Latviski · English
Technology leader · software engineer · independent cybersecurity researcher
I design, build and assess digital systems where security, data integrity, regulation, auditability and operational resilience matter.
I have spent 25+ years working with software and digital systems across product engineering, architecture, data platforms, cybersecurity, fraud prevention and operational infrastructure. I am especially interested in the boundary between what a requirement says and what a working system can actually demonstrate.
My recurring question is:
What evidence would show that the system, control or process actually works as claimed?
I prefer systems that are secure, observable, reproducible and boringly reliable.
A bilingual, evidence-based public reference for proposals on Latvia's digital governance, cybersecurity, coordinated vulnerability disclosure, vulnerability prioritisation, civil protection and critical-process resilience.
Its working model is:
source → claim → proposal → control → pilot → acceptance evidence
The repository separates source-backed facts from project recommendations and defines what evidence would be needed before a proposal should progress beyond a bounded pilot.
A bilingual reference for explaining cybersecurity roles, authorization boundaries, vulnerability-disclosure mechanisms and evidence quality.
Its core questions are:
role → authorization → evidence → accountability
The project distinguishes established professional concepts from inconsistent jargon and editorial metaphors.
Bilingual, evidence-backed password security guidance for users, product teams and service owners. The English edition is global; the Latvian edition is a localisation layer. The project separates user advice from service-side password-policy requirements and explicitly addresses common password myths.
Its evidence model is:
source → claim → guidance → validation
A 25-rule bilingual cybersecurity baseline for everyday digital life. The English edition is global, while the Latvian edition localises selected implementation details such as reporting paths and protective services without presenting them as global requirements.
Its evidence model is:
source → control → localised guidance → validation
Four bilingual, evidence-oriented self-assessment repositories covering executive digital governance, individual digital competence, organisational cybersecurity readiness and personal cybersecurity. The English editions are global baselines; the Latvian editions are localisation layers.
The shared model is:
source → domain → question → response state → gap → action → reassessment
The family intentionally avoids a single overall safety, compliance or maturity score and makes unknown or unsupported states visible.
- Executive Digital Governance Self-Assessment — governance evidence and decision readiness for executives, owners and boards.
- Digital Competence Self-Assessment — DigComp 3.0-aligned capability self-assessment for individuals, with project-specific response semantics.
- Cybersecurity Readiness Self-Assessment — NIST CSF 2.0-aligned organisational readiness and evidence-gap assessment.
- Personal Cybersecurity Self-Assessment — practice-based assessment of accounts, devices, data, fraud resistance and recovery readiness.
The v0.1.1 family baseline was hardened through a five-direction skeptical audit covering methodology, source fidelity, coverage and duplication, EN/LV localisation, and scoring/evidence semantics.
A bilingual release-readiness baseline for AI-assisted software development: 32 controls across eight domains, plus 16 diagnostic indicators for common AI-assisted development failure patterns.
Its evidence-based gate distinguishes BLOCKED, CONDITIONAL and READY without assigning an overall security score. The published v0.1.1 baseline includes a five-direction skeptical audit and release-contract hardening; it is not a certification or a substitute for independent security assessment.
A Cross-Sectional Study of CISA Known Exploited Vulnerabilities
SSRN / DOI 10.2139/ssrn.7355200
Current research directions include:
- vulnerability severity versus exploitation evidence;
- CVSS, EPSS and KEV as distinct decision signals;
- vulnerability prioritisation under operational constraints;
- coordinated vulnerability disclosure and vulnerability reporting;
- software supply-chain evidence;
- digital resilience and degraded operation;
- evidence-based cybersecurity assurance.
Cybersecurity engineering
Secure architecture, threat modelling, adversarial testing, ethical hacking, attack-surface analysis and vulnerability-management processes.
FinTech & RegTech
Financial and regulatory systems where integrity, traceability, auditability and operational controls are first-class requirements.
CivTech & digital resilience
Technology for public-interest services, institutional resilience, civil protection and trustworthy public digital infrastructure.
Data & reliability engineering
Data provenance, validation, versioned datasets, schema evolution, change detection, reproducible processing and operational observability.
AI engineering & governance
AI-assisted workflows with structured outputs, validation boundaries, provenance, deterministic controls where appropriate and explicit human authority.
Technical due diligence
Architecture, security, data quality, operational risk, maintainability, trust boundaries and engineering evidence.
I work at the intersection of engineering, cybersecurity policy, regulation and standards implementation.
The areas I work on and follow closely include:
- EU Cyber Resilience Act implementation;
- coordinated vulnerability disclosure and good-faith security research;
- vulnerability reporting and prioritisation;
- secure-by-design and secure-by-default practices;
- software supply-chain security and SBOM interoperability;
- cybersecurity assurance and conformity evidence;
- ICT lifecycle traceability;
- AI cybersecurity and governance;
- resilience of public digital infrastructure.
The engineering chain I care about is:
policy → standards → engineering controls → operational evidence → assurance
Evidence first. Important claims should be backed by data, logs, source material or reproducible system state.
Traceability by design. Changes, decisions, data transformations and deployed artefacts should be attributable and reconstructable.
Contracts before assumptions. Explicit schemas, APIs, invariants and compatibility rules are preferable to undocumented behaviour.
Security and privacy by design. Least privilege, secure defaults, minimal data collection and explicit trust boundaries belong in the architecture.
Resilience includes degraded operation. Important systems should deliberately define and test how they behave when normal operation is unavailable.
AI is not a source of truth. Consequential AI-assisted outputs need validation boundaries, provenance, reliable evidence and clear human authority.
Software
Go · Python · TypeScript · JavaScript · Dart · PHP
Backend & platforms
REST APIs · event-driven systems · asynchronous processing · distributed services · authentication & authorisation · integration architecture
Data
PostgreSQL · Redis · data pipelines · validation · provenance · schema evolution · snapshots · diffs · anomaly detection
Infrastructure
Linux · containers · cloud/edge architecture · reverse proxies · CI/CD · observability · deployment automation · performance engineering
Security
Threat modelling · secure architecture · least privilege · adversarial testing · ethical hacking · vulnerability research · privacy engineering
AI
LLM-assisted systems · structured outputs · retrieval · validation · guardrails · human oversight · evidence-backed automation
I am open to selected technical, research, policy-implementation and strategic collaborations involving:
- secure web, API and data platforms;
- cybersecurity and adversarial testing;
- vulnerability management and coordinated disclosure;
- FinTech and RegTech architecture;
- fraud and abuse prevention;
- software supply-chain security;
- data provenance and monitoring;
- AI-assisted automation with strong validation boundaries;
- cybersecurity policy implementation and technical standards;
- technical due diligence;
- high-trust and public-interest digital systems.
The best fit is work where architecture, security, data, regulation and accountability need to function as one system rather than separate workstreams.
This README is a professional profile, not an evidence register or legal statement.
For source-backed technical and policy claims, methodology, licensing and contribution rules, use the linked project repositories and their own documentation.