Principal Engineer building cybersecurity platforms — distributed systems at serious scale (6M+ endpoints, ~4M requests/minute, 99.99% availability), real-time threat scoring at sub-200ms p95, and a governed semantic data layer over that telemetry. I build applied AI-security systems end to end, including AgenticGuard, an endpoint sidecar for MCP/AI-tool discovery, prompt-injection detection, and tamper-evident audit. 20+ years designing, building, and operating cloud-native distributed systems.
Current interests: AI-agent governance and tamper-evident audit (MCP discovery, prompt-injection detection, safe-agent contracts), accountability limits for delegated agentic action, offline/edge ML with ONNX, structural measurement of undeciphered writing systems, and reliability engineering that treats uncertainty honestly.
| voynich-transfer | A reproducible metric for structural similarity between regions of an undeciphered text, applied to the Voynich Manuscript. 21 preregistered experiments, Python + NumPy only. Not a decipherment — a measurement any future theory has to explain. |
| indus-script | Machine-readable catalogues of 1,269 Mohenjo-daro/Harappa seals (Mackay + Marshall), 531 plate-codings, and 90 held-out validated constraints, with a pipeline comparing Indus sign sequences against Sumerian, Egyptian, and Linear A/B. No decipherment claimed — results are largely negative and corrections are kept in place, not deleted. |
| tallystick | An adversarial harness for accountability in delegated AI agent action: 850 scenarios, 34 adversarial classes, 18 adjudication baselines. Finds a conservation boundary — evidence-based mechanisms can resolve whether a party diverged from the record, never why, at no extra cost. |
| macrocanary | A public macro-risk dashboard that doubles as a privacy-minimized bot-detection canary. Real traffic, honeypot telemetry, and retrospective fleet-level campaign analysis on Cloudflare Pages/Workers/D1. Live |
| LocalGuard | A plant-inspired host IDS for air-gapped environments: hybrid heuristics + offline ONNX ML in C#/.NET, watching files and the Windows Registry for persistence and anomalies. |
| durabl | Privacy-first cycling durability analytics. FIT files analyzed entirely in-browser (Blazor WebAssembly) — fresh-vs-fatigued performance with explicit signal-quality reporting. |
I write about engineering judgment, AI security, and systems thinking at Medium:
- Your AI Agent Cannot Defend Itself With a Log It Wrote — why a self-authored execution log isn't accountability evidence, the question tallystick's harness makes precise
- The Voynich Manuscript — You Can't Read It. You Can Still Measure It. — the structural-similarity measure behind voynich-transfer, for a general audience
- Agent Workflows Are Rediscovering Durable Execution — the missing layer is definitions, execution records, identity, policy, and replay
- The Human Consensus Protocol in Your Browser — why "click = consent" is broken, and why AI agents make it urgent
- Using AI Against AI (Without Fooling Ourselves)
- Code Is Becoming Abundant. Judgment Is Not.
- The Faulty Screw Principle — how "normal" systems survive on imperfection
C# / .NET · Python · Go · TypeScript · AWS (ECS Fargate, Kinesis, EventBridge, Lambda) · Kubernetes · Terraform · Kafka · ONNX
