IT-security specialist for critical healthcare infrastructure (and KMU) since 2017.
I build fail-closed, auditable, self-hosted software - from GPU kernels to the Linux kernel.
I'm a systems programmer who cares about the boring, load-bearing things: fail-closed defaults, tamper-evident audit trails, and software that never leaves your network. My day job is keeping critical healthcare infrastructure, and the small businesses nobody else looks after, secure.
I like a problem that forces me down to the metal: a decompressor that has to be correct and fuzz-proof, a simulation squeezed into hand-written SIMD, an auth plugin that fails safe, a kernel driver that behaves. Different languages, same obsession β make illegal states unrepresentable, then prove it.
- π§° Comfortable across C, C++/CUDA, C#, Rust, and x64 assembly.
- π₯ Focused on self-hosted, single-tenant tools.
- π§ Occasional Linux kernel contributor.
ποΈ cudec
Auditable, fail-closed, fuzz-tested GPU decompression in CUDA C++. LZ4 batch-decoded on NVIDIA GPUs today; Snappy, GDeflate and Zstd planned. |
π jellyfin-plugin-sso
Single sign-on for Jellyfin via OpenID Connect & SAML 2.0 β a security-first revival of the archived |
π swarm.asm
A Particle Life engine written entirely in hand-written x64 assembly. Goal: 1,000,000 particles at 60 fps β no GPU, no dependencies, one small exe. |
π§ linux
My working tree for Linux kernel development and upstream contributions. |
If something I built saved you time, made your setup a little safer, or was just fun to read, you can buy me a coffee. It keeps the late-night, low-level side projects going. No pressure, always appreciated. π
Every coffee goes toward more auditable, self-hosted, fail-closed open source. Thank you. π




