Security consultant focused on AI agent security, action assurance, and PCI DSS compliance.
I have hands-on experience in web application and network security assessments, vulnerability assessment, and PCI DSS-oriented security consulting.
My current focus is how organizations can safely adopt agentic AI systems that call tools, access data, delegate tasks, and perform actions on behalf of humans or organizations.
Model output is not authority.
A model may suggest an action, but execution should be authorized, bounded, attributable, and evidenced by systems outside the model.
AAEF is an Action Assurance Control Profile for Agentic AI Systems.
It focuses on delegated authority, policy-enforced action boundaries, revocable trust, and verifiable evidence for high-impact AI agent actions.
AAEF asks:
Was this action authorized, bounded, attributable, and evidenced?
AAEF v0.2.0 is currently available as a Public Review Draft.
- Web application security testing
- Network security assessment
- Vulnerability assessment and reporting
- PCI DSS v3.2.1 / v4.0.1 compliance support
- Security control and evidence documentation
- AI agent security and governance research

