Projects
Open-source security tools and a product in development, covering shadow AI visibility, SOC automation and audit evidence for AI-assisted code.
2026In development
Greyron
GitHub App for AI-assisted code review and SOC 2 change-management evidence
- Collects pull-request metadata and detects likely AI-assisted changes.
- Enforces risk-tiered review through a GitHub status check, so higher-risk AI-assisted changes get extra scrutiny before merge.
- Keeps a tamper-evident evidence log, a per-tenant hash chain with KMS-signed exports, for SOC 2 change-management audits.
- Uses pull-request metadata only and never reads or stores source code.
Stack Python, Terraform, AWS (DynamoDB, KMS, S3, CloudFront), GitHub Apps
2026Open source
Argus
AI security posture assessment tool
- Finds shadow AI through OAuth inventory and DNS analysis, then classifies each tool across seven security risk factors, including data retention, compliance certifications, and encryption standards.
- Generates risk scores with an Approved, Conditional, or Prohibited classification.
- Maps findings to ISO 42001 and the OWASP LLM Top 10 and produces automated PDF reports. It targets the AI governance gap that enterprise tools solve at six-figure cost, with no accessible mid-market alternative.
Stack Python FastAPI, PostgreSQL, React, Microsoft 365 and Google Workspace OAuth
2024Open source
Pyzuh
Python library for the Wazuh SIEM
- Wraps 150+ Wazuh SIEM API functions covering user management, agent inventory, and security statistics.
- Reduces SOC automation development time.
Stack Python, Wazuh API