Threat Tape // Work

Work

FILE:
The portfolio
STATUS:
~14 platforms, built solo
METHOD:
AI agentic development — a 10× leverage model
BUILT:
Most of it inside a single year
DOMAINS:
Security & Governance · Trust & Information Integrity · Experience Economy · Work & Hiring

Roughly fourteen distinct platforms, built solo, most of them inside a single year. Not with a floor of engineers — with AI agentic development, running the kind of leverage where one operator ships what used to take a team. The security is the spine under all of it. The range is the point. Most of what's below started the same way: I ran into something broken, or stupid, or missing, and figured I could do better. All of it is mine, built start to finish. Here's the board.

The compliance-and-defense stack — RiskTape at the head of it.

Cyber governance and compliance — every risk, on the record.

Every security tool on the market is built for the people at the keyboard. RiskTape is built for the people who sign. When the board, a regulator, or your cyber-insurance carrier asks "are we compliant, who's accountable, and can you prove it," the honest answer is usually a two-week fire drill of screenshots and panic. RiskTape sits above the stack you already own and turns the firehose of technical noise into the handful of grades, named owners, and dollar figures the boardroom actually wants, with a defensible record so "prove it" takes one click instead of one fire drill.

Always current. Your compliance posture goes stale the second you measure it. RiskTape watches your real telemetry continuously, so what you see is what's true right now, not what was true the last time someone scrambled to reconstruct it.

Built on what's actually there. You can't secure, score, or defend what you can't see. It finds and evaluates the real assets on your network, so the whole picture is built on reality instead of the spreadsheet somebody swears is up to date.

risktape.io

EDGAR

You can't secure what you can't see. EDGAR sees all of it.

You can't secure what you can't see, and almost nobody can see all of it. The inventory is a spreadsheet somebody swears is current, the network has boxes on it nobody remembers standing up, and every tool downstream is quietly built on that bad data. EDGAR is the layer that fixes the foundation: agentless discovery that finds what's actually on your network and pulls the real configuration off it, so everything above it is built on reality instead of a guess.

The real inventory, not the spreadsheet. Agentless discovery finds the endpoints actually on your network, including the ones nobody put in the inventory, without installing software on every machine.

Configuration from the source. EDGAR authenticates to each endpoint and pulls real configuration data, so you're working from what's actually there, not the spreadsheet somebody swears is up to date.

The layer everything builds on. The forgotten box, the stray service, the thing a contractor stood up two years ago and never tore down, EDGAR finds it, and feeds the discovery-and-configuration picture every other tool depends on.

[ Open the file ]

CGAP

Governance maturity, measured from real evidence instead of a slide deck.

Compliance maturity usually gets measured the dishonest way: a questionnaire somebody fills out the week before the audit, drifting toward whatever the org wants to show its board. CGAP measures it from real evidence instead. It computes your governance posture from the security telemetry you already generate, maps it across every framework at once, and produces a single executive-facing score you can actually defend, because it's built from what's true, not what's convenient.

Evidence, not self-assessment. CGAP pulls from the telemetry you already generate, scanners, SIEM, and the rest, to compute compliance status from real evidence instead of self-assessment questionnaires that drift toward whatever looks good in the board deck.

Every framework at once. It maps your posture against four current-revision frameworks simultaneously, NIST CSF 2.0, ISO 27001:2022, CMMC 2.0, PCI DSS v4, with a cross-framework crosswalk so one piece of evidence is cited everywhere it's asked for. No double entry, no auditor confusion.

One score, fully reproducible. A single executive-facing score with full drill-down to control-level evidence, and every score is a timestamped, reproducible snapshot, so "what did we look like last quarter" is one click away.

[ Open the file ]

Recon

The people who know your attack surface best are the ones trying to get in. Recon levels the field.

Before you can defend the perimeter, you have to know where the perimeter actually is, and right now the people who know that best are the ones trying to get in. Attackers map your whole attack surface for a living, the technical one and the human one. Most organizations have never done it once. Recon closes that gap: it looks at you the way an adversary does, from the outside, with no inside knowledge, and hands you the picture while you can still do something about it.

Your real footprint, not your assumed one. The assets you forgot you had are the ones that get you. Recon finds the exposed technical surface that isn't in anyone's inventory, the forgotten subdomain, the stray service, the thing a contractor stood up two years ago and never tore down.

The humans are an attack surface too. The easiest way in is rarely a server, it's a person. Recon does the same OSINT an attacker runs on your company and your leadership: who your executives are, what's public about them, which ones make the obvious phishing and social-engineering targets, and how much of the org chart can be reassembled from the outside.

Seen the way they see it. No agents, no credentials, no cooperation from the target. Recon works from the outside in, because that's the only honest test of what an attacker can actually reach, then hands back what's exposed, why it matters, and what to do about it.

[ Open the file ]

Proving what's real when everything's cheap to fake.

OSTRAQ

Private, accurate, tamper-proof. Elections were told to pick two. OSTRAQ refuses.

Elections are stuck with a problem nobody's solved: you can have private, accurate, or tamper-proof, but never all three at once. OSTRAQ is what happens when you refuse to accept that trade.

Prove you can vote without giving yourself away. A voter should be able to establish they're eligible without handing over their identity to do it. (Behind the scenes: cryptographic identity proofing built on IdNFT.)

Every vote counted right, and provably so. Not "trust us." Counted correctly, and able to prove it after the fact without exposing how anyone voted. (Behind the scenes: zero-knowledge proofs.)

Results nobody can quietly change. Once it's recorded, it stays recorded. Tampering doesn't survive contact with it. (Behind the scenes: a hash-chained, tamper-evident ledger.)

