Skip to content
Available for select workWichita Falls, TX·—:—:— CT

/ 00 — Sanithu Hulathduwage

Student,softwareengineer &founder.

// Right now I'm

I'm a Computer Science student at Midwestern State University and multi-venture founder. Founding engineer + architect of a HIPAA-compliant healthcare CRM — built from zero, now scaled to a team. Founder of SetFlow. Inventor of the Universal Privacy Engine.

Download resume (PDF)·Updated May 2026·For recruiters + co-founders
Portrait of Sanithu Hulathduwage
Wichita Falls · Live
MeetHappy
01Now

Velant.ai

Founding engineer · HIPAA CRM in production

02Shipping

SetFlow

AI-native LMS · getsetflow.app · beta

03Inventing

Privacy Engine

Zero-knowledge data architecture

Velant.ai — HIPAA-compliant healthcare CRMSetFlow — AI-native LMSGoodFellow Support Services — UK careUniversal Privacy Engine — researchAvailable for select work
Velant.ai — HIPAA-compliant healthcare CRMSetFlow — AI-native LMSGoodFellow Support Services — UK careUniversal Privacy Engine — researchAvailable for select work

/ Based in

Wichita Falls, TX

Originally from Colombo, Sri Lanka 🇱🇰

Scroll to begin
The person
01 / About

On principle.

I went from class assignments to shipping enterprise-grade production systems in under a year. As founding engineer and architect at Velant.ai, I built the platform from zero — a HIPAA-compliant multi-tenant healthcare CRM with a full WebRTC VoIP softphone, an AI call intelligence pipeline, a real-time WebSocket architecture, and a cross-platform Flutter mobile app — across a 4-app monorepo. Now leading engineering alongside the team.

In parallel I founded SetFlow — an AI-native LMS for K-12, higher ed, and individual learners, with a Bring-Your-Own-Database tier for institutions. I also co-founded GoodFellow Support Services Ltd, a UK elderly care company, where I lead operations and technology remotely from the US.

I'm also inventing the Universal Privacy Engine — a privacy-first computing architecture where identity is destroyed before processing, not merely protected after collection. I treat compliance, cryptography, and zero-trust as architectural primitives, not policy afterthoughts.

Across healthcare (Velant.ai) and education (SetFlow), I've shipped against HIPAA, FERPA, COPPA, GDPR / UK GDPR, CCPA / CPRA, SOC 2 Type 1 readiness, and IDEA accommodations — DPAs and data-flow diagrams available under NDA.

Open to internships, full-time roles, founder collaborations, and research partners.

/ At a glance

Velant monorepo · founding engineer
0 apps
Feature modules shipped
0
Third-party integrations
0+
Compliance mindset
HIPAA

/ Currently

  • Co-Founder, COO & CTO — GoodFellow Support Services LtdDec 2025 – Present · UK elderly care + cleaning company, run remotely from the US.
  • Founder & CEO — SetFlowAI-native LMS at getsetflow.app. K-12, higher ed, and individual learners.
  • Founding Engineer & Architect — Velant.ai2024 – Present · HIPAA-compliant healthcare CRM with VoIP + AI. Built it from zero, now lead engineering alongside the team.
  • CS & Math Tutor — Midwestern State University2024 – Present · One-on-one and group tutoring across CS and math.
02 / Ventures

Three companies, one operator.

What I'm building today — across SaaS, healthcare, and care services.

/ 01

SetFlow

Founder & CEO

AI-native LMS for K-12, higher ed, and individual learners.

A learning operating system built on Next.js 14, Prisma, Postgres, and Anthropic Claude. Two products in one codebase — SetFlow (the LMS) and SetFlow Academy (the marketplace) — with a Bring-Your-Own-Database tier so institutions keep student data on their own Postgres.

Next.js 14PrismaPostgreSQLAnthropic ClaudeTailwindshadcn/ui
/ 02

Velant.ai

Founding Engineer & Architect

HIPAA-compliant healthcare CRM + telephony platform.

4-app pnpm monorepo: React CRM, Flutter mobile, patient portal, NestJS API. Includes a full WebRTC VoIP softphone, an AI call intelligence pipeline (Whisper → GPT-4o → follow-up content), Azure OpenAI SMS outreach with auto-takeover, multi-tenant data isolation, and 15+ third-party integrations.

