SAIG Academy
What this proves
That I know the regulation well enough to teach it — and that I ship a production platform with a working payment flow.
A training platform on European cyber legislation: NIS2 and the Cyber Security Act, the AI Act, DORA. Eight modules, in four languages, with payment processing and invoicing. I wrote and fact-checked the content, and built and deployed the platform myself.
This backs: Your board knows what is expected of it
View the platform →
The sovereign stack, in production
What this proves
That I run what I advise. The regulator is welcome to inspect my systems on site.
Nextcloud for documents, Authentik for single sign-on, Gitea for code, plus monitoring, alerting and a backup topology with offsite replication. Not a demo setup: this is the infrastructure my own company and my clients rely on every day. Anyone who wants to see what such an environment looks like under real use is welcome to come and take a look.
This backs: Who has access to what is fixed, and traceable
My own rack, my own hardware
What this proves
That the chain I recommend to you is, in my own case, mine down to the physical layer — and that recovery on it is tested, not assumed.
My systems run on my own hardware in a rack in a data centre, not on rented space in someone else's cloud. That makes the whole chain verifiable: from who can physically reach the rack, to the offsite replication that recovery is periodically tested against. Anyone who wants to see how it is set up is welcome to come and look.
This backs: Your recovery is tested, not assumed
sovereign-nix
What this proves
That I publish claims together with the test that backs them — and withdraw them in public the moment a measurement contradicts them.
When three outside reviewers found holes in my claims, I measured their points on a test machine, publicly withdrew two of my own statements and folded the findings into the code. That is what these modules are: open-source NixOS modules that harden a machine, give every host a reproducibly different configuration, and wipe the system root at every boot. Every statement in the documentation is tied to a test you can run yourself, and it says just as plainly what those tests do not prove. Released under the European EUPL-1.2 licence.
This backs: You can show that it works, not just that it is written down
View the code and the tests →
Security audit on an open-source project
What this proves
Independence you can verify, rather than a word on a website.
I carried out a white-box security analysis on enclosed, an open-source tool for encrypted notes. The findings were responsibly disclosed to the maintainer, and the proposed improvements are public as pull requests. Anyone can review the code and the reasoning for themselves.
View the pull requests →
EASEO CMS
What this proves
That my client work is maintainable enough to exist as open source.
A content management system that originated in a client project and was later extracted into an independent, version-controlled package. It now runs across multiple client sites, with a fixed release cadence and documented migration paths for every breaking change.
View the product →
WeFact MCP
What this proves
That I build working integrations and turn them into a commercial product.
A connector that lets AI assistants work safely with the invoicing software WeFact — creating invoices, looking up debtors, reading subscriptions. Born out of my own admin, grown into a paid product under a dual licence: open source for those who want it, commercial for those who need support.
View the product →