Skip to content
Rómulo Felizola

Web development · Application security

What you see
is what I build.

This page isn't an example of my work: it is my work. Load it, look at all of it, and if you like how it works, that's exactly what I build for your business.

Evidence

What your site would have

Six things this very page does, and yours would do the same. These aren't promises: they're its real numbers, measured on every release. If one gets worse, it shows up worse.

  • It opens before people give up waiting

    29.1 KB An average page weighs 2,000–3,000 KB. This one weighs 29.1.

  • It works even on a bad connection

    0 KB There are no scripts to download and wait for. The text is there from the first moment.

  • It doesn't eat your mobile data

    84 KB That's my photo. The original was 722 KB — nine times heavier, to look the same.

  • It reads with sunlight on the screen

    18:1 The text contrast. The international standard asks for 7:1 at its highest level.

  • Google understands what this is

    2 Languages, each with its own address. The previous site hid the English where search engines couldn't see it.

  • Nobody can inject code into it

    0 Scripts allowed. The security policy blocks every one of them, and it's verifiable.

Want to check? Press F12 and look at the Network tab. Or run Lighthouse on it.

Services

What I build

One person accountable for the whole cycle. No designer blaming the developer, developer blaming the host, and nobody answering for the result.

Your customer won't wait eight seconds

They leave before seeing what you sell, and you never find out they were there. I build in static HTML served directly, so the first screen shows up with nothing delaying it. That matters more than it sounds when a good share of your visitors arrive on a phone with limited data.

Your data and your clients' data, actually separated

The expensive failure isn't being attacked: it's one client seeing another one's information. I enforce isolation in the database rather than only in the code, so a query that forgets to filter returns nothing instead of returning what it shouldn't.

Security while it's being built

Reviewing it at the end means finding the problem when fixing it costs ten times more. Headers, content policy and tested authentication go in from day one, not as a farewell audit.

Published, not "almost there"

Plenty of projects die finished and unreleased. I close with the site live, working, and with a way to know whether it's doing anything for you. A site nobody measures is a site nobody learns from.

Portfolio

Two projects, two different kinds of proof

I built one from scratch; the other I migrated without losing a single indexed URL. Open them, read their source, run whatever tools you like on them.

  • jsbrandlab.com

    Open ↗

    8 pages · structured data with pricing · static HTML

    My agency's commercial site. Public pricing, one page per service with its own search intent, and structured data that lets Google show the figure in the result itself. Zero JavaScript shipped to the browser.

    • Astro
    • TypeScript
    • CSS nativo
  • labsbjj.com

    Open ↗

    55 indexed URLs · 41 intact · 11 redirected · 3 retired

    Migration of a jiu-jitsu academy from WordPress to static HTML without losing a single indexed URL, checked against the published site. Six were neither declared in the sitemap nor found by the crawler: they surfaced when the inventory was cross-checked against Search Console, and two would have become 404s.

    • Astro
    • Markdown
    • CSS nativo

Method

How I work

Eight phases, each leaving something verifiable behind. That's what separates knowing several things from improvising at all of them.

  1. 01

    Analysis

    What problem needs solving, and how we'll know it was solved.

  2. 02

    Benchmarking

    What the best in the field do. You don't reinvent what's already solved.

  3. 03

    Design

    Colour and type system with calculated contrast ratios, not estimates.

  4. 04

    Implementation

    Test first, code after. The test defines what should happen.

  5. 05

    Testing

    Automated, plus a security review.

  6. 06

    Measurement

    Speed, accessibility and search visibility, with numbers.

  7. 07

    Infrastructure

    Reproducible deployment, not "it worked on my machine".

  8. 08

    Improvement

    What got measured gets fixed. Then measured again.

Rómulo Felizola

About

Who's on the other side

I'm Rómulo Felizola. I worked as a backend developer at Aion Team (Barcelona, remote) from December 2023 to February 2025: production applications, databases, API integration and fixing real vulnerabilities — input validation, access control, authentication.

Today I run JS Brand Lab, where we build complete digital presence for businesses. This page is the proof of concept for what we sell: if I can't build mine well, I shouldn't be building yours.

I live in Venezuela and work remotely with clients in Spain, the United States and Latin America.

Spanish native · Portuguese C1 · English B2 · Italian B1

  • BA in International Commerce — UIP, Panama
  • Web Application Development — SOC, Spain
  • Ongoing training in ethical hacking and defensive security
See full profile →

Contact

I do this with a team, and it's called JS Brand Lab

If what you've seen here is what your business needs, that's where the packages live — public prices, delivery times, and what they don't include. And if you'd rather talk to me first, before looking at prices, just write.