About

Why four things

There is a version of this that is one project. I have found that it does not work.

The argument

Each altitude fails in its own way, and each failure needs a different kind of artifact to fix it.

State it as a principle and everyone agrees, because agreeing costs nothing. Build it as a product and it works for the people who happen to use that product, which is not the argument. Publish it as a protocol and it needs someone to adopt it. Explain it to the person actually holding the phone and it helps them tonight, but changes nothing about how the next product gets built.

So: all four. HumanTerms says what is owed. Q2D makes one part of it mechanically true rather than promised. Deeta is what a product looks like when it is built that way from the start, rather than retrofitted after the fact. Cyber Safety Group is for the parent who has to make a decision this evening and has no interest in any of the above.

On verification

The eleventh HumanTerms commitment is the one that matters most, and it is the least quotable: show your work. Publish what you collect, who you share it with, and what the AI sees — in plain English, on a public page, kept accurate.

It matters because the other ten are unfalsifiable without it. A privacy claim nobody can check is a marketing claim. That is also the standard this site should be held to: everything on it is meant to be verifiable against something you can go and read.

Writing

Published on LinkedIn. Collected there.

Cyber Safety Is Not Cybersecurity

Cybersecurity is a profession; cyber safety is personal. Most people are not defending an enterprise network — they are trying to protect a phone, an inbox, a bank account, and their kids. The distinction is why most security advice fails the people who need it most.

MCP: The Protocol Powering Your AI Agents Is Also Your Newest Attack Surface

Prompt injection, token abuse, rug-pull tools. The integration layer that made agents useful arrived faster than the practice of securing it.

The Key to Enterprise Agentic Adoption: Control

The interesting question is not what agents can do, but what happens off the happy path — a tool fails, context shifts, an agent takes a fallback route nobody designed or governed.

Software Engineering: A Science AND an Art

What separates engineers who thrive with AI coding tools from those buried by what those tools generate.

Work

I am an engineering and security leader. Over twenty-five years — fifteen of them in cybersecurity — I have built teams and modernized systems across startups, non-profits, enterprise organizations, and Big Tech, most recently at CrowdStrike and AWS. I am a Vice President in Core Engineering at Goldman Sachs.

I hold an MS in Cybersecurity Management from Purdue, and a graduate certificate in Strategic Management from Harvard.

The projects described here are independent of my employer. They are built on my own time with my own resources, they are not connected to my work, and the views expressed on this site are mine alone.