Projects & case studies

Architecture stories with enough detail to be useful.

A selected set of enterprise, research, and platform projects showing the business problem, architecture choices, technology stack, system flow, security and scalability thinking, and public links where permitted.

4case studies
2enterprise cases
2research cases

Enterprise delivery details are intentionally anonymized where project data, customer context, demos, or production metrics are private.

Enterprise AI architecture

Agentic AI delivery workflow for enterprise software

Built around slow enterprise implementation cycles, fragmented requirements, manual documentation, and repeated handoffs across discovery, specification, configuration, development, validation, and testing.

Business problem

Delivery teams lose context between business discovery, technical specification, configuration, generated artifacts, validation, and testing. That creates repeated clarification loops and weak traceability from requirement to shipped work.

Technology stack
Agentic AIRAGServiceNowPythonLLM guardrailsTest automationSaaS integrations
Architectural decisions
  • Split the workflow into specialized discovery, developer, decision, validation, and testing agent responsibilities.
  • Used enterprise knowledge retrieval so specifications and generated artifacts stay traceable to source context.
  • Added human review points for governance-sensitive outputs.
Security and scalability considerations
  • Scoped data access and traceable retrieval grounding.
  • Audit trails for agent-generated artifacts.
  • Reusable agent patterns for multiple SaaS workflows.
  • Review gates for high-risk or customer-facing changes.
Business inputsKnowledge layerAgent orchestrationServiceNow / SaaSValidation & testing

Platform engineering

ServiceNow solution design and R&D enablement

Supported enterprise teams that needed clearer platform architecture, stronger RFP solution narratives, and maintainable internal applications across ServiceNow and AI/ML use cases.

Business problem

Teams needed a bridge between business expectations, ServiceNow platform capabilities, internal R&D applications, and implementation-ready technical guidance.

Technology stack
ServiceNowPythonAI/MLITSMRFP architectureTechnical training
Architectural decisions
  • Converted business requirements into platform workflows, application structures, and implementation-ready documentation.
  • Kept reusable architecture patterns separate from customer-specific configuration.
  • Combined hands-on delivery with mentoring so platform knowledge did not stay isolated.
Security and scalability considerations
  • Role-aware workflow and instance governance thinking.
  • Reusable design assets for repeated solution patterns.
  • Operational documentation for maintainability.
  • Clear boundaries between configuration and customization.
Business needArchitecture blueprintServiceNow workflowIntegration planDelivery enablement

Cybersecurity research

CAIRN: causal active inference for cyber attack diagnosis

Addressed alert-heavy security operations where correlation alone makes it difficult to explain what is happening, choose safe interventions, and confirm competing attack hypotheses.

Business problem

IDS and SIEM workflows can produce many alerts without enough causal clarity. Analysts need interpretable evidence paths and low-risk ways to confirm or reject competing attack explanations.

Technology stack
Bayesian inferenceCausal graphsCyber telemetryGenAI-assisted CTIPython
Architectural decisions
  • Modeled telemetry as a probabilistic causal evidence graph.
  • Used Bayesian inference to compare attack explanations in real time.
  • Added an active intervention loop for probes, logging, decoys, and scoped isolation.
Security and scalability considerations
  • Low-risk interventions before disruptive response.
  • Explainable evidence paths for analyst review.
  • Scoped response actions tied to uncertainty reduction.
  • Graph-based reasoning over evolving telemetry.
TelemetryCausal graphBayesian diagnosisIntervention policyResponse decision

Trustworthy ML benchmark

EntroURL-Bench for malicious URL detection

Tackled the problem of evaluating malicious-URL classifiers on aging or shallow datasets that do not represent modern phishing, malware, and malicious web behavior well enough.

Business problem

Security teams and researchers need reliable benchmarks for malicious URL detection. Weak or outdated datasets make it harder to compare models, reason about trustworthiness, and study modern phishing and malware behavior.

Technology stack
Machine learningURL featuresSecurity datasetsBenchmarkingTrustworthy AI
Architectural decisions
  • Focused the benchmark on richer URL representations rather than only lexical surface features.
  • Framed the dataset around reproducible comparison and model trustworthiness.
  • Connected the project to broader security-evaluation needs for phishing and malware detection.
Security and scalability considerations
  • Consistent benchmark structure for reproducibility.
  • Feature-rich representation for modern URL analysis.
  • Extensible evaluation pattern for future research.
  • Trustworthiness framing beyond raw classifier accuracy.
Raw URLsFeature extractionBenchmark datasetModel evaluationTrust analysis