A full-stack, DevOps & security studio · AI products and the infrastructure that keeps them running · 7 open-source packages
Hiprax started long before invoices and contracts. It began with three friends wired on curiosity, breaking systems, rebuilding them, and refusing to accept a surface-level understanding of anything.
That curiosity turned into skill, and the skill into discipline. The mindset never changed.
We build web applications end to end — database and cloud infrastructure through to the last pixel of the interface. Across 10+ years of engineering (the studio itself has been trading since 2020) we've shipped under real pressure, the kind where "almost good" gets someone paged at 4am. No shortcuts. No hand-holding frameworks. No blind dependency on AI. Just engineers who understand what they build, top to bottom.
Every client we've worked with has chosen to work with us again. Not by chance.
Two things about that pipeline are worth saying out loud.
The threat model comes before the feature code. Retrofitting auth and authorization onto a shipped product is how most breaches start. We'd rather spend a day on it in week one than a month on it after someone finds the hole.
Everything ships as one self-contained stack. One compose file, one root .env, one port bound to the loopback interface, and an Nginx on the host holding the certificate. It runs identically on a laptop and on a bare VPS, which means "works on my machine" stops being a sentence anyone says.
| Service | What we deliver |
|---|---|
| Web development | Full-stack apps on the MERN stack and Next.js: real-time features, REST and GraphQL APIs, and database design that scales. |
| DevOps & cloud | CI/CD pipelines, Docker and Kubernetes, AWS, GCP and Azure, infrastructure as code, and hardened Linux servers. |
| Security | Security audits, penetration testing, secure code review, auth and encryption, and compliance guidance. |
| Technical consulting | Architecture reviews, technology selection, performance optimization, and team mentoring. |
Three senior engineers. No juniors to babysit, no account manager to route around — you talk to the person writing the code.
|
Sajad Khanmirzaei Founder & CEO Full-stack · DevOps @Sajadlance
|
Saeed Mirzade Full-stack & AI Engineer MERN · React Native @saeedmirzade
|
Ashkan Gholizade Back-end & Security APIs · Hardening @AshkanGholizadeh
|
A few of the products we've shipped. Most are under NDA, so these are the shapes rather than the client names.
| Project | What it does | Stack |
|---|---|---|
| AI Print-on-Demand Studio | Generate original artwork from a prompt, refine it in a full in-browser design editor, then order it on real products. | MERN · Fabric.js · Socket.io · GenAI |
| AI Political Transparency | Aggregates political news and fact-checks live speech in real time, with a conversational AI for civic questions. | MERN · WebSocket / SSE · AI |
| Omnichannel AI Sales | A subscription CRM where businesses train custom AI agents that run SMS and voice outreach and close deals on their own. | MERN · Stripe · AI |
| Conversational AI Ordering | Human-like voice AI that answers restaurant calls and takes orders through natural conversation. | Python · TensorFlow · Transformers · FastAPI |
| Financial Fraud Prevention | Real-time verification so people can tell a genuine bank contact from an impersonation scam. | Node · React · REST |
| Vending Ops Platform | Fleet operations end to end: inventory, dispatch, route optimization, per-machine financial reporting, subscription billing. | MERN · Stripe |
The full list — the 23 we can name
AI Company Showcase & Marketing Website · AI Market Intelligence Suite · AI Print-on-Demand Design Studio · AI-Powered Investment Signal Platform · AI-Powered Political Transparency Platform · Advanced HTTP Parameter Pollution Shield · Conversational AI Ordering System · Dynamic Audio Visualization Engine · Enterprise Admin Dashboard UI Kit · Enterprise-Grade Encryption Library · Financial Fraud Prevention Platform · Full-Stack Image Processing & Delivery System · Full-Stack Ticketing & Support Management System · Government Document Automation Suite · Omnichannel AI Sales Engagement Platform · Peer-to-Peer Storage Marketplace · Production-Grade Structured Logging Toolkit for Node.js · React SEO Management Hook · Real Estate Auction Intelligence System · Real-Time Penny Auction Platform · Social Engagement Rewards Platform · Stereoscopic 3D Streaming System · Vending Machine Operations Platform
Five of them are open source; you can read every line further down. The rest live at hiprax.com.
