Web Design & Development
Fast, privacy-first websites and web apps. Static-first, no trackers, accessible, and built to load instantly — like this page (zero JavaScript).
Security Engineer/Cryptography /Infrastructure
I design and build post-quantum cryptography, formally verified systems software, secure transport protocols, and privacy-first self-hosted infrastructure — in Rust, C11 and Python, on Linux.
In Code We Trust.I'm a Systems & Security Engineer based in Caxias do Sul, Brazil. By day I work in IT for an industrial group; outside that, I independently build and maintain Security Ops — a privacy-first stack of self-hosted services and open-source cryptographic software.
My focus is the parts of security that have to actually hold: post-quantum cryptography (ML-KEM, ML-DSA), formal verification (Jasmin, Frama-C/ACSL), constant-time implementation, secure transport protocols, and data compression. Every performance claim is a measured number or labelled as an estimate — no benchmarks I can't reproduce.
I ship in Rust, C11, Python and Bash, deploy on Linux with Docker and GNU Guix, and host everything across clearnet and Tor. I work in tight, buildable increments: complete code, real tests, NIST/RFC vectors where crypto is involved.
Websites, software, and security work — delivered as complete, documented, buildable deliverables.
Fast, privacy-first websites and web apps. Static-first, no trackers, accessible, and built to load instantly — like this page (zero JavaScript).
Systems software in Rust, C11 and Python — CLIs, daemons, SDKs and protocol implementations. Zero-warning builds, tested, packaged for real install.
Cryptographic inventory, crypto-agility assessment, and migration audits to ML-KEM / ML-DSA. Find what breaks under a quantum adversary — before it does.
Hardened, self-hosted deployments with defense-in-depth: Docker, GNU Guix, nftables, WireGuard, Tor + clearnet. Threat-modelled in plain English.
Constant-time review, side-channel analysis, threat modeling, and machine- checked proofs with Jasmin and Frama-C/ACSL for code that has to be correct.
Several projects ship AGPL-3.0 with a commercial license option for enterprise and banking use. Talk to me about dual-licensing and integration.
A selection of what I build and maintain. Source lives at git.securityops.co.
Post-quantum secure transport layer. Named after my late mother. AGPL-3.0 with a commercial license option.
// protocolBerkeley Transport Protocol — a post-quantum transport with no CA trust model and a cross-witness mesh. Targeting IRTF / PQUIP discussion.
// compressionCompression codec: LZ77 + 4-way interleaved tANS + order-1 context model, AVX2-accelerated.
// backupCompression + post-quantum encrypted backup, with VaptVupt as the default codec. CLI plus an Android client.
// sdkIn-house cryptography SDK providing a hybrid KEM and primitives shared across the Security Ops projects.
// androidSecure deletion for Android — crypto-erase backed by the Android Keystore for irrecoverable data destruction.
// searchA privacy metasearch instance — no tracking, no fingerprinting, self-hosted on clearnet and Tor.
// toolingCryptographic inventory scanner, crypto-agility checks, and migration-audit tooling for the post-quantum transition.
// commsEnd-to-end encrypted communication tools: SecVid · KeyWave · SecChat · TempChat.
// emacsA full WhatsApp client for GNU Emacs over a Baileys bridge — 70 commands, 80 keybindings.
Have a website, a piece of software, or a post-quantum migration in mind? Send a message — I read every one.
sac@securityops.co