Skip to content

Portfolio

Projects, described by engineering substance

Client names are withheld and no figures are claimed that we cannot evidence. Each profile sets out the problem, the environment we inherited, the architecture we designed, how it was implemented and what changed as a result.

Verified delivery record

Real projects and client reviews from Fiverr

15 delivered projects published on the public Fiverr profile of Salman Rizvi, with buyer reviews reproduced exactly as they appear there.

4.9 / 5 from 65 reviewsLevel 2 SellerVerify on Fiverr →
VoIP and Telephony5.0
“I want to give a huge shoutout for their outstanding assistance in resolving our 3CX system issue. They were incredibly knowledgeable, patient, and quick to respond. Thanks to their expertise, we were back up and running in no time. I truly appreciate the professionalism and dedication they brought to solving this problem. Highly recommended!”

Ordered by buyer

VoIP and Telephony5.0
“Problem was solved in 5 minutes. Thanks”

Ordered by buyer

VoIP and Telephony5.0
“He is the man for our 3CX voice over IP. Very satisfied. Second time we collaborate and we are highly satisfied.”

Ordered by buyer

VoIP and Telephony4.3
“very professional and co-operative. understands your desires and goes beyond to full them...highly recommended”

Ordered by buyer

Email Management5.0
“good and quick solve the problem.”

Ordered by buyer

VoIP and Telephony5.0
“Quick delivery and very responsive. Highly recommended”

Ordered by buyer

VoIP and Telephony5.0
“Thanks again. Always fast and skilled”

Ordered by buyer

VoIP and Telephony5.0
“Well recommended. Went above and beyond expectations. Will buy here again”

Ordered by buyer

VoIP and Telephony5.0
“He's terrific. Got our phone system up when others couldn't.”

Ordered by buyer

VoIP and Telephony5.0
“Great communication, keeping me informed, great attention to detail and in depth knowledge of his domain. Delivered a PBX on AWS, worked well, worked hard to integrate it with the rest of my system. Well done, happy to deal with again.”

Ordered by buyer

VoIP and Telephony5.0
“Superb! Thanks so much..”

Ordered by buyer

VoIP and Telephony5.0
“awesome work i love working with him, fast and communication is very on point. Definitely handled everything correctly and didn't have to ask too much he already knew exactly what i needed in the process of this project. will work again”

Ordered by buyer

Technical Support5.0
“definitely recommend him because he was very fast with the project”

Ordered by buyer

VoIP and Telephony5.0
“He was great and very knowledgeable of what he was doing. Since I knew what I wanted but didn't know the first thing about how to complete it, ssalmanrizvii walked me through it step by step. He was very patient and professional. I will recommend him to others. Thanks, Dennis”

Ordered by buyer

VoIP and Telephony5.0
“excellent and fast work an excellent and fast job I will work with him again without any doubt”

Ordered by buyer

Reviews are published by buyers on Fiverr and are shown here unedited. Buyer usernames are blurred to protect buyer identity; ratings and review text remain visible as published.

Engagements

Selected project profiles

Representative of the work we deliver across telephony, virtualization, cloud and email infrastructure.

Contact center / BPO

Outbound contact-center dialer platform

ViciDialAsteriskMySQLProxmox VE

Challenge

A growing outbound operation was running its dialer, database and recordings on a single server. Agents reported audio breakup at peak, campaign reports timed out, and there was no recovery plan if the box failed.

Environment

  • Single-server dialer carrying agents, database and recording storage
  • One SIP trunk with no failover path
  • No separation between agent traffic and back-office network
  • Backups limited to occasional manual copies

Architecture

  • Dialer nodes separated from the ViciDial web/database tier
  • Database moved to dedicated resources with tuned buffers and log archiving
  • Recording capture offloaded to separate storage with retention rules
  • Second carrier trunk added with failover routing and channel limits
  • Voice traffic placed on its own VLAN with QoS marking

Implementation

  • Baseline capture of busy-hour concurrency, dial ratio and database load
  • Rebuild on a Proxmox cluster with resources reserved for telephony guests
  • Campaigns migrated in stages with a pilot agent group validating each stage
  • DNC handling, retry logic and dispositions reviewed before full launch
  • Scheduled backups with a documented and tested restore procedure

Outcome

  • Agent audio complaints traced to dial ratio and channel saturation and resolved at source
  • Reporting queries no longer contend with live call traffic
  • A single node failure no longer takes the whole operation offline
  • Recording growth is bounded by policy instead of filling the system disk

Distributed services business

Multi-site VoIP consolidation

FreePBXAsteriskGrandstreamSIP trunking

Challenge

Several offices each ran their own phone system with separate providers and inconsistent numbering. Internal calls went out over the PSTN, and no one had a full picture of the numbering or of who could dial internationally.

Environment

  • Independent PBX per site with different vendors and firmware levels
  • Duplicate extension ranges across offices
  • Handsets configured individually with default administrative credentials in places
  • No central call reporting

Architecture

  • Central FreePBX platform with per-site outbound routes and local breakout where required
  • Unified extension plan and DID-to-destination map documented per number range
  • Site-to-site connectivity over VPN for inter-office dialling
  • Zero-touch provisioning templates per handset model
  • Outbound classes for internal, national and international calling

Implementation

  • Numbering and IVR logic documented from each legacy system before any change
  • Pilot site migrated first with the legacy PBX kept ready for rollback
  • Handsets re-provisioned from templates, default credentials removed
  • TLS signalling and SRTP media enabled and verified on live channels
  • Remaining sites cut over in sequence with a validation checklist per site

Outcome

  • Inter-office calls now stay on-net rather than traversing the PSTN
  • One consistent dial plan, IVR structure and reporting view across all sites
  • Handset replacement is a provisioning swap rather than a manual rebuild
  • International dialling is granted by class, not available to every extension by default

Manufacturing / distribution

Virtualization consolidation with tested disaster recovery

VMware vSphereProxmox VEVeeamZFS

Challenge

Business applications ran on ageing physical servers of varying age, with backups that had never been restored. A hardware failure would have meant rebuilding from scratch with no confirmed recovery time.

