Work

Proof of work

Two kinds of evidence sit here. The flagship is a named showcase of my own work, described in full. The engagements beneath it are rendered by domain and outcome. Status is stated plainly: nothing here is claimed beyond what was built.

Flagship — built end to end

A regulated controls-testing platform

The flagship is a four-service platform for regulated controls testing, architected and shipped end to end. It carries audit reasoning traceable to the controlling standards and keeps client evidence off shared LLMs entirely — zero client-evidence egress. The whole platform was built in under six months, with more test code than production code.

  • Java 25 / Spring Boot multi-module backend; Flutter Web frontend.
  • Rust ETL streaming 10GB+ evidence files; Rust-on-Lambda serverless surfaces.
  • Postgres, bitemporal XTDB, Memgraph knowledge graph, and Redis.
  • Reasoning traceable to the controlling standards; zero client-evidence egress to shared LLMs.
  • Every change adversarially reviewed and cryptographically signed, from first spec to production.
  • More test code than production code.
Java 25Spring BootFlutter WebRust ETLRust-on-LambdaPostgresXTDBMemgraphRedis
Recent systems — chosen for the runtime

Three Rust-serverless architectures

Where the problem called for spiky, low-latency, zero-idle-cost serverless, the stack was Rust on Lambda over serverless storage. Three built end to end:

White-label e-signature

eSign

Send any PDF for signature, collect legally valid signatures from parties who never create an account, and return a signed document plus a tamper-evident certificate. Rust on Lambda because signing traffic is spiky — it has to wake instantly and cost nothing between bursts — with tamper-evidence built on symmetric, post-quantum-durable cryptography.

Gated confidential room

Investor data room

A tiered-access room serving confidential materials to named parties, with authentication enforced at the edge and re-verified in depth. Rust on Lambda at zero idle cost, so a low-traffic room costs nothing to keep open and wakes with no cold-start penalty.

Cap-table + equity ledger

Equity cap-table engine

An auditable ledger of issuances, SAFEs, and equity grants built for diligence, where a fully executed document becomes a retention-locked, tamper-proof record the moment both parties sign. Rust on Lambda over serverless, WORM-capable storage — no database server to operate.

Selected engagements

Decades of work, by domain and outcome

Cybersecurity

A FedRAMP-High platform

Contributed across three product teams spanning data-security-posture management (DSPM), cloud-native application protection (CNAPP), and a unified AI surface — building high-throughput services in Rust and Kotlin over OpenSearch and Postgres, under continuous-authorization constraints.

Industrial IoT

Enterprise device discovery

Owned end to end the first capability to bridge modern cloud services with legacy on-premises systems for secure, multisite device discovery — delivered under uptime and compliance constraints, and adopted as the template for migrating further legacy features to the cloud.

Healthcare imaging

Imaging analytics platform

Harmonized DICOM and radiology-information-system data into a single queryable operational model, then built a scheduled-versus-actual comparison that surfaced hidden imaging-schedule inefficiencies — seeding a broader vision for continuous, model-based operational visibility.

Healthcare security

Endpoint incident response

Built an endpoint tracking and incident-response system used by hospital security teams during active threat events, architecting the telemetry pipeline that held up under enterprise alert volumes.

Medical-imaging AI

Medical-imaging AI backend

Built AI-model parsing services and custom DICOM decoding that reached thousands of practitioners, and led customer pilot integrations as the solutions-engineering bridge to early design partners.

Engineering analytics

Engineering-velocity analytics at scale

Built multi-source ingestion from developer tooling — version control and issue tracking — powering engineering-velocity analytics, and carried the pipeline to enterprise scale serving thousands of engineering organizations.

Education-technology ML

Automated language assessment

On the ML team building automated language assessment, delivered ETL pipelines and validation and ingestion APIs that scaled to very high exam volumes.

Cross-border commerce

Cross-border commerce platform

Built a custom inventory and invoicing system with UPC-scanning mobile tooling on cloud infrastructure, and grew the operation to scale.

Core-application AI

Inference you can afford to run at scale

I build AI into the core of the product — chat, extraction, analysis, and scoring — and engineer the inference to be cost-efficient from the first line. Unit costs are metered as a first-class part of the pipeline, inference is reduced to the smallest surface that still does the job, deterministic paths handle everything that never needed a model, and expensive compute is spent only where it produces something the customer can sell.

It is not a new discipline for me. I built AI-model parsing services and custom DICOM decoding that reached thousands of medical practitioners, and I build AI into the core of my own products — the same bet every time: models where they earn their cost, deterministic code everywhere else.

Start a conversation

If your work lives in a regulated, high-stakes, or operationally complex domain, that’s where I’m built to operate. Tell me what you’re trying to ship.