Security architecture and AI engineering work, grounded in systems that are running in production. Four ways engagements usually start.
Security architecture reviews for cloud, network, and application layers.
A written review of the system as designed, with findings ranked by exploitability and the trade-off behind each recommendation stated plainly. Useful before a build commits to a topology, or after one has outgrown the assumptions it started with.
Threat modeling, OWASP assessments, and secure design guidance.
Structured threat modeling against the OWASP Top 10 and, for agent systems, the OWASP Top 10 for Agentic Applications. Findings come with reproduction steps and a fix that fits the codebase rather than a generic control reference.
Conference talks, guest posts, and podcast appearances on AI and security.
Talks and long-form writing on AI agent architecture, autonomous system safety, and the security engineering behind both. Topics track what is actually shipping here — see the blog for the current material.
Contributing to or building on @dcyfr/ai and related tooling.
Support for teams adopting @dcyfr/ai, plus sponsored work on the framework itself. Everything under the @dcyfr scope is MIT-licensed, so this is about integration and direction rather than access.
Scope and availability vary by engagement. Describe the system and the question you need answered, and you will get a straight answer on whether this is a good fit.
Get in touch