation attacks.

Repository Visibility Note

Some source repositories are kept private where projects involve security workflows, compliance logic, data governance, or commercial product architecture. Live demos and case-study summaries are provided for portfolio review.

Pinned Loading

  1. EnGr_AI_MA EnGr_AI_MA Public

    Javine Tan | AIMM Dev β€” Enterprise AI Model Aggregator Platform & Multi-LLM Orchestration Sandbox Prototype.

    TypeScript

  2. jatansg jatansg Public

    https://github.com/jatansg/jatansg

    HCL 1

  3. advanced-sql-query-tuning-performance-optimization-4413111 advanced-sql-query-tuning-performance-optimization-4413111 Public

    Forked from LinkedInLearning/advanced-sql-query-tuning-performance-optimization-4413111

    This is a repository for the LinkedIn Learning course Advanced SQL for Query Tuning and Performance Optimization

    Dockerfile 1

  4. burrow burrow Public

    Forked from hyperledger-archives/burrow

    https://wiki.hyperledger.org/display/burrow

    Go 1

  5. chainkit chainkit Public

    Forked from blocklayerhq/chainkit

    ChainKit is a toolkit for blockchain development. It includes primitives for creating, building and running decentralized applications.

    Go 1

  6. doris doris Public

    Forked from apache/doris

    Apache Doris is an easy-to-use, high performance and unified analytics database.

    Java 1