Skip to content
View ancveirs-lv's full-sized avatar
🇱🇻
Alive and kicking
🇱🇻
Alive and kicking

Organizations

@finulio

Block or report ancveirs-lv

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
ancveirs-lv/README.md

Zigmārs Ancveirs

Latviski · English

LinkedIn ORCID SSRN

Technology leader · software engineer · independent cybersecurity researcher

I design, build and assess digital systems where security, data integrity, regulation, auditability and operational resilience matter.

I have spent 25+ years working with software and digital systems across product engineering, architecture, data platforms, cybersecurity, fraud prevention and operational infrastructure. I am especially interested in the boundary between what a requirement says and what a working system can actually demonstrate.

My recurring question is:

What evidence would show that the system, control or process actually works as claimed?

I prefer systems that are secure, observable, reproducible and boringly reliable.

Selected public work

A bilingual, evidence-based public reference for proposals on Latvia's digital governance, cybersecurity, coordinated vulnerability disclosure, vulnerability prioritisation, civil protection and critical-process resilience.

Its working model is:

source → claim → proposal → control → pilot → acceptance evidence

The repository separates source-backed facts from project recommendations and defines what evidence would be needed before a proposal should progress beyond a bounded pilot.

A bilingual reference for explaining cybersecurity roles, authorization boundaries, vulnerability-disclosure mechanisms and evidence quality.

Its core questions are:

role → authorization → evidence → accountability

The project distinguishes established professional concepts from inconsistent jargon and editorial metaphors.

Bilingual, evidence-backed password security guidance for users, product teams and service owners. The English edition is global; the Latvian edition is a localisation layer. The project separates user advice from service-side password-policy requirements and explicitly addresses common password myths.

Its evidence model is:

source → claim → guidance → validation

A 25-rule bilingual cybersecurity baseline for everyday digital life. The English edition is global, while the Latvian edition localises selected implementation details such as reporting paths and protective services without presenting them as global requirements.

Its evidence model is:

source → control → localised guidance → validation

Open Self-Assessment Family

Four bilingual, evidence-oriented self-assessment repositories covering executive digital governance, individual digital competence, organisational cybersecurity readiness and personal cybersecurity. The English editions are global baselines; the Latvian editions are localisation layers.

The shared model is:

source → domain → question → response state → gap → action → reassessment

The family intentionally avoids a single overall safety, compliance or maturity score and makes unknown or unsupported states visible.

The v0.1.1 family baseline was hardened through a five-direction skeptical audit covering methodology, source fidelity, coverage and duplication, EN/LV localisation, and scoring/evidence semantics.

A bilingual release-readiness baseline for AI-assisted software development: 32 controls across eight domains, plus 16 diagnostic indicators for common AI-assisted development failure patterns.

Its evidence-based gate distinguishes BLOCKED, CONDITIONAL and READY without assigning an overall security score. The published v0.1.1 baseline includes a five-direction skeptical audit and release-contract hardening; it is not a certification or a substitute for independent security assessment.

Research

When Severity and Exploitation Signals Diverge

A Cross-Sectional Study of CISA Known Exploited Vulnerabilities

SSRN / DOI 10.2139/ssrn.7355200

Current research directions include:

  • vulnerability severity versus exploitation evidence;
  • CVSS, EPSS and KEV as distinct decision signals;
  • vulnerability prioritisation under operational constraints;
  • coordinated vulnerability disclosure and vulnerability reporting;
  • software supply-chain evidence;
  • digital resilience and degraded operation;
  • evidence-based cybersecurity assurance.

Focus

Cybersecurity engineering

Secure architecture, threat modelling, adversarial testing, ethical hacking, attack-surface analysis and vulnerability-management processes.

FinTech & RegTech

Financial and regulatory systems where integrity, traceability, auditability and operational controls are first-class requirements.

CivTech & digital resilience

Technology for public-interest services, institutional resilience, civil protection and trustworthy public digital infrastructure.

Data & reliability engineering

Data provenance, validation, versioned datasets, schema evolution, change detection, reproducible processing and operational observability.

AI engineering & governance

AI-assisted workflows with structured outputs, validation boundaries, provenance, deterministic controls where appropriate and explicit human authority.

Technical due diligence

Architecture, security, data quality, operational risk, maintainability, trust boundaries and engineering evidence.

Policy, standards & implementation

I work at the intersection of engineering, cybersecurity policy, regulation and standards implementation.

The areas I work on and follow closely include:

  • EU Cyber Resilience Act implementation;
  • coordinated vulnerability disclosure and good-faith security research;
  • vulnerability reporting and prioritisation;
  • secure-by-design and secure-by-default practices;
  • software supply-chain security and SBOM interoperability;
  • cybersecurity assurance and conformity evidence;
  • ICT lifecycle traceability;
  • AI cybersecurity and governance;
  • resilience of public digital infrastructure.

The engineering chain I care about is:

policy → standards → engineering controls → operational evidence → assurance

Engineering principles

Evidence first. Important claims should be backed by data, logs, source material or reproducible system state.

Traceability by design. Changes, decisions, data transformations and deployed artefacts should be attributable and reconstructable.

Contracts before assumptions. Explicit schemas, APIs, invariants and compatibility rules are preferable to undocumented behaviour.

Security and privacy by design. Least privilege, secure defaults, minimal data collection and explicit trust boundaries belong in the architecture.

Resilience includes degraded operation. Important systems should deliberately define and test how they behave when normal operation is unavailable.

AI is not a source of truth. Consequential AI-assisted outputs need validation boundaries, provenance, reliable evidence and clear human authority.

Technical stack

Software

Go · Python · TypeScript · JavaScript · Dart · PHP

Backend & platforms

REST APIs · event-driven systems · asynchronous processing · distributed services · authentication & authorisation · integration architecture

Data

PostgreSQL · Redis · data pipelines · validation · provenance · schema evolution · snapshots · diffs · anomaly detection

Infrastructure

Linux · containers · cloud/edge architecture · reverse proxies · CI/CD · observability · deployment automation · performance engineering

Security

Threat modelling · secure architecture · least privilege · adversarial testing · ethical hacking · vulnerability research · privacy engineering

AI

LLM-assisted systems · structured outputs · retrieval · validation · guardrails · human oversight · evidence-backed automation

Collaboration

I am open to selected technical, research, policy-implementation and strategic collaborations involving:

  • secure web, API and data platforms;
  • cybersecurity and adversarial testing;
  • vulnerability management and coordinated disclosure;
  • FinTech and RegTech architecture;
  • fraud and abuse prevention;
  • software supply-chain security;
  • data provenance and monitoring;
  • AI-assisted automation with strong validation boundaries;
  • cybersecurity policy implementation and technical standards;
  • technical due diligence;
  • high-trust and public-interest digital systems.

The best fit is work where architecture, security, data, regulation and accountability need to function as one system rather than separate workstreams.

Scope

This README is a professional profile, not an evidence register or legal statement.

For source-backed technical and policy claims, methodology, licensing and contribution rules, use the linked project repositories and their own documentation.

Pinned Loading

  1. latvia-digital-resilience latvia-digital-resilience Public

    Bilingual evidence-based reference for Latvia's digital governance, cybersecurity and public resilience

    Python