Advanced Data Protection↗
Vectis protects sensitive data while preserving the operations an application actually needs. I help teams decide where that protection belongs and integrate it into systems that already have identity, storage, key management, and operational constraints.
- Architecture and threat-model reviews.
- Deployment and integration through HTTP, CLI, SDKs, and automation tooling.
- Custom storage integrations and private builds when the environment requires them.
- Applied cryptography using established libraries and explicit protocol boundaries.
- Maintenance and support defined for the engagement.
Technical collaboration can also include early design feedback and joint work on integrations that are useful beyond one deployment. A review reduces uncertainty; it does not guarantee security or compliance.
Operational Simplicity↗
Kanso makes operational friction visible and gives teams a way to measure its cost. The work begins with evidence and a defined system boundary, not a promise of savings.
- Training on friction detection, classification, and quantification.
- Setup of the Friction Ledger for the system in scope.
- Facilitation of the first Friction RCA.
- A baseline Kanso Index using a consistent team, system, period, and cost basis.
- Periodic reviews adapted to the Lite, Core, or Full implementation level.
The result is a working measurement process and a set of countermeasures the team can evaluate over time.
Secrets and PKI Infrastructure↗
I work with Vault, OpenBao, certificate authorities, and the infrastructure around them across on-premises, datacenter, cloud, and open-source environments.
- High-availability and disaster-recovery architecture.
- Upgrades, migrations, policy design, and authentication design.
- Certificate lifecycle automation with cfssl, OpenSSL, and related tooling.
- Dynamic secrets, credential rotation, and removal of credentials from repositories and pipelines.
- Architecture reviews against an explicit threat model.
- Network and access boundaries using controls such as
pfandiptables.
This can include a migration from Vault to OpenBao when licensing, governance, or an open-source strategy makes that a suitable choice. The right destination still depends on the operating context.
API Security and Quality↗
Security findings are more useful when they are reproducible and connected to the system’s assumptions. I combine contract testing, dynamic analysis, load measurement, and threat modeling to produce evidence that engineering teams can act on.
- OpenAPI contract testing with Schemathesis to detect drift between the specification and the implementation.
- Dynamic assessment with OWASP ZAP against a disposable, isolated instance.
- Load and latency baselines with k6 to measure current behavior and detect regressions.
- Native fuzzing for parsers and validation boundaries.
- SAST, DAST, and SCA controls integrated into CI/CD.
- A written report covering evidence, assets, trust boundaries, assumptions, and residual risks.
These activities do not by themselves constitute a formal penetration test, certification, or guarantee that a system has no vulnerabilities.
Workflow↗
problem -> conversation -> scoped proposal -> delivery -> handoff
- You describe the problem, its context, and the constraints around it.
- A short conversation establishes whether the work is a good fit.
- A scoped proposal defines deliverables, assumptions, boundaries, and limits.
- The engagement produces a review, plan, integration, or operational baseline.
- The handoff records decisions, documentation, and residual risks.
How I Work↗
Just a message [email protected]
Most engagements start from a symptom, not a clean specification.
Disclaimer↗
Vectis and Kanso are open source, and that will not change. What isn’t on GitHub is time, judgment, and accountability under someone else’s constraints — that’s what I offer commercially.