NestJSReactFlutterSupabasePostgreSQLRedisAuth0BullMQSIP.jsWebRTC
/ 03

GoodFellow Support Services Ltd

Co-Founder, COO & CTO

UK elderly care + specialist cleaning, run remotely from the US.

Non-clinical elderly care and specialist cleaning across the UK. I lead operations and technology remotely — service delivery, workforce coordination, hiring, onboarding, scheduling, the website, hosting, internal tools, and workflow automation.

OperationsWorkforce systemsWeb infraAutomationBrand
Featured · SetFlow

Featured · SetFlow

getsetflow.app ↗

SetFlow never
stores your
student data.

In spring 2026, Canvas was breached — roughly 275M student records compromised by ShinyHunters across 8,809 institutions. SetFlow’s architecture makes that scale of breach structurally impossible: districts keep their own data through our Bring-Your-Own-Database tier.

The Canvas breach. April 29 – May 7, 2026

Attributed: ShinyHunters

0M

records compromised
Stolen
3.65 TB
Records
~275 million
Institutions
8,809
Countries
50+
Notable
8 Ivy League schools

In spring 2026, ShinyHunters breached the Canvas learning platform and exfiltrated student data — roughly 275 million records across 8,809 institutions, with outages dragging through finals week. It became one of the largest education-data breaches on record.

✕ Exposed

Full names · email addresses · student IDs · billions of private messages between students and teachers

✓ Not exposed (per Instructure)

Passwords, SSNs, and financial info (per Instructure).

▲ Primary risk

Targeted spear-phishing + social engineering using the stolen private messages.

The takeawayCentralized student data is one breach away from catastrophe.

The lesson isn’t to harden a central vault — it’s to stop centralizing student data in the first place. SetFlow keeps each district’s data in the district’s own Postgres, AES-256-GCM-encrypted at the connection layer, never on our servers.

How SetFlow prevents this

/ Why SetFlow is different

/ 01

Platform, not feature

Classroom + study + AI tutor + LMS integration in one — an order-of-magnitude bigger moat than any single-workflow competitor.

/ 02

LTI 1.3 from day zero

AGS grade passback + NRPS roster sync + Deep Linking 2.0 shipped. School IT deploys SetFlow into Canvas / Brightspace / Moodle / Blackboard via SSO. Most new entrants haven’t.

/ 03

Tori is course-aware

Every class gets its own Tori with its own memory, learning the student over a semester. Not "ChatGPT for school" — a tutor per course.

/ 04

Free for the first 50 students

Per teacher, no card required. District pricing only at scale. Priced for adoption, not extraction.

/ The market

US K-12 EdTech

$13B → $30B

by 2030 · HolonIQ

AI tutoring slice

$1B → $20B+

by 2030

Inference cost

$3 – $8

per student / year

Status

Live · getsetflow.app

Pre-revenue · WFISD in talks

/ Cleared forFERPACOPPAGDPR / UK GDPRSOC 2 Type 1CCPA / CPRAIDEADPA on request
03 / Stack

What I work with.

The languages, frameworks, and primitives I reach for. Updated regularly.

01

Languages

TypeScriptJavaScriptPythonDartJavaC++
02

Backend

NestJSNode.jsPrismaBullMQSocket.IOPassport.jsZodclass-validatorFastAPIFlask
03

Frontend

React 18Next.js 14ViteZustandTanStack QueryReact Hook FormChakra UITailwind CSSFramer Motionshadcn/ui
04

Mobile

FlutterRiverpodDioGoRouterflutter_secure_storageSIP_UAWebRTC
05

VoIP & Real-Time

SIP.jsWebRTCSocket.IOSupabase RealtimeBroadcastChannel APIAPNs VoIP PushFCM
06

AI / ML

OpenAI GPT-4oWhisperAzure OpenAI AssistantsAnthropic ClaudeRAG pipelinesOllamaPineconeTensorFlowpgvector
07

