Security Engineering / Local AI
CodeGuardian AI
A privacy-first secure code review platform that combines context-aware static analysis with local AI interpretation and professional reporting.
Software Engineer Security Researcher Open Source Contributor
Software Engineer & Security Researcher
I build backend systems, local AI products, security tooling, and developer-focused software while contributing to open source and conducting responsible vulnerability research.
01 — About
My work is grounded in systems that are useful, understandable, and designed around real operational constraints.
I build Python backends, Django applications, APIs, and local AI systems that keep sensitive context closer to the people using them. Security remains part of that engineering process—from secure code review and practical tooling to evidence-led vulnerability research, responsible disclosure, and maintainable open-source fixes.
02 — Selected Work
Focused project previews lead to concise technical case studies covering the problem, architecture, engineering decisions, and current state.
Security Engineering / Local AI
A privacy-first secure code review platform that combines context-aware static analysis with local AI interpretation and professional reporting.
Security Operations / AI
An analyst-grade investigation platform that turns uploaded or streamed logs into correlated attack stories, cases, and reports.
Additional systems
Local AI / Agentic Systems
A portable local AI knowledge and engineering workstation built for grounded research, repository intelligence, and approval-led agentic work.
Organizational Intelligence
A secure local organizational knowledge system for source-grounded answers, meeting intelligence, and human-reviewed action.
AI / Career Technology
A local-AI interview preparation and assessment platform combining mock interviews, resume analysis, and structured practice.
03 — Research
I approach vulnerability research through reproducible analysis, coordinated disclosure, regression testing, and upstream remediation. The public record below links directly to official project advisories.
View all researchPotential bypass of Django DATA_UPLOAD_MAX_MEMORY_SIZE when parsing oversized JSON and urlencoded request bodies via DRF request.data
GHSA-2m8g-3cmr-wg3w
AdminRenderer may disclose GET-protected data when rendering invalid write requests
GHSA-g47c-3xmw-q6m2
CyberChef’s pretty-recipe parser vulnerable to client-side ReDoS / CPU exhaustion when parsing a malformed #recipe= URL
GHSA-w74r-jxjh-gwr6
04 — Open Source
Selected bug fixes, regression work, and security-focused engineering across established open-source projects.
05 — Expertise
Technologies and disciplines I use across backend delivery, local intelligence, security engineering, and infrastructure.
Python · Django · Django REST Framework · FastAPI · REST APIs · PostgreSQL · Redis · Celery
Local LLMs · Ollama · RAG · ChromaDB · Agentic Workflows · AI-assisted Applications
Secure Code Review · Application Security · API Security · Vulnerability Research · Security Automation · Log Analysis · Static Analysis
Docker · Linux · Git · GitHub Actions · Nginx
06 — Approach
Designing dependable backend services and product foundations.
Keeping inference, knowledge, and sensitive context closer to users.
Learning, reviewing, and improving software in public.
Finding, reproducing, reporting, and helping remediate vulnerabilities.
07 — Contact
I’m open to conversations around software engineering, backend systems, local AI, open-source collaboration, and security research.