Skip to content

Backend Engineer · Cesta Technology · Istanbul

AliYılmaz.

I build scalable backend systems across legal, insurance, e‑commerce and many other domains.

I build microservice architectures on the Java and Spring ecosystem. At Cesta Technology I designed and shipped the backend for CestaLex and CestaLaw, and I have built products in insurance, barter marketplaces, recipe recommendation and task management. I work with Kafka, Redis, PostgreSQL, Docker and Kubernetes.

sites live
4
sites live
projects
13
projects
years coding
5+
years coding
01 / 04

01

Selected work

Products running in production. Each one is written up as a case study covering architecture, technology choices and results.

All projects →
01LiveYargıtay · Regional Courts · Constitutional Court

CestaLex

AI-assisted case-law research platform for the Turkish courts

A case-law research platform for law firms, covering Yargıtay, the regional courts of appeal and the Constitutional Court, with semantic search, a streaming AI assistant and a document editor.

CestaLex — Visit site
3
isolation layers
3
high-court corpora
0
manual invoicing steps
SHA-256
chained audit log
  • Multi-tenant architecture: each law firm's data is isolated from the others in three independent layers, including PostgreSQL Row-Level Security.
  • JWT/OAuth sessions, UYAP e-signature for legally binding actions, plus 2FA and role-based access for privileged operations.
  • Transactional outbox over Kafka for lossless event delivery between services; a SHA-256 chained, tamper-evident audit log.
  • Java 21
  • Spring Boot
  • PostgreSQL
  • Kafka
  • Redis
  • Qdrant
  • Gemini
  • Docker
  • Kubernetes
  • S3
02LiveECHR · Europe

CestaLaw

Research platform for European Court of Human Rights case law

Sister product to CestaLex, focused on European Court of Human Rights case law and expanding toward wider European jurisdictions.

CestaLaw — Visit site
1
shared platform foundation
2
distinct jurisdictions
0
model calls on the request path
  • ECHR judgments have their own citation structure and procedural logic; the search and citation layer was modelled for this corpus specifically.
  • Kafka handles inter-service communication and Redis caches the hot read paths.
  • An AI microservice plugs into the drafting flow, with model calls kept off the request path.
  • Java
  • Spring Boot
  • React
  • Kafka
  • Redis
  • Docker
  • CI/CD
03LiveRecommender system

ChefsStack

Recipe platform with a vector-based recommendation engine

A recipe and recommendation platform where suggestions come from vector similarity instead of hand-written rules, and user interactions flow through Kafka and Redis into personalized feeds.

ChefsStack — Visit site
<50ms
similarity query
1.000+
interaction events processed
0
hand-written recommendation rules
  • Similarity queries answer in under 50ms on FastAPI + pgvector.
  • 1,000+ user interaction events flow through Kafka and Redis into personalized feeds and live trending lists.
  • Ingestion and serving are decoupled, so a slow model never blocks reads.
  • Python
  • FastAPI
  • PostgreSQL
  • pgvector
  • Redis
  • Kafka
  • Docker
04In developmentEvent-driven marketplace

TradeHub

Barter marketplace with a two-sided confirmation protocol

A barter marketplace. With no escrow, trust between two strangers is built through a two-sided confirmation protocol.

2
phase confirmation protocol
5+
microservices
0
single-sided cancellation paths
  • Two-phase handshake: a trade can't settle unless both sides confirm, making the single-sided cancellation attack impossible by design.
  • The outbox pattern keeps trade state safe even if a service dies mid-transaction.
  • Google OAuth2 and role-based access control span 5+ services.
  • Java
  • Spring Boot
  • PostgreSQL
  • Kafka
  • Redis
  • Docker
  • OAuth2

02

At a glance

Live data refreshes hourly from GitHub and Medium.

  • Java 21
  • Spring Boot
  • Spring Security
  • Kafka
  • Redis
  • PostgreSQL
  • Docker
  • REST API
  • JWT & OAuth2
  • Python
  • FastAPI
  • Qdrant / pgvector
  • SQL
  • Git
  • CI/CD
  • Kubernetes
  • TypeScript
  • React
  • Next.js
  • Coolify
  • Nginx
  • Swagger / OpenAPI
  • Scikit-Learn

03

How I work

Four approaches I apply across projects.

01

Security starts at the database layer

I don't leave authorization and data isolation to application code alone. I back them with database-level mechanisms such as PostgreSQL Row-Level Security and role-based access control.

02

Services communicate through events

Between microservices I use Kafka with the transactional outbox pattern, so state transitions are not lost and data stays consistent even when a service goes down.

03

Caching and asynchronous processing

I keep frequently read data in Redis and move long-running work such as AI model calls off the request path, which keeps response times predictable.

04

Measurable results

I track the effect of every technical decision with metrics such as response time, latency and accuracy. Every number on this site is tied to a specific design decision.

Have something in mind?

Let's talk backend architecture, microservices or a new product. I usually reply the same day.

aliyilmazsoftware@gmail.com