Our Work

Some of what is below is ours: designed, built and operated by Cyberfu. Entries marked Experience are from my earlier career. I would rather show you working things than talk about theory.

In development

Mocktail

Own product · Vanilla JavaScript, no framework · v0.9

The problem. People who sell API products have a demo problem. The buyer does not want a Postman collection; they want to see their own use case working, today, without a sales engineer on the call.

What we built. Paste your API payload and it becomes a form with sensible field types. Pick a browser or phone frame, brand it, and the demo plays live while you edit: the request updates line by line and the response types itself out, with realistic latency and both success and failure paths.

The name is the idea. All of the product experience, none of the backend: a Mocktail looks and feels like the real thing, with none of the risk. Every demo packs into a single link that carries the whole demo inside it, so nothing is stored on any server. v0.9 is deliberately single-user; workspaces and viewer analytics come next.

Vanilla JSURL-encoded stateProduct designAPI sales
Shipped

Native Sailfish OS apps

Five apps, three shipped · QML, Silica, Qt · Jolla Phone

The context. Murat carries a Jolla Phone running Sailfish OS, a genuinely independent Linux phone. The platform has gaps, so we filled them with native apps, built to a standard other people can use.

  • enteauth (v1.1): a two-factor authenticator for Ente Auth, with login, PIN lock and an end-to-end encrypted vault handled by a small C helper. The wire protocol was verified live against the real API before writing any app code.
  • zaptecfish: control for a Zaptec home EV charger. Live charger state, start, stop and restart, and quiet re-authentication when the API's 24-hour token expires. The command maps were read from the vendor's live endpoint, not guessed from forum posts.
  • sailddit (v0.2): a Reddit reader. Anonymous Reddit access in 2026 is effectively RSS-only, so it ships as an RSS-backed reader, with the hostile API surface documented along the way.
  • octofish: Octopus Agile electricity rates on the phone. Colour-coded half-hourly prices for all 14 UK regions, with find-my-region by postcode, all over a public API that needs no key.
  • osmfish: survey businesses into OpenStreetMap from the phone. Offline-first drafts in SQLite, then real OSM edits through the write API, attributed to your own OSM account.

Why this matters to you. One habit runs through all of them: check how the thing actually behaves before trusting it. That is exactly how your vendor integrations get treated.

QMLSilicaSRP cryptoOAuthIoT APIs
Live in production

ArchiveGaza.org

Public-interest archive · Astro 5, Leaflet, markdown · live at archivegaza.org since 2026-08-30

What it is. A public-interest website archiving Palestinian culture and the documented historical record: 43 culture entries covering food, tatreez, music, poetry, celebrations, places and language, a sourced 63-event timeline running from 3300 BCE to August 2026, a historical map gallery with an interactive map, and a 13-case claims-and-evidence ledger.

How it was built. It is Murat's passion project for his wife, Lara, put together with agent-assisted research: three research passes over the timeline, the misinformation ledger and freely-licensed culture media, with every claim source-verified and retractions linked. Site text is CC BY-SA 4.0, and an Arabic edition led by Lara is planned next.

Why it is evidence. It is the evidence-first method Cyberfu sells, applied to a content-heavy site: content modelling, media licensing discipline and maps, end to end on an Astro stack. Humanitarian value is the point; revenue is not a purpose.

AstroLeafletMarkdownResearchCC BY-SA
Live in production

prayertimes.tr

Own product · Go, Astro, REST API · live at prayertimes.tr since 2026

The problem. Turkey's prayer times are published officially by Diyanet, but the data is awkward to consume and most existing sites bury the answer in adverts.

What we built. A Go API over the official data with an Astro front end, covering all 81 provinces and 869 towns, running on infrastructure we pay for and look after. A freemium tier with self-service signup is on the way.

Why this matters to you. It is our own product, at our own cost and risk. The same care we put into it is what you get on your project: take an official or vendor data source, wrap it in a clean API, and keep it running.

