Ally
An AI-native operating organism: logically separated agent teams, layered memory, governed action, and a shared life ontology designed to turn one human's intent into coordinated work.
Project briefEngineer. Operator. Entrepreneur.
I combine engineering, infrastructure, cybersecurity, and AI to build intelligent systems that hold up in the real world.
In the workshop
Active work at the intersection of AI, security, and systems engineering. Follow the idea from research to working system.
An AI-native operating organism: logically separated agent teams, layered memory, governed action, and a shared life ontology designed to turn one human's intent into coordinated work.
Project briefPrivate behavioral intelligence that learns how an individual or organization normally operates, detects meaningful deviation where it happens, and escalates only the evidence that deserves deeper reasoning.
Project briefSelected portfolio
Case studies built around the problem, constraints, architecture, results, and what comes next.
Explore all workAn experimental operating system for a single-human company: a deterministic operational spine, governed agent teams, scoped memory, and a structured model of organizational reality in PostgreSQL.
Code release for a 2026 paper: a Mamba state-space sequence model over Tetragon/eBPF kernel telemetry, evaluated on 22 ATT&CK techniques run by an LLM-assisted agent.
Can a transformer beat the MLP inside PPO and SAC? A three-way study placing the transformer on the actor, the critic, or both, with a CoordConv-ResNet encoder, the failure modes that shaped it, and held-out results across five agents.
How I work
Business outcome, architecture, data, infrastructure, security, and operations stay connected.
Architecture decisions, trade-offs, experiments, and limitations are part of the work.
The thread stays intact from the first difficult question to the system people can operate.
Latest thinking
Insights on AI, security, infrastructure, research, and the engineering behind systems that last.
Read all insightsA research note on giving efficient local models and larger central systems different jobs inside one security architecture.
From the law of large numbers to Mamba-based telemetry analysis and human trial-and-error, the value of repetition depends on what the process lets us observe.
A practical explanation of ML-KEM, hybrid key establishment, and the inventory, testing, and crypto-agility work required for a credible post-quantum migration.
Ventures
Honest status, clear origin stories, and a public record of what the strongest ideas are becoming.
A governed agent harness that behaves less like a chatbot swarm and more like a living organization—specialized teams, shared memory, durable world state, and cryptographically bounded action.
Follow the ventureGive every endpoint a private model of normal behavior, then connect those models to a central intelligence layer that understands the people, policies, assets, relationships, and routines behind the activity.
Follow the ventureGive small businesses without an IT department one partner accountable for the whole stack: monitoring, endpoints, networks, cloud, security, vendors, and the person who shows up when something breaks.
Follow the venture
About Ryan
My work connects engineering, infrastructure, cybersecurity, AI, research, and entrepreneurship. The common thread is systems: seeing the whole, working through constraints, and building something useful.
Read the storyWork with me
I work with teams navigating AI architecture, cybersecurity, infrastructure, technical strategy, and complex execution.
Start a conversation