Databases & Caching

PostgreSQLSupabaseRedis (ioredis)MySQLMongoDBPinecone (Vector DB)
08

Infra & DevOps

AWS S3AWS Secrets ManagerVercelDockerTerraformpnpm monorepoCI/CDCloudflare
09

Integrations

Convirza (VoIP/SMS)Auth0Meta AdsGoogle AdsWhatConvertsSquareClaimMDSentryDatadogNew Relic
10

Security primitives

AES-256-GCMJWT RS256MFA / TOTPRow-Level SecurityRBAC (capability-based)Audit loggingRate limitingTLS / HSTS / CSPAWS Secrets ManagerConfidential computing posture
11

Regulatory compliance

HIPAAFERPACOPPAGDPR / UK GDPRSOC 2 Type 1 (readiness)CCPA / CPRAIDEA accommodationsData Processing AgreementsData residency planning
04 / Experience

From IT desk to enterprise systems.

A non-linear path that runs from physical IT and brand design through to founding and engineering production platforms.

Dec 2025 – Present · Remote (UK)

Co-Founder, COO & CTO

GoodFellow Support Services Ltd

Co-founded a non-clinical elderly care and specialist cleaning company across the UK. Lead operations + technology remotely from the US — workforce coordination, scheduling, website, and full technical infrastructure.

2024 – Present · Remote

Founding Engineer & Architect

Velant.ai

Architected and shipped the entire Velant platform from zero — a HIPAA-compliant enterprise healthcare CRM with VoIP telephony, AI call intelligence, a real-time WebSocket architecture, a cross-platform Flutter app, and a secure patient portal. 31 feature modules, 15+ third-party integrations. Now leading engineering alongside a small team.

2024 – Present

Founder & CEO

SetFlow

Founded SetFlow — an AI-native LMS at getsetflow.app for K-12, higher ed, and individual learners. Built on Next.js 14 + Prisma + Postgres + Anthropic Claude, including a Bring-Your-Own-Database tier so institutions can host student data on their own Postgres.

2024 – Present · Wichita Falls, TX

CS & Math Tutor

Midwestern State University

One-on-one and group tutoring across Computer Science and Mathematics — data structures, algorithms, calculus, debugging, and problem sets.

2024 · Wichita Falls, TX

Graphic Designer

McCoy's Roofing & Renovations

Redesigned business cards and brand logo (+20% client inquiries); built and optimized the LinkedIn presence to grow visibility.

2024 · Wichita Falls, TX

Graphic Designer

Empire Tax Services

Designed branded marketing materials that contributed to a 15% increase in event attendance.

2022 – 2023 · Wichita Falls, TX

IT Technician

Midwestern State University

Built and configured 60+ computers (−25% downtime), resolved 95% of IT support tickets on first contact, and maintained on-campus servers, networks, and AV infrastructure.

2021 – 2022 · Colombo, Sri Lanka

IT & Operations

K Life Private Limited

Improved equipment uptime by 10% and managed social media — 3% audience growth and 18% profit increase across owned channels.

Selected work · Hire me · Co-found
05 / Selected work

Things I've shipped.

From class assignments to enterprise-grade production systems. Tap any row to expand.

Two products in one codebase. SetFlow (the LMS) at getsetflow.app and SetFlow Academy (the marketplace) at academy.getsetflow.app. Same Vercel deployment, separate auth.

  • 5-role shell architecture (Student / Educator / School Admin / Founder / Member) with superadmin impersonation
  • Bring-Your-Own-Database — AES-256-GCM-encrypted Postgres URLs with self-healing migrations
  • Tori AI with Anthropic Claude Sonnet 4.6 + Haiku 4.5 routing, cost-gated by plan tier
  • Server actions follow an ActionResult convention with Zod parsing + tenant-routed Prisma
  • /dashboard/admin founder cockpit — analytics, economics, live globe, CRM, promo codes, tech docs

4-app pnpm monorepo serving as a unified platform for healthcare lead management, VoIP telephony, AI automation, appointments, and patient intake.

