Patrick Kipkoech

Software Developer · MIT, Cyber Security and Networking

I build products, not demos.

Full-stack web and mobile, with AI where it earns its place.

I graduated with a Master of Information Technology in May 2026. Alongside it I designed, built and shipped four production applications on my own. The main one is My County, published on Google Play with over 500 installs and a 5.0 rating — a Flutter app shipping to Android and web from one codebase, which I migrated onto a Django backend while it was live, and which now runs an AI news desk with a human approval gate. The others are a documentation tool for the Australian NDIS and aged care sector, an AI study platform, and a bilingual assistant paid for by mobile money.

Each one went from an empty repository to authentication, a payment path, a deployment pipeline and real users' data to protect. My degree specialised in cyber security and networking, and that shows up in the code rather than only on the certificate — every project here enforces access at the database, not in the client.

This is not a career change. I hold a BSc in Mathematics and Computer Science from Maseno University, and I worked in IT and networking for over three years before the Masters — as a network technician and later ICT clerk at ECAN-CRF in Eldoret, and in technical roles at Stewards Media and Wimp Technologies.

I'm looking for a graduate or junior developer role in Australia where I can keep working at that width.

Qualification
Master of Information Technology
Cyber Security and Networking
University
Murdoch University
Completed
May 2026
Earlier degree
BSc Mathematics and Computer Science
Maseno University
Based in
Perth, WA
Work rights
Full working rights
Temporary Graduate 485, to Jan 2028
Focus
Full-stack · Mobile · AI integration

Selected work

Four projects

All four are my own work, built solo. The first three are live — open them from the links on each project. The code sits in private repositories, and I'm glad to walk through any of it in an interview or grant access on request.

My County

Live on Google Play Android & web · v1.4.7

Community platform · Published Android and web app · Django backend · AI news desk

My County is published on Google Play and runs as a web app from the same Flutter codebase. It gives Kenyan counties, constituencies and wards their own local feed — posts, events, a marketplace, a business directory, attractions and real-time chat, all scoped to where you actually live. It is the project I have worked on longest, it has real users, and it spans four distinct pieces of engineering.

The app

Flutter across twelve feature modules, at version 1.4.7, build 30, with Riverpod for state and go_router for navigation. The feed ranks on a blend of recency and engagement, pages with Firestore cursors rather than offsets, and keeps like and comment counts correct under concurrency using transactional counters behind an optimistic UI. Access is enforced with ownership and field-level Firestore rules, image-only Storage rules, and composite indexes backing every ward and constituency query. Chat carries presence, typing indicators and last-seen; posts and comments support @mention tagging with de-duplicated notifications.

The backend migration

I rebuilt the backend as Django REST Framework on PostgreSQL, verifying Firebase ID tokens as JWTs so the mobile client's authentication carried over unchanged, with S3 presigned URLs for media. It deploys to a DigitalOcean droplet through Docker and GitHub Actions on every push to main, behind Caddy for automatic TLS.

I mapped the Django models one-to-one onto the existing tables and adopted them with migrate --fake-initial, so 241 live posts carried across with no data migration at all. The cutover was a single base-URL change in the Flutter client, and reversible instantly by changing it back.

The AI news desk

A Django app that drafts local news through a five-stage pipeline: ingest, dedupe, write, critique, gate. A critic stage checks every claim in a draft against its source and sends unsupported ones back to the writer for a bounded revise loop. Nothing reaches the feed on its own — anything the critic marks sensitive always goes to a human review queue, and by default routine stories do too.

The cost controls are deliberate. A queue cap stops drafting entirely once the review queue is full, so there is no model spend on stories nobody has capacity to judge, and deferred clusters flow again once it drains. Headline-only and paywalled sources are skipped and marked seen so they are never paid for twice. Every stage reports its cost, and each cluster, space agent and persona is isolated so one failure cannot take down the batch.

Systems design

The platform is growing an identity graph — schools, cohorts, workplaces and shared spaces. One endpoint answers "how are we connected?" with a bounded six-degrees path search: direct links first, then a single intermediary, with school ties deliberately usable only as a direct link and never as a traversal hop, because alumni fan-out is enormous. Space-mate fan-out is capped per side and the intersection is done in memory, keeping the whole answer to roughly seven indexed queries. I specified it, and twenty other features, as written design docs before building them.

Specification

Status
Live on Google Play — 500+ installs, rated 5.0
Role
Sole developer
Platforms
Android and web from one Flutter codebase
Mobile
Flutter · Dart · Riverpod · go_router · flutter_map · geolocator
Backend
Django REST Framework · PostgreSQL · Redis · Firebase Admin SDK
Infrastructure
Docker · GitHub Actions · DigitalOcean · AWS S3 · Caddy
AI
Multi-stage drafting pipeline with a critic, human approval gate and queue-cap cost control
Scale
12 feature modules · 9 backend apps · 21 written design specs
Notable
Live backend migration with one-line rollback, bounded graph search, transactional counters, field-level security rules

ShiftNote AI

Live

Healthcare documentation · Built for the Australian market

Support workers in NDIS and aged care finish a shift and still owe an hour of paperwork. ShiftNote AI takes the rough notes they actually write — "leon refused meds again. oats for breakfast. gp called." — and returns a structured, section-numbered progress note in the format their provider expects.

