Systems nominal Enterprise infrastructure · Software · Cyber defense — UTC --:--:--
Orospor Orospor

Founder & CTO — Orospor

Gurcharanjit Singh

Infrastructure · Software · Cyber Defense · Jalandhar, Punjab

I build infrastructure that holds under real load — and platforms that solve problems nobody else has solved cleanly. Founder of Orospor since 2016. We run 12,000+ global nodes, deliver national-scale exam-integrity systems, and engineer the kind of security that lives below the operating system.

12K+Global Nodes
<5msOroLink Latency
99.99%Uptime
2016Founded

The full picture

Engineer, founder, and the person who gets called when the architecture has to hold

I am Gurcharanjit Singh — engineer, founder, and the person who gets called when the architecture needs to hold and the existing tools do not cut it. I started Orospor in 2016 to build infrastructure and software at the kind of quality that enterprise organisations actually need but rarely find from a single team.

My work spans three disciplines and they are not separate. Infrastructure — cloud workstations, bare metal, GPU clusters, edge compute, 12,000+ nodes globally. Software engineering — C++ engine work, C# backend architecture, microservices, real-time systems. Cyber defense — DDoS mitigation, red teaming, zero-trust architecture, SOC operations. The same engineering standard runs through all of it: clear architecture, phased delivery, runbooks your team can own after we leave.

The two things I am most proud of building are OroLink and OroStat. OroLink is a source-available examination delivery protocol built from the ground up for the adversarial environment of high-stakes national exams — not video conferencing adapted, not a lockdown browser bolted on top. Purpose-built and legally admissible, with the full source handed to the organisations that license it — auditable to the last line, but a commercial product rather than free public software. OroStat goes further: it is a below-OS network monitoring appliance that catches the class of exam-centre cheating — a kernel rootkit concealing a remote-desktop session — that defeats every tool which trusts the operating system. We removed the assumption. We watch from the layer the rootkit cannot reach.

I publish security research openly. When I find something architectural — a design characteristic that becomes a weapon under load rather than a traditional bug — I write it up and publish the analysis. The WordPress REST API worker-exhaustion research came from live defensive work: understanding exactly how unauthenticated endpoints bypass every caching layer and collapse a PHP-FPM pool at a few dozen concurrent requests, and exactly how to stop it. The knowledge is more useful public than private.

I turned 37 in July 2026. Orospor turns 10 this year. Neither of us is done.

What we have built

Products

OroLink

Flagship Platform

Secure exam delivery + remote protocol

A source-available examination delivery protocol built for national-scale programs — purpose-built for the adversarial environment of high-stakes exams, not video conferencing adapted or a lockdown browser bolted on. Licensing organisations receive the full source, auditable to the last line — a commercial product, not free public software. Captures what standard screen sharing cannot, giving proctors a complete, unfiltered view of every candidate session, with legally admissible evidence. Runs on any candidate hardware. Also powers OroLink Remote — low-latency enterprise remote sessions with policy-enforced transport and operational telemetry.

Source to LicenseesNational ScaleAny Hardware<5ms Latency
Explore OroLink →

OroStat

Security Appliance

Rootkit-resistant exam monitoring

A below-OS network monitoring appliance for examination centres. When an insider conceals a remote-desktop session with a kernel rootkit, every tool that trusts the OS goes blind. OroStat removes that blind spot — a minimal, read-only VM sits between the physical NIC and the host, inspecting every packet before the host and its rootkit can touch it. Deploy in under 5 minutes per machine. Licensed operators receive the full source for auditor review.

Below OSRootkit ResistantSource to Licensees<5 min deploy
Explore OroStat →

Oro Cloud Workstations

Infrastructure

Dedicated GPU workspaces, globally

Dedicated GPU workspaces with deterministic graphics throughput and secure remote access. Built for VFX rendering pipelines, AI workloads, and compute-heavy engineering that cannot tolerate shared-resource contention. 12,000+ global nodes. 99.99% uptime SLA.

GPU Clusters12K+ NodesVFX / AI
Explore Workstations →

WordPress Attack-Surface Research

Defensive Security Research

How normal endpoints become a weapon under load

A defensive research series documenting how unauthenticated REST API endpoints bypass every caching layer to exhaust PHP-FPM worker pools — and how that availability failure chains into Google search deranking. Written up for operators to find and close their own exposure, with the full defense matrix and a 15-minute hardening checklist. Produced on authorized test infrastructure and submitted for responsible disclosure.

Defensive ResearchFull Defense MatrixResponsible Disclosure
Read the research →

Engineering disciplines

Four practices, one standard

Cloud Infrastructure

Bare metal, DigitalOcean, AWS, GPU clusters, VFX pipelines, edge compute, SAN storage, 12K+ node operations.

Software Engineering

C++ engine modifications, C# backend architecture, microservices, real-time netcode, legacy modernisation, GraphQL, Kubernetes.

Cyber Defense

DDoS mitigation, red teaming, penetration testing, zero-trust architecture, 24/7 SOC operations, below-OS security.

Network Engineering

Cloudflare WAF/CDN, packet-level analysis, UFW hardening, VPC architecture, latency optimisation, protocol design.

Exam Integrity

National-scale secure exam delivery, rootkit-resistant monitoring, below-OS appliances, legally admissible evidence systems.

Security Research

Attack-surface mapping, PHP-FPM exhaustion analysis, WAF/CDN resilience testing, and responsible public disclosure of findings.

Timeline

Ten years, one standard

  1. 2016 Founded Orospor. Infrastructure consulting and software engineering — production-grade delivery, runbook-first handoff, no systems left unowned.
  2. Active 12,000+ global nodes across regions. GPU clusters, VFX rendering pipelines, enterprise remote access. Sub-5ms OroLink latency. 99.99% uptime.
  3. 2026 OroLink & OroStat launched — two purpose-built products for examination integrity, both source-available for auditor review.
  4. 2026 WordPress attack-surface research published — a defensive series on REST API exhaustion and the Google deranking chain.
  5. Now Orospor: enterprise infrastructure, software & cyber defense. Four practices, one engineering standard. Jalandhar, Punjab — operating globally.

“I do not hand over slideware. Every engagement ships as working, observable, owned systems — engineered to hold up under real load. If it cannot survive production, it does not leave my hands.”

— Gurcharanjit Singh, Founder & CTO, Orospor

Leadership

The founding team

Gurcharanjit Singh

Founder & CTO

Engineering lead across infrastructure, software, and cyber defense — the technical standard behind every Orospor engagement and its OroLink and OroStat products.

Nishant Mehta

Co-Founder

Co-founded Orospor with a management background, pairing the company's engineering practice with business and operational leadership.

Contact

Work with the team behind Orospor.

Enterprise infrastructure, secure exam delivery, and cyber defense — tell me what you are building.

Technologies we run
  • Kubernetes
  • Linux
  • Terraform
  • C++
  • Go
  • Rust
  • .NET
  • Kafka
  • PostgreSQL
  • Redis
  • gRPC
  • Zero Trust
  • SIEM
  • NVIDIA CUDA
  • Prometheus
  • HashiCorp Vault
  • GraphQL
  • Nginx