Projects

Open-source security tools and a product in development, covering shadow AI visibility, SOC automation and audit evidence for AI-assisted code.

2026In development

Greyron

GitHub App for AI-assisted code review and SOC 2 change-management evidence

  • Collects pull-request metadata and detects likely AI-assisted changes.
  • Enforces risk-tiered review through a GitHub status check, so higher-risk AI-assisted changes get extra scrutiny before merge.
  • Keeps a tamper-evident evidence log, a per-tenant hash chain with KMS-signed exports, for SOC 2 change-management audits.
  • Uses pull-request metadata only and never reads or stores source code.

Stack  Python, Terraform, AWS (DynamoDB, KMS, S3, CloudFront), GitHub Apps

2026Open source

Argus

AI security posture assessment tool

  • Finds shadow AI through OAuth inventory and DNS analysis, then classifies each tool across seven security risk factors, including data retention, compliance certifications, and encryption standards.
  • Generates risk scores with an Approved, Conditional, or Prohibited classification.
  • Maps findings to ISO 42001 and the OWASP LLM Top 10 and produces automated PDF reports. It targets the AI governance gap that enterprise tools solve at six-figure cost, with no accessible mid-market alternative.

Stack  Python FastAPI, PostgreSQL, React, Microsoft 365 and Google Workspace OAuth

2024Open source

Pyzuh

Python library for the Wazuh SIEM

  • Wraps 150+ Wazuh SIEM API functions covering user management, agent inventory, and security statistics.
  • Reduces SOC automation development time.

Stack  Python, Wazuh API