Projects we’ve shipped. Architecture to deployment.
Security Research — Vulnerability Discovery & Disclosure
Source audits, cloud platform testing, and cryptographic spec review across production infrastructure and upstream open source. Most findings are reported privately; CVE-2026-46386 is one that is public.
Kubernetes Ruby on Rails Go OpenStack Semgrep AFL++ MITRE ATT&CK
Offensive security across managed Kubernetes platforms, upstream open source, and cryptographic implementations: black-box testing, white-box source audit, supply chain review, and conformance against FIPS, RFC, PKCS #11 and KMIP requirements. Findings are driven to a working proof of concept and composed into end-to-end attack chains mapped to MITRE ATT&CK, rather than delivered as a severity list. The bulk of this work is reported privately under engagement and program terms and cannot be detailed publicly. CVE-2026-46386 in OpenProject is a publicly citable sample of it.
An AI-powered inbox for startup CEOs that reads everything and surfaces only what matters. Solo-built, currently in private beta.
Next.js 15 TypeScript PostgreSQL Redis Claude API AWS
Reads every email, Slack message, and calendar event. Classifies by strategic priority. Drafts voice-matched responses. Generates morning briefs and weekly strategic reflections. Built as an agentic-first company: 1 human + AI agents running classification, drafting, scheduling, and infrastructure pipelines. Profitable unit economics with optimized AI routing (Sonnet for strategic, Haiku for tactical).
Open-source tool that visualizes container image structure, SBOMs, signatures, and vulnerabilities. Shipped in 2 weekends, 10 releases.
Go Svelte 5 Tailwind CSS 4 Trivy Cosign SLSA
Built because verifying a container’s supply chain required 7 different tools and 15+ commands. Visualizes layers, manifests, attestations, VEX documents, and signatures with integrated Trivy vulnerability scanning and VEX cross-referencing. Complete Svelte 5 rewrite with TypeScript. Supply chain artifacts signed with Cosign and attested with SLSA Provenance.
Platform for managing millions of connected devices. Scaled 100× to 10K msg/sec while maintaining 99.95% uptime over 2+ years.
Go TypeScript AWS Kubernetes MQTT DataDog OpenTelemetry
Introduced full observability stack (OpenTelemetry → DataDog + PagerDuty), reducing false-positive alerts by 95%. Processed billions of events across millions of connected devices. Designed AI integrations with OpenAI and Claude.
SLX.cloud — Cloud IDE for Multicore C/C++ Optimization
Brought a desktop compiler analysis tool to the browser as a SaaS product. Go-live in under 3 months. 65% of qualified leads at peak. Company acquired by AMD/Xilinx.
Eclipse Che Docker Kubernetes AWS D3.js clangd
SLX.cloud analyzed C/C++ code for parallelism opportunities, cache bottlenecks, and functional dependencies — then generated optimized OpenMP code automatically. Built on Eclipse Che with custom workspace stacks, D3.js visualizations for code analysis graphs, and a clangd language server for in-browser autocomplete.