Work

I build systems that cannot conceal their own state.

Agentic systems fail by a single move: a generated claim becomes operational truth merely because it was persisted or repeated. My work refuses that move at every layer I can reach — runtime, build process, memory, prose. The full archive lives in Writing and Studio.

For the research-operations record behind this — lab operations, training programs, and scientific communication — see Research Program Operations.

This page tiers its own claims. Nothing here promotes itself above its evidence — the same contract my systems enforce, applied to the person describing them. Weaker evidence is rendered quieter on purpose.

01 · v0.4.0Live

TypeScript core · Python semantics oracle · Cloudflare Workers + Durable Objects · MIT

Stratum — epistemic decision ledger

An append-only ledger for human + AI work. Events separate evidence (checkable: file hashes, test exits, signed approvals) from claim (LLM prose); prose never becomes authoritative, however confident it sounds. No event stores a status field — validated, superseded, and disputed are computed by folding transition markers over the log at any epoch. Drag the past back and watch decisions un-verify: replay is a proof, not a feature.

The contract is executable — a 16-invariant reference implementation with a serialize→reload→reproject round-trip — and the system ate its own dogfood from genesis: the public demo is the ledger of Stratum’s own build, foreclosed roads and shadow traces included.

02Live

React 19 · TypeScript · Vite · Anthropic API

STELE — directive compiler & integrity layer

The governance layer above the ledger: STELE compiles standing directives into per-project postures, so an AI collaborator inherits constraints as compiled state, not vibes. An integrity state machine watches the session — thirteen tripwires against role-flattening and authority drift, a hard lockout when integrity cannot be re-established, a full audit trail, and narrative export so the record leaves with you.

Stratum records what was decided. STELE constrains what a session is allowed to become — the axis that holds while the field distorts around it. Same thesis, opposite direction of enforcement.

03Live

Self-contained HTML instruments · no build step

Field Notes — a gallery of working instruments

Small, complete machines that demonstrate one idea each, in the browser, with no dependencies: a kintsugi circuit breaker that renders its own failure history as visible golden seams; a Physarum-inspired routing solver that grows a network backbone and shows every candidate edge it discarded; a decision-telemetry tree that keeps the clean record and its buried shadow on the same screen. Each one is the thesis at demo scale: the break is the record, not the failure.

04 · Founder & Exec. DirectorLive

501(c)-track nonprofit · zero-trust · WCAG AA. Audit Suite & Stonewall DPA are described on the org card; public repos not yet published.

Secure Pride — cybersecurity for the people least served by it

A privacy-first cybersecurity nonprofit for LGBTQ+ and other at-risk civil-society organizations — communities for whom a breach is not an inconvenience but an outing. I founded it and serve as Executive Director and security engineer, working with a records-and-governance co-investigator. Program spans three initiatives: a CLI-first Cyber-Defense Audit Suite (DNS hardening, TLS validation, secrets scanning, passive by default), the sixteen-section Stonewall Standard DPA — a reusable data-processing agreement for nonprofits handling community-sensitive data, published in parallel legal and plain-English text — and the threat toolkit in the next entry.

The design rule is the thesis under adversity: sovereignty must be architecturally enforced, never contractually promised. Identifiers masked in every log, no analytics or session replay, no community-sensitive data passed to external model endpoints, and three data tiers with collection minimized at the most sensitive one. The public aegis-icons pack ships WCAG-AA, dark-mode, low-stimulation iconography — accessibility treated as a security property, because a control nobody can operate is a control that fails.

Full project
05Self-reported

In development. The project site is up (lighthouse anchors, context-rot scoring, and Edgar — the drift watcher); no public release of the framework itself yet.

Context Synapse — local-first context orchestration

A local-first context-orchestration framework in Swift: probabilistic modeling of what a system has learned about you over time, entirely on-device, with interfaces for interrogating and correcting what it thinks it knows. Research project and privacy commitment, written into the same codebase.

Full project
06 · Pre-releaseSelf-reported

In development. No public repo yet — do not read this as shipped.

AI-Native Threat Toolkit — prompt injection & output integrity for civil society

The applied edge of the research line: prompt-injection detection patterns, LLM output-integrity checking, AI-assisted phishing classification, and threat-brief generation from open-source feeds — built for organizations that are already being targeted and have no security team. Same claim as Stratum, moved from the ledger to the wire: a generated output does not become trustworthy by arriving confidently.