Environment

  • Mixed-age physical servers, several past end of support
  • Backup jobs reporting success with no restore ever attempted
  • Management interfaces reachable from the general user network
  • No documented recovery point or recovery time objectives

Architecture

  • Clustered hypervisor platform sized with N+1 headroom from measured usage
  • Redundant storage paths and workload-matched performance tiers
  • Separate networks for management, migration, storage and workloads
  • Application-aware backups with an offsite and immutable copy
  • Recovery objectives agreed per service before the design was finalised

Implementation

  • Dependency mapping and measured resource profiling across a full business cycle
  • Migration in waves, starting with low-risk internal workloads
  • Physical sources kept recoverable until each wave was signed off
  • Management plane moved onto a restricted network with role-based access
  • Restore tests executed and the actual recovery time recorded per service

Outcome

  • Recovery is now a rehearsed procedure with a known, documented duration
  • Host maintenance happens without taking applications offline
  • Capacity decisions are driven by measured data rather than server specifications
  • Backup failures raise an alert to a person instead of sitting in a log

Professional services

Corporate email migration and DMARC enforcement

Microsoft 365Google WorkspaceSPF / DKIM / DMARC

Challenge

Mail ran on a legacy hosted mailbox service with no sender authentication. Outbound mail was landing in spam for some recipients, and the domain was being used in spoofed messages.

Environment

  • Legacy IMAP mailboxes with inconsistent client configuration
  • SPF record present but incomplete; no DKIM signing; no DMARC policy
  • Shared administrative credentials with no multi-factor authentication
  • No visibility into who was sending on behalf of the domain

Architecture

  • Tenant, domain and organisational structure defined before migration
  • Mail flow and routing rules mapped for every legitimate sending source
  • SPF corrected, DKIM signing enabled, DMARC introduced in monitoring mode
  • Conditional access and multi-factor authentication on administrative roles
  • Retention and external sharing policies aligned to business requirements

Implementation

  • Full inventory of applications and services sending as the domain
  • Staged mailbox migration with a pilot group and a defined rollback point
  • DMARC aggregate reports reviewed until all legitimate sources aligned
  • Policy moved from none to quarantine and then to enforcement in steps
  • Administrative roles reviewed and shared logins removed

Outcome

  • Legitimate mail is authenticated and aligned across all sending sources
  • Spoofed mail using the domain is rejected by receiving providers under enforcement
  • Administrative access is individual and protected by multi-factor authentication
  • Mail flow and policy are documented rather than held in one person's memory

Retail / e-commerce

Cloud VPS migration for business applications

Cloud VPSLinuxNginxAutomated backups

Challenge

Customer-facing applications ran on an under-specified shared host with unpredictable performance and no maintenance window. Deployments were manual and there was no staging environment.

Environment

  • Shared hosting with no control over the underlying resources
  • Manual file-level deployments directly to production
  • TLS certificates renewed by hand and occasionally missed
  • Backups provided by the host with no verified restore path

Architecture

  • Right-sized VPS instances derived from measured traffic and resource usage
  • Separate staging environment mirroring production configuration
  • Reverse proxy with automated certificate issuance and renewal
  • Scheduled off-instance backups with retention and pruning rules
  • Firewall policy with administrative access restricted to known networks

Implementation

  • Application dependencies documented and reproduced on the new platform
  • Data pre-seeded and kept in sync ahead of the cutover window
  • DNS time-to-live reduced in advance so the switch was fast and reversible
  • Cutover limited to the final delta sync, traffic switch and validation checklist
  • Legacy host retained read-only until sign-off

Outcome

  • Performance is now a function of resources the business controls
  • Changes are validated in staging before they reach customers
  • Certificate expiry is automated and monitored rather than remembered
  • Restores have been tested from the new backup target

Healthcare administration

Network segmentation and infrastructure hardening

VLAN segmentationFirewall policyMFAMonitoring

Challenge

A flat network placed servers, workstations, phones and management interfaces in the same broadcast domain. Any compromised endpoint had a direct path to critical systems, and voice quality suffered during data bursts.

Environment

  • Single VLAN carrying all traffic types
  • Hypervisor and switch management reachable from user devices
  • Shared administrative accounts without multi-factor authentication
  • Monitoring limited to basic host up/down checks

Architecture

  • Separate VLANs for servers, users, voice, guests and management
  • Default-deny policy between segments with documented exceptions
  • QoS marking so voice traffic is prioritised over bulk data
  • Multi-factor authentication on every administrative entry point
  • Service-level monitoring with predictive alerts on capacity and certificate expiry

Implementation

  • Traffic flows captured before segmentation so exceptions were based on evidence
  • Management plane isolated first, then workload segments introduced in stages
  • Individual administrator accounts issued and shared logins retired
  • Runbooks written for the top failure scenarios and escalation paths agreed
  • Change log, IP plan and topology diagram handed over with the environment

Outcome

  • A compromised workstation no longer has a direct path to critical systems
  • Voice quality is stable through data-heavy periods
  • Administrative access is attributable to an individual engineer
  • Alerts now fire ahead of capacity and certificate-related outages
Project profiles are anonymised at client request. Verifiable delivery history and client feedback are available on our Fiverr portfolio.

Ready to scope the work?

Share your environment and objectives. You will get an engineering response covering scope, approach and considerations.