Carlos Fuentes Navarro
A one-person engineering practice run with the discipline of a team: adversarial audits, technical debt documented with an explicit trigger condition, nothing declared "closed" without end-to-end verification.
How I work
Adversarial audits, not self-congratulation.
Every piece of code that touches authentication or billing goes through a security review in an independent session — so I'm never the one reviewing my own work.
Technical debt gets declared, not hidden.
When something is deferred (a legal review, a storage migration), it gets written down with the reason and the exact condition that triggers resolving it — not a vague promise to "get to it later."
Verified in production, not on localhost.
Nothing gets marked closed until it's confirmed with a real transaction, a real deployment, a real push — not with "it works on my machine."
One person accountable, zero team excuses.
There's no committee to dilute a security decision, no "someone else owns that." Whatever you see published, I decided it, built it, and verified it myself.
Published assets
Looking for my profile as an engineer? portfolio.thenapply.dev