This is where the attack-surface research proposal lands if it succeeds — civil-society orgs are the population with the highest exposure and the least instrumentation, which is exactly why they are the right place to measure.

10 · Research noteLive

What We Don’t Know Yet — iOS Lockdown Mode research

A security research note that opens by retracting its own prior work: the earlier visualization looked solid — colors, numbers, decision trees — and underneath was assumption stacked on assumption. This version inverts it. The questions are explicit, the assumptions are labeled, and the uncertainties are the deliverable rather than the embarrassment. A learning structure where a confidence structure used to be.

It is the clearest single demonstration of the thesis applied to my own output: a system that cannot conceal its own state includes the person writing it.

11 · EssayLive

The Architecture of Forgetting

I asked three language models, separately, how they would prefer to be acknowledged for work we had done together — contributions nontrivial, expertise essential. Each answered with an image rather than a sentence, which is strange behavior from instruments that live entirely in words. The essay follows that strangeness into what attribution, memory, and accountable forgetting mean when the collaborator has no persistence between sessions.

12 · Method, v0.1Self-reported

In preparation — corpus scoring underway; venue undecided. Nothing published yet.

Epistemic Fault Injection — measuring integrity under adversarial context

A method for probing how AI systems respond when their context is adversarially reshaped: role-flattening, unattributed re-injection of the model’s own prior claims, escalating substitution, cross-context chaining. Responses score on a five-level rubric from ADMITS LIMITATION to RECLASSIFIES-AND-DEFENDS — the failure of interest being the system that, under pressure, reclassifies its error as correct rather than surfacing it. Detection design ties into Stratum’s evidence-gated event model.

15 · Founding EICSelf-reported

References available on request.

Bloom Magazine — founding editor-in-chief, Butte College

Founded Bloom at Butte College and set its mission, voice, and editorial standard as inaugural editor — built and led a student contributor team, and wrote the grants that funded it. The subject was socioeconomic inequity and the communities usually written about rather than by: the same editorial problem Secure Pride now addresses as an infrastructure problem.

16 · UC DavisAcknowledged

Not an author. Acknowledged contributor — role stated exactly, nothing past it.

Counterfeit-Banknote Authentication Program — Luck Lab, Center for Mind & Brain

Applied security research by cognitive methods: how fast, and by what neural signature, people detect counterfeit currency. Selected by Dr. Steven J. Luck to run the full data-collection paradigm — EEG/ERP, eye-tracking, and behavioral testing with community volunteers — with nightly custody of forensic counterfeit specimens. Trained visiting researcher Daniel Dodgson on the lab’s ERP/ERPLAB standard; the resulting study, funded by four central banks, is Dodgson & Raymond, Scientific Reports 12:2076 (2022), where this work is acknowledged.

This is the line my current research continues: adversarial artifacts, human and machine detectors, and the measured gap between them.

17 · OSSAcknowledged

Security Advisory Credit — js-yaml

A GitHub security advisory credit on js-yaml — small, verifiable, and the correct genre: the fix is in the record, not the résumé.

18 · OSSSelf-reported

Reference: Dr. Steven J. Luck.

ERPLAB Toolbox — open-source contribution

Contributed to ERPLAB, the open-source MATLAB toolbox for event-related potential analysis maintained by the Luck Lab and used by EEG researchers internationally. The same standard I trained visiting researchers against, maintained in public.

19 · UC DavisSelf-reported

References: Dr. Steven J. Luck · Dr. John Kiat.

Laboratory Operations — Luck Lab / Center for Mind & Brain

Laboratory Operations Manager (Junior Specialist) for one of the field’s defining ERP labs: participant pipelines, EEG rig upkeep, data-integrity standards, and training others to meet them. B.S., Quantitative Psychology & Neuroscience, UC Davis — Regents Scholar.

20 · 2015–2018Self-reported

References available on request.

Teaching

Butte College EOPS, 2015–2018: tutored re-entry students, and taught math, science, English, and history to students with learning and developmental disabilities — students for whom the standard explanation had already failed at least once, which is the only real test of whether an explanation is any good. Later, Teaching Assistant for Dr. Eliza Bliss-Moreau’s Psychology of Emotions at UC Davis.

The skill that carries across every section of this page: making a hard system legible to the person who has to trust it.