Skip to main content

Systems

Things I've shipped.

Research is one thing; getting it to hold up under real traffic is another. These are the tools, security prototypes, and backend services I've built and deployed.

17 projects · public repositories & live deployments

  • OffensiveFlagshipOpen source

    google-botguard-security-research

    105

    An analytical survey of Google’s VM-based BotGuard engine, built on public research. It covers the bytecode interpreter, the anti-debugging tricks and the obfuscation layers, plus an unreproduced 2021 note on token binding.

    Reverse EngineeringAnti-Fraud VMBotGuard
  • OffensiveFlagshipOpen source

    fingerprintproxy

    A TLS-fingerprinting proxy written in Go. It supports JA3/JA4 emulation across 65+ browser profiles, MITM packet interception, and a straightforward configuration API.

    GoTLS / JA4MITM
  • OffensiveDisclosed

    smart-id-security-research

    Protocol analysis of Smart-ID’s cross-device authentication, pinpointing where the trust boundaries break down during device handoffs. Reported to SK ID Solutions in November 2025, with a public disclosure timeline.

    Smart-IDeIDASCoordinated Disclosure
  • OffensiveOpen source

    C3EE-Cyber-CTF

    Estonia’s Cybercrime Unit (C3, part of the Keskkriminaalpolitsei) decided to skip standard LinkedIn job postings and put out a recruitment challenge disguised as a CTF, but calling it a CTF is giving it way too much credit. It was just an old-school book cipher for beginners.

    GoCTFWrite-up
  • ProductsFlagshipLive

    Proksimity

    Passive identity verification from network-level timing and TLS handshake characteristics instead of tracking cookies or canvas fingerprinting. It reads no packet payload and stores no personal data.

    IdentityTLSPrivacy
  • ProductsLive

    Specter

    Edge-based access control that classifies requests into human, scripted, and hostile sessions. It applies progressive rate limiting and emits a cryptographically signed audit log for every routing decision.

    EdgeAccess ControlSigned Audit
  • ProductsFlagshipLive

    SteroidID

    Pairs FIDO2 passkeys with Smart-ID to remove the mobile prompt from desktop login. A browser extension, a local daemon, and an accessibility hook finish authentication in roughly 8 seconds from a single fingerprint read.

    FIDO2Smart-IDPasswordless
  • AI & RetrievalPrivate source

    Discord RAG pipeline

    A role-based retrieval pipeline over FastAPI: LanceDB vector search and BM25 combined into hybrid retrieval, with RBAC-aware filtering so access control is part of the query, not an afterthought.

    RAGLanceDBBM25
  • AI & RetrievalPrivate source

    deepgram-batch

    A CLI for batch speech-to-text jobs across 50+ languages on Deepgram Nova-3. Built to process entire directory archives, not single files.

    GoSpeech-to-Text50+ languages
  • AI & RetrievalPrivate source

    lovable-codebase-agent

    An AST-based cleanup tool for raw Lovable.dev exports. It strips vendor wrappers, removes dead dependencies, migrates SSR setups to SSG, and generates standard CI workflows.

    PythonCodegenRefactor
  • AI & RetrievalLive

    SKILL Lab

    An in-browser editor that catches the mechanical patterns of AI writing: filler transitions, structural symmetry, passive constructions. It runs on-device, with no external API calls.

    LLMWritingOn-device
  • AI & RetrievalReference

    deepseek-offpeak

    A zero-dependency timezone tracker and cost calculator for DeepSeek’s discounted off-peak pricing windows.

    JavaScriptPricingDevTool
  • AI & RetrievalReference

    Hele Beež Pastakas

    A math-grading interface built on Vision-Language Models (OpenAI / Anthropic), wrapped in an offline-first PWA. Designed for evaluating handwritten work with local data storage.

    FlaskPWAVLM
  • SystemsPrivate source

    Vooglaadija

    A media-extraction service backed by Redis task queues, JWT auth, and rate limiting, with an HTMX frontend and SSE streaming. Instrumented with Prometheus, OpenTelemetry, and Sentry inside a 7-container Docker Compose setup.

    FastAPIRedisObservability
  • SystemsPrivate source

    scripts

    Tom’s Awesome Scripts — a battle-worn collection of bash for server setup and management. The stuff you’d otherwise copy-paste at 2am, made idempotent and safe.

    BashServer SetupOps
  • FrameworksFlagshipOpen source

    zero-trust-octagon

    An architectural reference that breaks Zero Trust into 8 structural axioms and a 9-dimension evaluation matrix, focused on concrete breach failure modes rather than vendor compliance checklists.

    Zero TrustArchitectureNIST 800-207
  • FoundationsPrivate source

    tartu-progeksam-2025

    Questions and clean Python solutions for the University of Tartu 2025 programming exam. A study resource, worked end to end.

    PythonEducation