Then Apply ← Back to home
ABOUT // who's behind Then Apply

Carlos Fuentes Navarro

A one-person engineering practice run with the discipline of a team: adversarial audits, technical debt documented with an explicit trigger condition, nothing declared "closed" without end-to-end verification.

How I work

Adversarial audits, not self-congratulation.

Every piece of code that touches authentication or billing goes through a security review in an independent session — so I'm never the one reviewing my own work.

Technical debt gets declared, not hidden.

When something is deferred (a legal review, a storage migration), it gets written down with the reason and the exact condition that triggers resolving it — not a vague promise to "get to it later."

Verified in production, not on localhost.

Nothing gets marked closed until it's confirmed with a real transaction, a real deployment, a real push — not with "it works on my machine."

One person accountable, zero team excuses.

There's no committee to dilute a security decision, no "someone else owns that." Whatever you see published, I decided it, built it, and verified it myself.

Published assets

web-to-markdown

Converts web pages and raw HTML into clean, LLM-ready Markdown.

openapi-to-mcp

Turns an OpenAPI 3.x spec into a working MCP server.

mcp-shield-proxy

A local firewall for MCP servers that inspects tool calls and masks secrets.

Looking for my profile as an engineer? portfolio.thenapply.dev