I built the whole product: Firebase email authentication with verification, a template engine so a provider can encode their own note format, per-account usage metering against daily and lifetime limits, and Stripe subscriptions with webhook-driven enforcement across a free and Pro tier.

The compliance side shaped the design as much as the AI did. Raw notes are minimised rather than retained, the output follows NDIS progress-note conventions, and the data model was built with Australian privacy expectations in mind.

Specification

Status
Live — deployed on Vercel
Role
Sole developer
Stack
Next.js 14 (App Router) · TypeScript · Tailwind CSS
Services
Firebase Auth · Firestore · OpenAI · Stripe
Deployment
Vercel
Notable
Subscription limit enforcement, usage metering, prompt-driven template system

YoohStudy

Live 50 students · 132 courses

AI learning platform · Whole syllabus generated at controlled cost

A live platform with fifty registered students, which has generated over 130 courses to date. A student enters their institution, their course and what they already know, and it generates the entire syllabus from that: six to eight units, four to six lessons each, and an end-of-unit exam of ten to fifteen auto-graded questions on a countdown timer.

Generating a course is expensive if you do it naively, so it is deliberately cost-engineered — GPT-4o-mini rather than a frontier model, generation deferred until a lesson is actually opened, and content streamed to the page as it arrives instead of blocking on a complete response. A full course lands at roughly one to two dollars of inference.

Data sits in Supabase Postgres with Row Level Security on every table, so a student can only ever read their own progress, attempts and answers — enforced at the database rather than trusted to application code.

Specification

Status
Live at yoohstudy.com — 50 registered students, 132 courses generated
Role
Sole developer
Stack
Next.js 14 · TypeScript · Tailwind CSS
Data
Supabase · PostgreSQL · Row Level Security
AI
OpenAI GPT-4o-mini · streamed generation
Notable
Just-in-time content generation, per-course cost modelling, ten-table relational schema

AskKenya AI

Built 2026

Conversational AI · Mobile money payments

A bilingual AI assistant in English and Swahili, paid for the way people in Kenya actually pay: M-Pesa.

The payments work is the substance. It runs against Safaricom's Daraja API using STK Push — the server initiates the charge, the customer's phone prompts for a PIN, and an asynchronous callback later confirms or fails the transaction and credits the account. That means designing for a payment whose confirmation arrives out of band, minutes later, or never at all.

Around it: Firebase authentication and storage, document upload so users can ask questions about a PDF or spreadsheet, a credit ledger with usage analytics, and a real internationalisation layer rather than hardcoded strings.

Specification

Role
Sole developer
Stack
Next.js 14 · TypeScript · Tailwind CSS
Services
Firebase Auth · Firestore · Storage · OpenAI
Payments
M-Pesa Daraja — STK Push and callback reconciliation
Notable
Asynchronous payment settlement, English/Swahili localisation, credit ledger

Technical skills

Used in shipped work

Languages

  • TypeScript
  • JavaScript
  • Dart
  • Python
  • SQL
  • HTML
  • CSS

Frontend

  • Next.js App Router
  • React
  • Flutter
  • Tailwind CSS
  • Riverpod
  • go_router

Backend

  • Django
  • Django REST Framework
  • Node.js
  • REST API design
  • Server-side rendering

Data

  • PostgreSQL
  • Firestore
  • Supabase
  • Redis
  • Schema design
  • Migrations
  • Indexing

Cloud & DevOps

  • Docker
  • GitHub Actions
  • AWS S3
  • DigitalOcean
  • Vercel
  • Firebase
  • Caddy

AI integration

  • OpenAI API
  • Multi-stage pipelines
  • Automated critique
  • Human-in-the-loop review
  • Prompt design
  • Streaming responses
  • Token and cost budgeting

Payments

  • Stripe subscriptions
  • Webhooks
  • M-Pesa Daraja
  • Usage metering

Security

  • Firebase Auth
  • JWT verification
  • Row Level Security
  • Firestore rules
  • Ownership checks

How I work

I finish things

Every project here went from an empty repository to authentication, payments, a deployment pipeline and a path to a paying user. I'm comfortable owning a feature end to end rather than only the layer I was handed.

I enforce access at the data layer

Field-level security rules, Row Level Security, ownership checks and server-side token verification recur across this work, because I would rather the database refuse a bad request than trust the client not to make one. My masters specialised in cyber security and networking, so this is training as much as instinct.

I don't let AI publish unsupervised

My County drafts local news with a model, but a critic stage checks each claim against its source, sensitive stories always route to a human, and a queue cap stops generation when nobody has capacity to review. Useful AI needs a gate, a budget and a person.

I plan for the version already running

Cost per request, pagination under load, counter correctness, and a rollback that takes one line. The My County backend migration mattered because it was reversible, not because it was clever.

Open to graduate and junior developer roles

I'm looking for full-stack, backend or mobile work in Australia — a team where I can learn from people more experienced than me and still be trusted to ship. The fastest way to reach me is email.