Selected systems
Work that can be inspected,
not merely described.
Each project starts with a governance problem and ends with something usable: a lab, an evidence runtime, a work queue, a decision model, a control pipeline, a research artifact, or an accountable intervention.
02LIVE DECISION TOOL
IMPACT!
Cyber risk translated into decisions.
An interactive FAIR-informed decision environment connecting modeled loss exposure, control posture, financial consequence, causal explanation, tail-risk exploration, and executive risk communication across analyst, guided, and board views.
Problem Quantified cyber risk still fails if analysts, executives, and boards cannot see how technical assumptions become business consequences and decisions.
Built A linked decision environment with scenario modeling, TEF/vulnerability-driven loss frequency, deterministic Monte Carlo tail exploration, causal traces, guided walkthroughs, financial analysis, and a board-level risk memo.
Inspect Analyst workspace · tail lens · causal explanation · guided mode · board view · assumptions · public source.
Launch IMPACT! ↗
03CHANGE ASSURANCE RUNTIME
ChangeProof
AI can write the change. Prove it deserves to ship.
A profile-driven software change-assurance runtime that combines source discovery, scoped execution receipts, cross-artifact inference, evidence classification, review compression, and explicit validation boundaries across modern and legacy workloads. Built for the IBM TechXchange 2026 Pre-conference Dev Day Hackathon with IBM Bob 2.0.
Problem A requested change can pass its functional test and still be unsafe to release because related source, configuration, schedules, or target-only validation remain outside the ticket.
Built A reusable evidence pipeline that separates executed, observed, and inferred evidence; preserves release holds when acceptance passes but the evidence chain is incomplete; and demonstrates reuse across both an IBM i-style ORDERPRO workload and an unrelated Node/config workload.
Inspect Live Review Workspace · baseline and post-change evidence packs · machine-readable findings · CI evidence freeze · independent REPORT-GW reuse proof · public source.
Built for the IBM TechXchange 2026 Pre-conference Dev Day Hackathon. ORDERPRO is the primary demonstration workload; the evidence pipeline is the reusable product surface.
04AI ASSURANCE RESEARCH
ControlSift
Can a small AI model tell proof from paperwork?
Applied AI assurance research testing small-model approaches to cybersecurity control-evidence classification with a hardened synthetic benchmark, classical baselines, Gemma prompting, QLoRA, failure analysis, and explicit research-governance controls.
Problem Relevant documentation can look convincing without proving a control operated, and an AI experiment can look convincing without justifying the claim made from it.
Built A reproducible research stack spanning benchmark generation and leakage hardening, classical baselines, zero- and few-shot Gemma, QLoRA, strict parsing, Failure Lab analysis, Data and Model Cards, a risk register, and a sealed protocol.
Inspect Public research hub · experiment ledger · report · narrated presentation · release artifacts · source.
Developed through Google DeepMind AI Research Foundations via Mentor Me Collective. Within the controlled Gemma v1.0 experiments, few-shot prompting was strongest and QLoRA did not outperform it; the negative result and version boundary are preserved rather than turned into an artificial AI win.
05CYBER-LOSS CASEBOOK
INQUISITION
Interrogate the loss story
Examines 34 public cyber incidents through cited evidence, source-quality labels, transparent loss assumptions, and bounded FAIR-informed simulation.
Problem Public breach-loss narratives often collapse uncertain facts into false precision.
Built A casebook that keeps sources, evidence quality, assumptions, and quantitative ranges visible together.
Inspect 34 incident cases · citations · source labels · transparent assumptions · bounded simulation.
Launch INQUISITION ↗
06IBM i REMEDIATION CURATOR
IBM i Vulnerability Curator
IBM CVE claim → local fix state → reviewable evidence
IBM's CVE_INFO service identifies CVEs affecting a release, but not whether each correcting fix is applied. The curator resolves IBM bulletin remedies, supplies an ACS-ready SQL evidence kit, compares browser-local PTF and Group PTF exports, and packages expected versus observed evidence.
Problem “Release affected” is not the same claim as “correcting fix absent on this system.”
Built Remedy resolution, SQL evidence collection, local export comparison, and reviewer-ready expected-versus-observed output.
Inspect Live curator · public source · SQL evidence kit. Not a scanner of record or live partition connection.
Open the curator ↗
07CONTROL PIPELINE
GRC Engineering Pipeline
Controls that ship with the system
Terraform, OPA/Rego, OSCAL, signed evidence, and CI/CD enforcement assembled into a verifiable governance pipeline for a regulated workload.
Problem Control evidence is often reconstructed after the fact instead of produced with the system.
Built A policy-as-code assurance chain that preserves passing and failing decisions, signed evidence, and OSCAL-linked control context.
Inspect Terraform · Rego · CI enforcement · signed artifacts · verification paths.
Built through the GRC Engineering Club six-week challenge · 2nd place.
Inspect the pipeline ↗
LABADDITIONAL SYSTEMS & EXPERIMENTS
More systems in the lab
The projects above are the curated front door, not the full inventory. Smaller decision tools, course builds, disclosure experiments, cloud-native evidence work, and newer prototypes stay available without competing with the flagship work for attention.