I take on a small number of outside engagements a year. The core is identity and systems work; some of it is AI. In every case the same thing is true: the problem is real, the domain is one I know, and getting it wrong is expensive. Here’s what I take on.
Identity & systems
The centre of what I do: digital identity (OID4VP, SD-JWT VC, OIDC/CIBA, OAuth 2.0), verifiable credentials, KYC and KYB, and the backend architecture around them, in TypeScript and Rust, from first design to production. If you’re building something where authentication, trust or compliance is load-bearing, this is the work.
AI that fits your stack
Most off-the-shelf AI SaaS is built for American startups: generic workflows, US-hosted infra, and a procurement conversation with your DPO you’d rather not have. When the fit is wrong, the tool sits in a tab nobody opens. I build AI features that fit instead.
- Scoping first. Not every problem is an AI problem. I’ll tell you where it helps and where it doesn’t, before you spend on a build.
- Deep integration into your stack. Proper integration into your data, your workflows, your auth. If you have an identity system, the AI respects it.
- EU-resident by default. Mistral, Scaleway, OVHcloud, or self-hosted. No US-subprocessor surprises in the DPIA.
- Compliance as an output. GDPR and EU AI Act posture handled as part of the engagement: risk classification, audit logging, disclosure copy, post-market monitoring scaffold. (More on what “aligned” means in this post.)
AI security review
You already shipped the AI, and now you want to know whether it leaks. Traditional security review doesn’t catch this: the linters pass, the pentester cleared the endpoints, and the chatbot still hands one customer’s data to another who asked nicely. I test the AI layer specifically (prompt injection, RAG data exfiltration, agent abuse, PII in outputs and logs), human-led and AI-aided where it helps, and hand back a report your engineers can act on, not a pile of findings with no fix plan.
Where I come from
Fourteen years building products end to end, currently Senior Identity Engineer at TWIN (IOTA Foundation). A few concrete examples:
- An OID4VP verifier built to the EU’s HAIP profile and interop-tested against the official EUDI Reference Wallet, the same standards the EU Digital Identity Wallet runs on.
- A GLEIF vLEI to IOTA DID bridge with keys that never leave the browser, and a GDPR right-to-erasure flow that cascades across DID documents, a Vault key wipe, and audit-log scrubbing.
- A digital identity platform now backing KYC across 10+ partner products, and a regulated crypto exchange with KYC-gated trading.
The resume has the longer version, and selected work has the projects.
How I work, and what it costs
I keep this selective, so I take a small number of engagements at a time. I price on the problem, not by the hour, and quote a fixed number once I understand the scope. Engagements start around €8k / $9k; below that there’s usually a better-fit option than me, and I’ll point you to it. If I’m not the right person for it, I’ll say so early.
Get in touch
Tell me what you’re building and where it’s stuck. I’ll tell you honestly whether I’m the right person for it. Drop me a line or reach out on WhatsApp.