  • Full WebRTC VoIP softphone — SDP munging for cross-platform compat, DTMF, synthetic ringback, hold/resume reinvite queuing, SIP REFER transfer, BroadcastChannel cross-tab dedupe
  • AI call intelligence: Whisper-1 → GPT-4o-mini for sentiment, intent scoring, objection detection, opportunity extraction — wrapped in Opossum circuit breakers
  • Azure OpenAI SMS outreach with conversation memory + progressive 7-day cadence + auto-takeover after 300s of agent inactivity
  • Multi-tenant isolation: UUID-scoped Prisma queries, Auth0 JWT RS256 with custom claims, Supabase RLS, 7-role capability-based RBAC
  • iOS CallKit native UI via APNs VoIP push + Android FCM HIGH priority for real-time call alerts
  • Patient portal with invite-based reg, MFA/TOTP, digital signature capture, jsPDF form generation

Anonymize → Tokenize → Encrypt → Process → Destroy Tokens → Keep Anonymous Output Only. A new privacy infrastructure layer for healthcare, banking, government, and AI.

  • Irreversible anonymization with no recovery key
  • Vault-isolated double-path separation — identity universe vs data universe
  • Session-ephemeral re-linking — identity links self-destruct after sessions
  • Privacy-safe AI processing — models never receive direct identity
/ 04

News Bot — AI News Aggregation

Real-time news fetcher with a custom RAG pipeline using Pinecone and Ollama to summarize articles into concise, categorized insights.

PythonRAGOllama+2
Private
/ 05

Campus Bot — RAG Student Assistant

Campus assistance chatbot with a custom-built RAG pipeline using Pinecone and Ollama for semantic, context-aware responses to student queries.

PythonRAGOllama+2
Private
/ 06

MedAnalyser — AI Medical Insight

AI system that analyzes medical reports and generates simplified, user-friendly health insights from complex clinical data.

PythonAI/MLOCR+1
Private
/ 07

Personal Finance Manager

Finance tracking application for income/expense logging and budget management with an intuitive, minimal UI.

PythonBudgetingUX
Private
06 / Hire me

I build websites, apps,& platforms.

Open for freelance and contract work alongside my own ventures. I design and ship production systems — marketing sites, web apps, mobile apps, internal tools, AI integrations, and full platforms — solo or with your team.

01

Websites

Marketing sites, portfolios, landing pages, e-commerce. Fast, accessible, SEO-ready.

Next.js · Astro · Tailwind · Vercel · Cloudflare

02

Web apps

Dashboards, SaaS products, internal tooling, admin panels, auth systems.

Next.js · React · NestJS · Prisma · PostgreSQL · Supabase

03

Mobile apps

Cross-platform iOS + Android apps with deep native integrations (push, calling, biometrics).

Flutter · Riverpod · WebRTC · APNs · FCM

04

AI integrations

RAG pipelines, AI agents, chatbots, voice transcription, intelligence layers on top of existing data.

OpenAI · Anthropic Claude · Pinecone · Whisper

05

Platforms

Multi-tenant SaaS architecture, real-time WebSocket systems, telephony, scaling, compliance.

Monorepos · Redis · BullMQ · Auth0 · WebRTC

06

Brand & design

Logos, brand systems, marketing assets — pulled into your product end-to-end.

Figma · Brand systems · Marketing collateral

/ How it works

A simple, no-friction process.

/ 01

Intro call

Free 20 minutes. We scope the problem.

/ 02

Proposal

Fixed scope, fixed timeline, fixed price.

/ 03

Build

Weekly demos, live preview link, full ownership of code on day one.

/ 04

Launch

Deploy + handoff. 30 days of bug fixes included.

/ Get in touch

Have a project?
Let's talk.

I reply within 24 hours. Free 20-minute intro call to scope your project. WhatsApp is fastest.

Message me on WhatsApp
07 / Build with me

Let's build a companytogether.

Startups are my obsession. The mess, the speed, the stakes — all of it. I’ve started three companies in under a year and I’ll start another one with you. Whether you have a wild idea and need a technical partner, or you’re an operator who needs a builder, I want to hear it.

Identity and data should never permanently coexist.
A founder principle I happen to live by.

0

Ventures running

<0yr

From class to prod

0 apps

In one monorepo

0+

Integrations shipped

/ I’m open to

Joining you as CEO, CTO, or co-founder.

  • Day-zero technical co-founder — I bring the engineering, you bring the wedge.
  • CTO role if you’ve raised or have signed LOIs and need to ship fast.
  • CEO / operator co-founder if you’re a deep technical expert who hates the business side.
  • Cross-border builds — I run a company in the UK remotely from the US, I know the playbook.