All of it runs on cryptography built for the threats that are coming, not the ones we already beat, while most of the country still votes on decades-old staleware. We can do better. OSTRAQ is what better looks like.

[ Open the file ]

SourceIQ

Disinformation got cheap. SourceIQ tells you what you're actually looking at.

Disinformation got cheap, fast, and good. A convincing lie now costs almost nothing to manufacture and almost nothing to spread, and by the time anyone asks "wait, is this real," it's already done the damage. SourceIQ is built for the people whose job is to answer that question before it matters, not after. It takes the raw material of a modern influence campaign, the memes, the posts, the links, the story that's suddenly everywhere, and tells you what it's actually made of.

The stuff that actually moves. Not press releases, the real vectors: memes, social posts, shared links, the screenshot making the rounds, the narrative three different accounts started pushing on the same afternoon. SourceIQ ingests what people actually see and share, not the sanitized version.

Where it really came from. Provenance, not vibes. SourceIQ traces a piece of content back toward its origin instead of taking the label on the front at face value, so a "grassroots" story that started in one coordinated place stops looking grassroots.

Organic, or manufactured. There's a difference between a thing people are genuinely saying and a thing built to look that way. SourceIQ reads the pattern, the timing, the coordination, the amplification, and tells you which one you're staring at, and who's working the levers.

[ Open the file ]

HumanGrove

Every account is a verified human, every moderation call is on the record, and the feed is yours. The anti-everything-app.

Social platforms rot because the business model rewards outrage and surveillance. HumanGrove fixes the structure, not the symptoms: small self-governing communities, one verified human per account, and moderation you can actually audit.

One human, one account. A phone turnstile mints a portable token, so a block sticks to the person — not a handle they can respawn an hour later.

Moderation on the record. Every mod action is a hash-chained entry anyone can recompute. Tamper with one and the whole chain breaks, live, in front of you.

[ Open the file ]

Thirty years in and around live entertainment, conventions, and sport — turned into product. This is the one that's just getting started.

Promenade

Ten thousand strangers on one boat for seven days. Promenade is how they find their people before the ship sails.

A social and media layer that drops into a cruise line's guest app: affinity groups, photo sharing, and the photographer re-bundle, sitting on a reservation-derived accountability backbone that quietly automates the CVSSA crime-logbook obligation.

Find your people, opt-in by design. System and user-created affinity groups, so ten thousand strangers can sort themselves into the handful of people worth meeting, without anyone being opted into something they didn't choose.

"Photos of me," free to share. Guests find the shots they're actually in, and the ship's photographer re-bundles them into something worth buying, instead of a wall of prints nobody claims.

Accountability built into the backbone. Audited, case-bound identity resolution for crew, on a reservation-derived spine that turns the CVSSA crime-logbook obligation from a manual chore into something the system just keeps.

Built for the ship, not the cloud. A per-cruise data module that runs local-hot at sea and goes cloud-cold after, so it works when the satellite link doesn't.

[ Open the file ] Launch demo

Iqon

Run a convention at real scale and the tooling is either ancient or held together with tape. This is the replacement.

Run a convention at any real scale and you find out fast that the tooling for it is either ancient or held together with tape. Iqon is the replacement.

One system, not six. The operations, the schedule, and the commerce in one place instead of six tools that don't talk to each other.

The part everyone forgets. It manages the volunteers who actually make the event run — the piece nobody plans for until it falls apart — built by someone who has actually run the floor, not guessed at it from a product spec.

[ Open the file ]

MyAthlete

Every kid's recruiting profile is scattered across ten sites and a shoebox of screenshots. MyAthlete pulls it into one.

Recruiting rewards the families who can afford a $3,000 service and a parent with time to chase every form. MyAthlete is for everyone else.

One profile, not ten tabs. It pulls a young athlete's stats, film, and recruiting footprint out of the ten places they're scattered and puts them in a single profile.

From the data families actually have. It reads the stats off the screenshots and flyers parents already keep, instead of demanding clean spreadsheets nobody maintains, so the kids without a service in their corner aren't invisible.

[ Open the file ]

eCombine

Roster decisions based on something real, not a gut call and a stopwatch.

The other half of the same problem: eCombine is the evaluation side. Roster and recruiting decisions too often come down to a gut call and a stopwatch — eCombine scores and evaluates athletes so those calls rest on something real.

The measurable, comparable, defensible side. Built for the combine: the part of athlete assessment you can actually put a number on and stand behind.

FERPA-clean from the ground up. Student data handled the way student data has to be handled, from day one.

[ Open the file ]

eTrax

Where's the gear, and whose name is on it? eTrax always knows.

Two halves of one problem nobody in school athletics wanted to own — where's the equipment, and how good is the athlete. eTrax is the equipment half: it tracks athletics gear and its chain of custody so nothing walks off without a name attached.

Accountability the gear budget deserves. Built for school athletics, where the equipment budget is real and the accountability usually isn't. eTrax is the ledger that makes someone answerable for every item.

FERPA-clean from the ground up. It touches student data, and that's not optional, so it was built to handle it correctly from the first line of code.

[ Open the file ]

DraftIQ

Your league's sharks have spreadsheets and a Discord. DraftIQ puts the same edge in your corner, live, on the clock.

Fantasy drafts are won and lost in the ninety seconds you're on the clock, and the people who win have a war room you don't. DraftIQ is that war room, for everyone else.

A co-pilot on the clock. It reads your roster, your league's scoring, and the board as it empties, then tells you who's actually worth taking next, while the pick still matters.

Wherever you draft. Desktop and web, side by side with whatever platform your league uses. No tab-juggling, no paste-the-export rituals. Built for the people who take the draft too seriously, by someone who does too.

Launch demo

The honest version of getting hired.