Independent engineering practice
We build the systems other systems depend on.
Hello Infotech works from firmware and packet forwarding up to distributed platforms — software, embedded and networks — for teams in regulated and industrial sectors, designed by the engineers who stay accountable for them in production.
- Kubernetes
- BGP / EVPN-VXLAN
- Embedded Linux
- Go
- Rust
- DPDK
- Segment Routing
- Zephyr RTOS
- OpenTelemetry
- Kafka
- Yocto
- gRPC
- eBPF / XDP
- Terraform
- 5G Core
- FreeRTOS
- PostgreSQL
- ARM Cortex-M
- Argo CD
- IEEE 1588 PTP
- NETCONF / YANG
- P4
Capabilities
Four disciplines, one engineering practice
Few problems worth solving sit inside a single layer. A latency regression can be a scheduler decision, a queue policy or a cache line — and finding out which requires someone fluent in all three.
All capabilitiesSystems & Software Architecture
Distributed systems designed to survive contact with production — and with the next five years of change.
- Architecture definition and technical due diligence
- Monolith decomposition and service boundary design
- Event-driven and streaming platform design
- API design, versioning and contract governance
- Consistency models and partition behaviour
- Idempotency and exactly-once semantics
Embedded Systems & Firmware
Firmware and embedded Linux for products that ship, run unattended for years, and update safely in the field.
- Board bring-up and hardware/software integration
- Bare-metal and RTOS firmware development
- Embedded Linux BSPs, Yocto layers and kernel drivers
- Secure boot, chain of trust and OTA update design
- Deterministic real-time scheduling and jitter budgets
- Secure boot chains, TrustZone and PSA
Networking, Datacom & Telecom
Carrier and data-centre networking from the packet up — control plane, data plane, and the software that operates both.
- Network architecture for data centre, campus and carrier edge
- Routing and switching design, migration and convergence tuning
- Data-plane development and packet processing optimisation
- Network automation, telemetry and closed-loop assurance
- Sub-second convergence and BFD timing
- ECMP hashing and flow entropy
Platform, DevOps & Reliability
The delivery path and the runtime beneath it — automated, observable, reproducible, and boring in the best sense.
- Kubernetes platform design and hardening
- GitOps delivery pipelines and progressive rollout
- Infrastructure as code and environment reproducibility
- Observability: metrics, logs, traces and SLOs
- SLOs, error budgets and burn-rate alerting
- Progressive delivery and automated rollback
How we operate
Engineering,
not resourcing.
A body-shop sells hours. An engineering practice takes responsibility for an outcome. The difference shows up on the day something goes wrong.
Accountable, not resourced
The engineers who design the system remain answerable when it runs. No hand-off to an anonymous delivery pool.
Decisions are written down
Every significant trade-off ships with the reasoning behind it. You own the architecture, not just the artefacts.
Measured, not asserted
Performance and reliability claims come with the methodology and the numbers. If we have not measured it, we say so.
Whole-stack fluency
Firmware, packets and distributed services in one practice — because the hardest defects live exactly where those layers meet.
Selected work
Systems we have designed and built
Products we are building and own, reference architectures, and client engagements — each labelled for what it is, with what has been verified stated up front.
All workcorerouter — a first-party routing stack in Rust
An edge routing stack with no unauditable components — DHCP, DNS, firewall, multi-WAN failover, traffic shaping and a transactional configuration plane, all first-party, with zero third-party runtime dependencies and a total footprint of about 15 MB.
Status In service on ARM64 hardware, serving live clients — Wi-Fi, DHCP, DNS, NAT and firewall. Current scope is IPv4 edge routing.
- Third-party runtime dependencies
- Zero
- Total memory footprint
- ~15 MB
- Config transactions, auto-revert
- Atomic
- Failure paths tested against a live kernel
- Fault-injected
NorthStar — end-to-end encrypted conferencing for regulated organisations
Browser-based video conferencing where the media server never holds the keys — built for organisations whose legal team needs a better answer than "trust the vendor".
Status In pilot with design partners. End-to-end encrypted two-party calling and screen share, verified across desktop and mobile browsers. Multi-party is in development and ships as secure only when its cryptography is verified.
- MLS group keying
- RFC 9420
- Keys held by the server
- Zero
- Nothing to install
- Browser
- AES-GCM media encryption in the browser
- Per-frame
ChatForge — team messaging you host yourself
A self-hosted messaging platform for teams whose conversations should not live on someone else’s servers — real-time and complete enough to use, small enough to audit.
Status Phase 1 shipped and tested: the real-time messaging core — conversations, replies, reactions, presence, read state and attachments — running end to end on infrastructure you control.
- Your infrastructure, your jurisdiction
- Self-hosted
- A standard schema you can audit and export
- PostgreSQL
- Audit log on every mutating operation
- Append-only
Method
A predictable path from problem to production
The same five stages on every engagement, scaled to the size of the work. You always know which one we are in and what leaves it.
How we engineer- 01
Frame
We establish what the system must do, what it must never do, and which constraints are real. Most projects fail here, quietly, and only find out later.
- 02
Design
Boundaries, contracts, failure modes and capacity — written down as decision records with the trade-offs made explicit, so the reasoning outlives the meeting.
- 03
Build
Small, reviewable increments behind automated verification. Working software at every step, never a six-month integration cliff at the end.
- 04
Harden
Load, fault injection, soak testing and security review before production — not after it. We try to break it while breaking it is still cheap.
- 05
Hand over
Documentation, runbooks, telemetry and a team that can operate the system without us. An engagement that leaves you dependent has failed.
Insights
What we are working on and what it taught us
Engineering notes, teardowns and design records. Published as the work happens, so you can judge the thinking rather than the brochure.
All insightsYour average latency is a story about a system nobody uses
Mean response time describes a request that mostly does not exist. Tail latency describes the one your customer remembers — and at scale, almost every user hits the tail eventually.
Network convergence is not one number
A vendor datasheet quotes convergence as a single figure. In production it is a chain of four independent delays, and the one you did not tune is the one that decides your outage duration.
The bootloader is the only code that is never allowed to be wrong
Every other component in an embedded product gets a second chance through an update. The code that performs the update does not. That asymmetry should change how it is written and reviewed.
Start here
Have a system that has to work?
Bring the hard part. Architecture reviews, greenfield builds, firmware bring-up, network design, or a platform that has stopped being predictable — start with a conversation, not a contract.
Typical reply within one business day · IST (UTC+5:30)