Demand-side platform · Ad techlive
Moloads
An outcome-oriented DSP for app marketing in India — answers OpenRTB auctions in milliseconds, controls budgets across instances and attributes every conversion back to spend. Live with brand campaigns.
- role
- CTO, brandMongo — architect & lead
- period
- 2026 – present
- 700+
- automated tests
- 22
- API controllers
- 4
- role levels
- ms
- bid latency budget
- CI-gated
- auto deploy + rollback
- Live
- brand campaigns
# the idea
Own the buy side of programmatic advertising: accept a bid request, decide in milliseconds whether that impression is worth buying for a campaign, and close the loop all the way to a paid conversion — so advertisers pay for outcomes, not impressions.
# what I built
- OpenRTB 2.x bid endpoint with schema validation and a hard processing deadline (tmax).
- Bidding engine: banner-size matching, priority-weighted campaign selection, bid floors and an ML bid optimiser.
- Targeting on geo, device, OS, browser, time-of-day, app/site, audiences and first-party segments.
- Private marketplace deals — private-auction and preferred deals, attributable per deal and per supply route.
- Atomic per-impression budget reservation in Redis, so daily and total caps hold across every Cloud Run instance.
- Signed win notices, idempotent win recording, click tracker, impression pixel and server-to-server postback attribution.
- Fraud checks — IP/UA heuristics, per-IP rate limiting and blocklists; supply-chain validation; GDPR erasure.
- Four-role access model (super admin, account manager, agency, client) — margin fields stripped server-side for external roles.
- Report builder and time series across the full funnel: bids → wins → impressions → clicks → conversions → spend → revenue → ROI.
- Admin UI with advertisers, campaigns, creatives, offers, deals, rules, segments and monitoring.
# key decisions
- One FastAPI service instead of microservices — the latency budget is milliseconds, and network hops are the enemy.
- Deploys gated on a green CI run (700+ tests on SQLite and PostgreSQL, migrations and a live-bid smoke test), with automatic rollback on failed health checks.
- Security boundaries enforced in the API, not the UI — an agency literally cannot receive margin data.
- Redis for cross-instance state (budgets, frequency caps, rate limits); PostgreSQL as the system of record.
# stack
- Python
- FastAPI
- PostgreSQL
- Redis
- Alembic
- Cloud Run
- Cloud SQL
- Cloudflare
- GitHub Actions