| Layer | Tools |
|---|---|
| Frontend | React · TypeScript · Next.js · Tailwind · Three.js |
| Backend | Node · Express · Python · FastAPI · Django |
| Data | MongoDB · Redis · PostgreSQL · MySQL · Elasticsearch |
| Infra | Linux · Docker · Kubernetes · Nginx · AWS · Cloudflare · GitHub Actions |
| Applied AI | RAG · agents · OpenAI · LangChain · Hugging Face · PyTorch · Whisper / voice |
| Security | OWASP · OAuth / JWT · AES-GCM · Argon2id · TLS · pentesting |
Vue, Svelte, Angular, Flask, PHP, and Laravel are in the toolbox too, when a project already lives there.
We build for developers as well as clients. Seven packages on npm — four under the @hiprax scope, three unscoped — all MIT, around 11,600 downloads in the last year. @hiprax/crypto and @hiprax/logger publish straight from CI through npm's OIDC trusted publishing, so no token ever sits on a laptop.
Good engineering should strengthen the ecosystem instead of extracting from it. These are free, and they stay free.
| Package | What it gives you |
|---|---|
@hiprax/crypto |
AES-256-GCM authenticated encryption with Argon2id key derivation, file streaming, and constant-time comparison. Zero runtime dependencies. |
hppx |
HTTP Parameter Pollution shield for Express: blocks prototype pollution, null-byte injection, and DoS vectors with nested whitelists. |
pixel-serve-server |
Sharp-powered image middleware: on-the-fly AVIF and WebP conversion, resizing, strict path validation, smart caching. |
pixel-serve-client |
The React half of Pixel Serve: multi-format srcset, lazy loading, a skeleton loader, SSR-safe fallbacks. |
@hiprax/use-seo |
One React hook for titles, Open Graph, Twitter Cards, hreflang, and JSON-LD. SSR-safe and fully tested. |
@hiprax/logger |
Winston-based structured logging with daily rotation, verified IANA timezones, and an Express middleware that masks secrets automatically. |
@hiprax/errors |
Modular error handling for Express: structured, typed error classes and consistent API responses. |
Also on the shelf: h-vault — a zero-knowledge, self-hostable password manager and encrypted notebook. AES-256-GCM happens in the browser; the server only ever sees ciphertext.
"The best full-stack team I have ever met in my working career, and even better individuals. Thank you Hiprax for your work and amazing results for us."
Ovidio Gomez
"It is hard to find devs who actually care about the backend security as much as the front-end design. Hiprax is the real deal. They spotted a vulnerability we did not even know we had and patched it without making a fuss."
Elena Rodriguez
"We were in a huge bind after our previous developer left us hanging right before launch. Hiprax stepped in and cleaned up the code in three days. They literally saved our launch week."
Marcus Thorne
Those are all three we've published, names as given. We don't dress them up with stock photos or invented job titles.
It can be imagined? It can be built.
It's complex? Even better.
It's impossible? Let's make it happen.
Have something complex, security-critical, or a little impossible in mind? That's our favourite kind of brief.
How to start. Email dev@hiprax.com with three things: the problem, the stack you're on, and the deadline you're working against.
Who reads it. An engineer, not a salesperson. You'll get an honest read on how we'd build it and whether we're the right team for it. If we're not, we'll tell you, and usually point you at who is.
Currently available for new work.
Three hand-written SVGs and a few live npm badges. No stats cards, no streak counters, no snake.
Every animation is CSS and respects
prefers-reduced-motion.Tell us what you're building: dev@hiprax.com
