Bienvenidos, San Antonio · 25% off all cybersecurity services, now through December 31, 2026. See what qualifies →

Selected Work · Proof

Built, not just advised.

Most security consultancies can tell you what to do. Fewer can show you the proof: the companies we have delivered for, and the working systems we have built and shipped. Each one carries the security discipline it was engineered with.

Enterprise engagements

The successes that keep clients coming back.

Whether you're a small business or a large enterprise, we have you covered. Here are a few of our previous successes, and we'd love to talk about yours.

Vulnerability Management at Platform Scale

Secure agentic AI · VM operations

Led vulnerability-management operations for a top-500 delivery platform. Designed and shipped agentic security tooling with explicit containment boundaries, human intervention points, and append-only audit logging, automating detection and triage across a large service estate and remediating cloud and dependency misconfigurations.

What it demonstrates

  • Agentic automation with guardrails: boundaries, not free rein
  • Append-only audit logging for model and agent activity
  • Detection and triage automation that keeps a human in the loop
  • Measured, reported risk reduction: outcome, not activity
Claude Code (agentic)WizEndor LabsJiraAWS / GCP

−41%

net OS-CVE reduction, 129 services, 21 days

DisciplineVulnerability management, cloud security
ClientCDW-facilitated enterprise contract

A SOC 2 Type I Engagement, Automated

SOC 2 Type I · Evidence automation

Automating the SOC 2 Type I readiness engagement for Wagner Engineering. A formula-driven control register as the system of record, 35 criteria across the nine Common Criteria domains plus Confidentiality, feeds a live dashboard with automated percent-complete-by-domain rollups and a dashboard kept in lockstep to all live changes.

What it demonstrates

  • One formula-driven control register as system of record
  • Automated percent-complete-by-domain rollups on a live dashboard
  • PM board synced to the register by a push rule and daily reconcile
  • Per-control evidence vectors, SOPs, and Definition-of-Done gates
Google SheetsApps ScriptClickUpMicrosoft GraphAICPA TSC

35

SOC 2 criteria tracked in one automated register

DisciplineSOC 2 readiness, evidence automation

A Security Program, Zero to Audited

Program build · Offensive validation

Built an information-security program from the ground up across four web and SaaS products at Wolfe LLC: secure-by-design reviews, threat modelling, SAST/DAST/SCA in the SDLC, SIEM logging and detection rules, endpoint controls, and a NIST-CSF-based third-party risk process. Ran three PCI DSS audit cycles across 300+ controls, and personally found and exploited a P1 broken-access-control flaw, then drove it to full remediation.

What it demonstrates

  • Standing up governance and controls where none existed
  • Security embedded across the SDLC, not bolted on
  • Offensive validation: found and proved a critical flaw
  • Audit delivery under PCI DSS at real control volume
SemgrepSnykBurp Suite ProSumo Logic (SIEM)PCI DSS · NIST CSF

300+

PCI DSS controls, 3 audit cycles

DisciplineProgram build, AppSec, offensive validation
ClientWolfe LLC

Third-Party Risk Intake, Automated

TPRM · Third-party intake automation

The founder's first production security automation, built at Wolfe LLC. A Microsoft Power Automate flow behind a Microsoft Form: a submitter completes intake, the entry is parsed through Excel and scored by an inherent-risk calculator against controls drawn straight from NIST, tailored to what Wolfe offered at the time. The owner is emailed the exact controls their case requires, with security-team contact, and every submission lands in a centralized ownership register. Since rebuilt with LLM and AI capability.

What it demonstrates

  • Control scoring curated from NIST, tailored to the business
  • Inherent-risk weighting (CIA plus additional factors)
  • Automated owner notification with the controls each case needs
  • Centralized ownership register, nothing falls through
Power AutomateMicrosoft FormsExcelNIST controlsInherent-risk scoringAzure

1st

production security automation the founder shipped

DisciplineTPRM intake, control tailoring
ClientWolfe LLC

Systems we've built

Tooling in production.

Each system is engineered the way we would engineer yours: read-only where it can be, fail-closed when something breaks, secrets in a vault, and an audit trail by default.

OSINT Enrichment Engine

OSINT · Third-party risk profiling

An engine that turns an ambiguous company name into a scored, sourced risk profile. Deterministic code owns parsing and de-duplication; a guardrailed AI agent owns the open-source research and the write-up, scoring each organization on a 100-point rubric where “security need” is a weighted dimension. The same tradecraft as vendor due diligence and pre-engagement reconnaissance, run at machine speed and held to evidence standards a court would recognize.

Secure by design

  • Lawful, public OSINT only: no scanning, no exploitation
  • Every claim tiered: Confirmed / Strong / Hypothesis / Unknown
  • Adverse findings need a primary source under our OSINT framework
  • Entity disambiguation before attribution
  • A suspected weakness is never stated as confirmed
  • Business-context data only; fails closed on any error
PythonClaude Code (agentic)WebSearch / OSINT100-pt rubric1Password

100%

of adverse findings tied to a primary source, or labelled unverified

DisciplineTPRM, attack-surface recon
ClientInvictus (internal)

Document Intelligence Pipeline

Document intelligence · Intake to RAG

One pipeline, two disciplines. Deterministic single-scan intake splits, OCRs, classifies by rule, enforces naming, and files every artifact audit-safe. Then the AI stage turns that corpus into a semantic, citable knowledge base an LLM can query: chunked with page-level provenance, vectorized by a local embedding model into a vector store, and served through an MCP server that answers meaning-based queries with exact source, section, and page citations.

Secure by design

  • Deterministic classification; unmatched routes to a review queue
  • OCR once, enforced naming, traceable scan-to-final-location
  • Fully local AI stage: no cloud API, no document egress
  • Localhost-bound; exposable as a secured, authenticated API
  • Fail-closed ingestion, nothing stored unverified
  • Every answer carries a real citation (source · section · page)
OCR pipelineRule-based classificationPythonMCP (FastMCP)Ollamabge-m3Qdrant

4-gate

fail-closed quality checks, nothing stored unverified

DisciplineChain of custody, RAG grounding
ClientInvictus (internal)

The same hands that built these will build yours.

No handoff to a junior, no watered-down delivery. Whether you're adopting AI, standing up a security program, or proving your risk actually went down, you work directly with the people who built the work above. Let's talk.