/ What I bring

An operator, not a contractor.

  • Full-stack engineering

    Web, mobile, AI, real-time, infra — architected a HIPAA-compliant healthcare CRM from zero and shipped it to production.

  • Multi-venture operating

    Three companies running today across SaaS, healthcare, and UK care services.

  • AI-native instincts

    RAG, agents, voice, embeddings, vector stores — production-grade, not demo-grade.

  • Product + design

    I’ll design the brand, the marketing site, the product, and the founder narrative.

  • Speed

    Class assignment to enterprise-grade production system in under a year.

  • Compliance mindset

    HIPAA, encryption, RBAC, audit logging — architectural, not policy-bolted.

/ What I’m looking for

A real partner.

  • Domain experts

    You know an industry deeply — healthcare, finance, defense, legal — and you need a builder.

  • Operators with networks

    You can close enterprise deals, recruit talent, or open doors I can’t.

  • Conviction + follow-through

    You don’t need permission to ship. You finish what you start.

  • Sectors that matter

    AI infrastructure, healthcare, education, security, privacy, fintech, defense, climate.

/ Hard nos

Things I won't build.

  • Pure crypto / token-speculation plays.
  • Surveillance, data-broker, or attention-maximizing products.
  • Anything that needs me to stop building — I write code daily.

/ Next step

Pitch me. Or invite me to pitch you.

WhatsApp is fastest. Tell me what you’re building, what you need, and what stage you’re at. I reply within 24 hours.

Research · Notice of originality

/ 08 — Research

The Universal
Privacy Engine.

In progress — actively under development·Invented · All rights reserved

A privacy-first computing architecture where identity is destroyed before processing.

An independent invention: a zero-knowledge data platform where identity is destroyed before processing, vault-isolated, and session-ephemeral. Reproduction or use of the architecture requires written permission.

01 Anonymize02 Tokenize03 Encrypt04 Process05 Destroy Tokens06 Anonymous Output
Background · The person
09 / Foundations

Education, certifications, and leadership.

/ Degree

Bachelor of Science in Computer Science

Midwestern State University · Wichita Falls, TX

Expected December 2026

/ Coursework

Data StructuresObject-Oriented ProgrammingHigh-Performance ComputingSoftware EngineeringArtificial IntelligenceLogic DesignNetworks

/ Certifications

  • The Complete 2024 Web Development Bootcamp — Dr. Angela Yu (in progress)
  • Software Development from A to Z — Karoly Nyisztor
  • Python (Basics) — HackerRank

/ Leadership & Activities

  • Founder & CEO — SetFlow (getsetflow.app)
  • Co-Founder, COO & CTO — GoodFellow Support Services Ltd
  • Member — Association of Computing Machinery (ACM), Midwestern State University
10 / Off the keyboard

What I do when I'mnot coding.

I train hard. Daily. Combat sports keep me sharp, the gym keeps me strong, music keeps me grounded. The bansuri is from home — Sri Lankan roots in a Texas garage.

/ 01

Combat

  • Boxing
  • MMA
  • Brazilian Jiu-Jitsu
  • Karate
/ 02

Strength

  • Gym
  • Bodybuilding
/ 03

Court

  • Badminton
/ 04

Music

  • Guitar
  • Bansuri — bamboo flute

/ Discipline as a love language

I treat training the way I treat shipping — daily, obsessive, joyful. Combat sports build focus under pressure. Music keeps me honest about beauty. Both feed the engineering.

/ StackBody + Mind + Code
11 / Words

What people say.

Sanithu moves ideas into production fast, with taste.

Bryln McCoy

Business Owner · McCoy's Roofing

He takes a deep understanding of computer science into goals to bring concepts to reality.

Bailey Tate

Friend / Peer

The chillest guy I ever met.

Ethan

Friend

/ 12 — Resume

Resume — printable, ATS-ready.

Single-page-portrait PDF. Mirrors the work on this site, formatted for recruiters and ATS parsers.

● Updated May 2026·3 pages·212 KB · PDF
Let's talk
13 / Contact

Let's work together.

Internships, full-time roles, founder collaborations, or research partners — I am open to all of it. I respond within 24 hours.