GoAstroREST APIProduction ops
Experience

Payments APIs at Orbital

Earlier work · Payments, Node.js · demo live at getorbitaldemo.cyberfu.co.uk

The work. Building against Orbital's payment products: hosted payment page deposits, rapid deposits, an embedded payment page, and API-driven invoicing.

The demo. The public result is getorbitaldemo.cyberfu.co.uk: a working demo application created so clients could understand how the product and its API work in something much closer to real life than a documentation page. Each flow can be walked end to end, with realistic requests, responses and payment states.

What it demonstrates. Taking a payments API and making it tangible: authentication, the happy path, the failure path, and a presentation that lets a non-technical stakeholder watch what is happening to their money at every step.

PaymentsAPI integrationDemos
Experience

Payment orchestration at Checkout.com

Earlier work · Orchestration, fintech · global merchants

The work. Murat worked on ProcessOut, Checkout.com's payment orchestration product: many payment providers behind one clean API, so merchants never rebuild their checkout to add or switch acquirers. He led technical implementations for global merchants and managed the full lifecycle, acting as technical consultant and advisor on REST API integrations and complex payment architectures.

The details. When implementations hit trouble, he investigated and resolved the blockers by analysing backend logs and gateway responses, and owned post-implementation support and incident resolution afterwards, with deep troubleshooting and root-cause analysis. He bridged the gap between technical and business stakeholders with clear documentation and architectural walkthroughs to reduce integration friction, and partnered with Product and Engineering to turn merchant feedback and integration trends into roadmap priorities and product improvements.

What it shows. Orchestration is integration work where the details really matter: idempotency, webhooks, failure modes, and money that has to reconcile. It is also merchant-facing work, and it taught him to make complicated integration stories simple. That experience sits behind the way Cyberfu handles a client's payment integrations today.

OrchestrationREST APIsPSP integrationsIncident resolution
Experience

WhatsApp Payments at Facebook

Earlier work · Product Operations Analyst · P2P payments: UK, EU, India

The work. Murat was a Product Operations Analyst on WhatsApp payments, working across the UK, EU and India markets. He did product development for P2P payments, ran UX research and beta testing for products still in development across Payments, Oculus (Quest) and Meta Portal, and managed partnerships with several banks as integration partners, collaborating with NPCI, the Indian governing body, to ensure 100% local legal compliance.

The scale. The India P2P UPI product launched to 500 million users. To run operations locally, Murat established a Product Operations presence in India, hiring and training four analysts to take over the project, which cut partner query turnaround time by 30%. When Facebook consolidated its payments projects, he handed the UK/EU product over to Facebook Pay Engineering.

What it shows. Payments across three regulatory regimes, from research to launch to handover, and a team built and left behind cleanly. That is the depth behind the integrations Cyberfu builds today.

PaymentsP2PUPIPartnershipsTeam leadership
Experience

Google Pay at Google

Earlier work · Solutions Engineer · EMEA

The work. Murat was a Solutions Engineer on Google Pay, serving as a technical implementation consultant for banks and financial institutions across EMEA as they onboarded to the platform. He conducted API implementation reviews, bug triaging and regression testing, so that not one launch-blocking issue reached an integrated partner, and provided consultation and accreditation to mobile OEMs to ensure adherence to Google's behaviour and standards.

The results. Working with Business Development, he upsold features such as flight tickets and Membership Passes, achieving 90% of the annual new business target. He led an optimisation project with Samsung to enhance NFC performance for mid-range Galaxy devices, reducing customer service inquiries by 10%, and acted as the SME contact for the Google I/O and Liverpool Stadium ticketing integrations, increasing client adoption by 15%.

What it shows. The same payments work from the other side of the table: helping banks and device makers implement the stack properly, and being accountable when it launches.

Google PayAPIsOnboardingNFCEMEA

Your project could be next on this page.

Tell us what is broken