github.com/trustsentinel
profile
Cloud & security architect · PhD researcher

Building things that watch, guard, and map networks.

Eighteen years across distributed systems, cloud-native platforms, and security — from high-scale backends to blockchain custody and decentralized-network research. The tools that endured are gathered under TrustSentinel.

The trajectory

How the work evolved

A drift from high-load systems toward security and decentralized-network research — described by the technology and skills, and where the projects were born.

2006
–2014

High-load distributed systems

Distributed, fault-tolerant server platforms at scale. JVM performance tuning, heap analysis, and cross-platform systems architecture.

JavaSpringPythonRedisRabbitMQCassandra
2014
–2021

Cloud-native architecture & SecDevOps

Distributed systems for 10K+ concurrent users. Early Docker, Redis sharding, Kubernetes, CI/CD and event-driven pipelines, Linux OS tuning, IaC — and security hardening entering the practice.

Go.NETNode.jsKubernetesDockerAWSGCPTerraform
Projects born · INCIBE finalistsstuk ’18marshmallows ’19stk ’19
2021
–2022

Platform security & private cloud

Security engineering for high-traffic infrastructure: a DIY private cloud, Kubernetes-bound clusters, IaC, and OS-level hardening to sub-10ms P99 latency.

OpenStackKubernetesGoElasticsearchgRPCCloudFormation
2022
–2024

Blockchain & custody security

Secure custody for Bitcoin and multi-coin: Lightning Network Layer-2, hardware key custody (FIPS 140-2 L4 HSM), IAM, secrets management, STRIDE threat modelling, audit-grade event sourcing.

BitcoinLightningHSMKeycloakVaultKafkagRPC
2020
–now

Decentralized-network security & zero trust

Doctoral research into the attack surface of blockchain P2P networks, decentralized identity (DID/SSI), self-custody and Layer-2 — alongside zero-trust architecture, service-mesh microsegmentation, and AI/LLM security governance.

Zero TrustIstioCiliumDID/SSIEthereumNISTAI Security
Knowledge domains

What the work spans

Security & architecture

Zero TrustSecurity by DesignThreat Modeling (STRIDE/PASTA)NIST 800-53 / 207ISO 27001OWASP ASVS/SAMMSecurity GovernanceDevSecOps

Distributed & cloud

Distributed SystemsMicroservicesEvent-DrivenKubernetesService Mesh (Istio/Cilium)AWS · GCP · OpenStackIaC (Terraform)

Identity & cryptography

IAM (Keycloak/Okta/Cognito)OAuth · SAML · OIDCPKI · mTLSHSM Custody (FIPS 140-2)Decentralized Identity (DID/SSI)E2E EncryptionNoise Protocol

Blockchain & AI security

Bitcoin · Lightning / L2EthereumSmart-Contract SecurityP2P Protocols · Self-CustodyOWASP LLM Top 10MITRE ATLASNIST AI RMFPrompt-Injection Defense
Current work

Serious projects

Secure access & infrastructure

stuk

2018

Port-knocking SSH access manager · TOTP/MFA.

Secure mesh networking for IoT — an encrypted peer overlay with 2FA/U2F. Tailscale-like.

stk

2019

Browser remote-shell broker over the Noise Protocol.

Network intelligence & research

netso

2020

Secure decentralized platform — self-sovereign identity (SSI) & E2E encryption.

argos

2024

Distributed P2P blockchain scanning & vulnerability analysis.

RLP codec for Ethereum node discovery (discv4).