Founder, Sentinel Forge · EU citizen (Spain) · open to remote / relocation
I build local-first, evidence-first cybersecurity: every claim ships as a re-examinable artifact — a hash, a signature, a reproducible test, a validation record — not an assertion. My core is the control layer between what an AI agent intends and what it actually executes: deterministic, fail-closed enforcement, with traceable evidence at every boundary.
Alongside the defensive core, I do lawful, adversary-informed work — authorized, scoped, lab-safe — to sharpen detections, remediation quality, and proofs. AI is used as a support layer for review, diagnosis, documentation, and remediation planning. Security decisions remain scoped, human-reviewed, reversible where possible, and backed by traceable evidence.
- AI agent security & deterministic (fail-closed) enforcement
- Formal verification of authorization properties (SMT/z3, symbolic execution)
- Blue Team validation · security validation · evidence automation
- AppSec support · secure remediation · patch validation
- Threat modeling · risk & residual-risk review
- Authorized offensive research (SMT/z3 red teaming, CTFs) — to strengthen defense
- Tamper-evident evidence (hash chains, Ed25519 signatures, trusted timestamping)
- Local-first defensive automation · audit-ready, sanitized reporting
| Repository | Demonstrates | Evidence Type |
|---|---|---|
| z3-reversing | SMT/z3 for security — the same solver used to prove no authorization bypass exists and to find one: 18,000 self-authored solved challenges (9 families) + external picoCTF solves | Reproducible solvers, Ed25519-signed certificate & attestation, CTF writeups |
| lab-records | Signed, sanitized records of real defensive operations; hash-verified case study on non-auditable LLM self-report | Lab records + SHA-256 sidecars |
| FCCSecurity-Public | Defensive console, public-release governance, validation records, residual-risk tracking | Static app, documentation, release-gate evidence |
| ai-threat-model-dependency-risk-lab | Threat modeling, dependency-risk review, remediation planning, human approval gate | Threat model, dependency review, remediation plan, validation report |
| codex-safe-operation-lab-public | Human-controlled AI workflow, Windows defensive triage, local-first evidence handling | Safe operation docs, static panel, sanitized triage summary |
Scope -> Review -> Remediate -> Validate -> Evidence -> Sanitize
Every security claim is bounded by: observed facts; reasonable inferences; hypotheses; recommendations; unknowns. The goal is not vague automation — it is defensive work that can be reviewed, reproduced, audited, or safely sanitized for portfolio use.
| Evidence Class | Meaning |
|---|---|
| Observed Fact | Directly seen in file, command output, log, screenshot, diff, hash, test, or artifact |
| Reasonable Inference | Supported by observed facts, but not directly proven |
| Hypothesis | Plausible but not yet validated |
| Recommendation | Action proposed from evidence, risk, or missing validation |
| Unknown | Data still required before a claim can be validated |
Defensive-primary. Public material is sanitized and does not include secrets, private host data, live target details, credential material, exploit chains, persistence, evasion, malware, or unauthorized third-party activity. Any adversary-informed activity is authorized, scoped, non-destructive, lab-safe (self-authored labs and public CTFs), and used only to improve defenses, detections, remediation quality, and documentation.
This profile shows proof of work through public labs and documentation. It does not claim formal certification, third-party audit, legal attribution, complete absence of vulnerabilities, employment, membership, partnership, endorsement, or authorization outside the declared scope of each repository.
This work is AI-assisted and human-reviewed: AI supports review, diagnosis, documentation, and remediation planning; a human scopes, reviews, decides, and signs the evidence.


