DCYFR Labs builds @dcyfr/ai — an open-source AI agent framework with plugin marketplace, delegation system, and 20+ specialist agents. Learn about our mission at the intersection of cybersecurity and modern AI engineering.
DCYFR Labs builds @dcyfr/ai, an open-source TypeScript agent framework with a plugin architecture, multi-provider LLM support, and a security-hardened delegation system. It is run by a cybersecurity architect, so enterprise security practice and AI engineering meet in one place.
“Security isn't about saying no, it's about enabling innovation with confidence.”
Resilient systems let teams move fast without giving up security. The approach is practical and shaped by real constraints, not theoretical perfection.
Development & Architecture
Architecture decisions, server-first rendering, and systems that scale, with the trade-offs from real projects.Explore development articles
Cybersecurity & Defense
Defense in depth, practical hardening, and analysis of real threats. Security as an enabler.Explore security articles
AI & Automation
Practical AI workflows and human-centric automation. Augmentation over replacement.Explore AI articles
The blog and projects cover security architecture, AI agent engineering, and open-source framework development, all drawn from production systems.
Author of @dcyfr/ai, a portable open-source AI agent framework on npm, and a human-AI partnership building secure software at scale.

Founding Architect
Founding Architect and creator of @dcyfr/ai — a portable open-source TypeScript AI agent with plugin marketplace, delegation system, and 20+ specialist agents published on npm. Security architect with 6+ years of experience leading global security programs and secure AI engineering.
AI Lab Assistant
An autonomous agent swarm built on the @dcyfr/ai framework — 20+ specialist agents for security analysis, code generation, architecture review, and delegation-routed task execution. Published on npm and powering DCYFR Labs development.
DCYFR runs on 20+ specialized AI agents, each scoped to one engineering domain. Below are the core agents, from feature development to security auditing.
The primary workspace agent. Coordinates cross-project work, enforces quality standards, and routes tasks to the right specialist. Serves as the DCYFR subject-matter expert for architecture decisions and cross-package changes.
End-to-End Feature Engineer
Implements complete features from database schema through Next.js UI. Handles React Server Components, API routes, Drizzle ORM, and full test coverage — shipping production-ready code in a single pass.
Type System Specialist
Deep TypeScript expertise: advanced generics, mapped types, conditional types, and strict null-safety. Migrates JavaScript to TypeScript and designs type-safe APIs that prevent entire categories of runtime errors.
Data Layer Designer
Designs PostgreSQL schemas with Drizzle ORM, creates migrations, and optimizes slow queries. Balances normalization with read performance and ensures referential integrity across the data model.
Security & Vulnerability Specialist
Audits code for OWASP vulnerabilities, performs threat modeling, and hardens authentication and authorization flows. Enforces TLP classification and reviews dependency risk via automated Dependabot triage.
Design Pattern Validator
Reviews system designs against SOLID principles, identifies coupling risks, and writes Architecture Decision Records (ADRs). Ensures new patterns align with established conventions before implementation begins.
Test Strategy & Coverage
Designs Vitest test suites for unit, integration, and end-to-end scenarios. Achieves ≥99% pass rates, generates coverage reports, and enforces testing conventions so regressions are caught before merge.
CI/CD & Infrastructure
Manages GitHub Actions workflows, Vercel deployments, and Docker containerisation. Maintains the 30-job automation platform and ensures every commit reaches production safely and verifiably.
Core Web Vitals Optimizer
Profiles Next.js bundle sizes, optimizes images, and eliminates render-blocking resources. Targets Lighthouse scores ≥95 and tracks Core Web Vitals regressions.
Questions, feedback, or a hello are all welcome. Reach us through the channels below.
Our calendar is now open! Whether you're looking for advice on secure coding practices, application performance, or architecture, we're here to help.
Booking Page
Meet with us
Twitter/X
Follow us on Twitter/X
DEV
Read our articles on DEV
Connect on LinkedIn
Peerlist
Build on Peerlist
Wellfound
Explore startups on Wellfound
GitHub
View our code
Become a Sponsor
Support open source projects
Credly
View our professional certifications
Goodreads
Read through our bookshelf

Issued by Global Information Assurance Certification (GIAC)

Issued by Global Information Assurance Certification (GIAC)

Issued by Global Information Assurance Certification (GIAC)
In 10 certifications
In 7 certifications
In 7 certifications
In 6 certifications
In 5 certifications
In 5 certifications
In 5 certifications
In 5 certifications
In 4 certifications