
Ksatria Bintang Samudra
AI Engineer · Automation Builder · Solutions Architect
Pontianak, Indonesia
About Me
I’m Ksatria — an AI-native engineer from Pontianak, the Indonesian city that sits right on the equator. I build production systems end-to-end: an OpenAI-compatible AI gateway with live cost metering, an anti-fraud attendance and payroll platform for a mining contractor, and payment-native automation that runs while its owners sleep.
My path is a little unusual. I started analysing social-media data for clients on Upwork, moved into penetration testing, then spent a year and a half administering Google Workspace for a mining company. Each stop left a habit I still use: respect data, assume nothing is safe by default, and automate whatever doesn’t need a human.
Today I work spec-first and AI-orchestrated — Claude Code and Cursor do a lot of the typing, and I own every decision. If you need something real shipped quickly, without cutting corners on security or data integrity, let’s talk.
Quick Facts
Expertise
What I’ve shipped
Concrete things I built end-to-end, with the scope that matters. Every link is live.
- CoalTrack — anti-fraud workforce & payroll for mining2026
Flutter + Laravel, multi-tenant. Tamper-resistant attendance (server time, device binding, mock-GPS rejection) that feeds Indonesian payroll, bank files and payslips. 7 languages. In pilot with a coal-mining contractor.
- Vensix — OpenAI-compatible AI gateway2026
One key, one Rupiah balance: routes to Claude, GPT, Gemini, DeepSeek and Kimi with live cost-based metering, QRIS top-ups and automated hosting provisioning.
- Makmur Motor — edge-native showroom & CMS2026
Next.js on Cloudflare Workers with D1 and KV; a dealership runs its own inventory, photos and SEO from an admin panel.
- Lavelle — digital wedding-invitation studio2026
Staff portal with live preview, Supabase row-level security and one-click publishing of each invitation to its own subdomain.
- Phishing threat-intel case files2026
Passive OSINT dissection of a WhatsApp phishing / CPA-fraud campaign: 500+ related domains mapped, chain-of-custody manifests, abuse reports.
How I work
The rules behind everything on this site — and everything I ship for clients.
- Spec first
- Every build starts with scope, constraints, contracts and acceptance criteria. The AI inherits the spec — never the guesswork.
- AI-orchestrated
- Claude Code, Cursor and custom prompt chains do the typing. The right tool for each layer, not one hammer for every nail.
- Human-verified
- I read what the tools produce, test it, and own every architectural decision, security boundary and trade-off.
- Security by default
- Pentesting taught me to assume nothing is safe: server-side verification, least privilege, idempotent payments, no secrets in the client.