Skip to content
View mazze93's full-sized avatar
:atom:
Building
:atom:
Building

Organizations

@Secure-Pride

Block or report mazze93

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
mazze93/README.md

A geological cross-section, fractured by two fault lines, reading: I build systems that cannot conceal their own state

Security engineering, open infrastructure, and AI evaluation for systems that should fail visibly, not silently.

mazzeleczzare.com  ·  ORCID  ·  Get in touch


Thesis

Systems reveal themselves under pressure — that's the working premise behind everything in this profile. I build and test for observable state: security tooling, privacy-preserving infrastructure, and human-AI systems designed so that failure surfaces early instead of getting buried under a passing test suite.

Every project here is built against the same constraint: it has to work, be auditable, and be legible to people who aren't security engineers.


Current Excavations

  • Hardening privacy-first, local-first infrastructure (Meridian, mindful-dev)
  • Building policy guardrails and integrity telemetry for agentic AI (praxis-aegis, stele)
  • Extending forensic tooling and MCP-server infrastructure (git-forensics-agent, kairos-mcp)
  • Writing on privacy infrastructure and human–AI collaboration

Work Strata

Domain Focus Typical output
Security & privacy infrastructure Threat-informed hardening, container/CI security, adversarial-conditions design tooling, templates, audits
Trustworthy & agentic AI Policy guardrails, integrity telemetry, epistemic decision logging guardrail libraries, ledgers, research notes
Apps & product design Local-first sync, E2E-encrypted social systems, editorial platforms shipped apps, calm UX under real constraints

Bedrock

The load-bearing layer — the sites where the evidence checks out cleanly against the claims. Not a "best of," a "checked."

  • mazze-leczzare-blog — 16 published essays, five green CI pipelines (build, CodeQL, dependency review, docs integrity, Lighthouse), live.
  • secure-container-template — non-root enforcement gated in CI, actions pinned to commit SHAs, a release that's actually shipped.
  • kairos-mcp — MCP server for reasoning frameworks, dual transport, real tests, clean dependency hygiene.
  • github-mcp-gateway — GitHub App OAuth gateway for MCP clients, in active daily use.
  • stratum — dual Python/TS implementation with parity checked in CI, doc-drift detection, a live Cloudflare Worker demo.

Selected Sites

Three exposures, drilled from the same face. Expand a core sample to see what's in it.

Security & privacy infrastructure
Project What it does
secure-pride Privacy-first cybersecurity tools and standards for LGBTQ+ communities and high-risk groups, built for adversarial conditions
git-forensics-agent Zero-knowledge forensic case-file agent for adversarial git incidents — Durable Object brain, AES-256-GCM, HMAC-signed repair gate
mindful-dev Claude Code pre-action safety gate — blocks dangerous commands, redacts secrets, guards shell access
Trustworthy AI & agentic systems
Project What it does Live
praxis-aegis Trust-layer for agentic AI: policy guardrails and signing-aware controls for AI tool use
stele Directive compiler and integrity telemetry — governance-as-code for AI-assisted work stele.mazzeleczzare.com
context-synapse Experimental engine for modeling how humans and AI systems negotiate context
adaptive-response Schema-driven AI response engine — Cloudflare Worker + Zod-validated typed output, deny-by-default CORS
Apps & product design
Project What it does
meridian Privacy-first, local-first calendar for Apple platforms — Tailscale-only peer sync, no cloud
lockr Privacy-first dating and social app for the LGBTQ+ community — E2E encryption, safety-first design
daedalus-switch Identity & context switcher — one command switches VPN, terminal, browser, and filesystem context

Instrument Panel

Python TypeScript PostgreSQL Docker Cloudflare GitHub Actions Tailscale

The instruments that show up across these sites, not a full résumé of tools.


Research Line

Essays, technical notes, and research on privacy infrastructure, human–AI collaboration, and open-source systems thinking.

mazzeleczzare.com  ·  ORCID 0009-0005-9661-4780


Build Philosophy

Software should be secure, humane, understandable, and accessible to people who aren't security engineers.

That's not a nice-to-have. That's the constraint every project here is built against.


Work Together

Open to collaboration on privacy tooling, secure infrastructure, and human–AI systems — especially with researchers, independent builders, and mission-driven organizations.

Open an issue, or reach out directly.

Pinned Loading

  1. stratum stratum Public

    Epistemic decision ledger: append-only event log with evidence-gated trust, deterministic Tessera projection, and a human control room. TypeScript + Cloudflare Workers.

    HTML 2

  2. github-mcp-gateway github-mcp-gateway Public template

    Self-hosted remote MCP server on Cloudflare Workers — GitHub App OAuth 2.1 gateway (PKCE, DCR, CIMD) exposing 21 repo/issue/PR/contents/search tools to Claude Code, Claude.ai, and any MCP client

    TypeScript 1

  3. stele stele Public

    STELE — egregore compiler and integrity telemetry. Posture: GUARDIAN.

    TypeScript 1

  4. mazze-leczzare-blog mazze-leczzare-blog Public

    Personal editorial platform for essays, privacy writing, and security-forward design. Built with Astro + Cloudflare Pages.

    HTML 2

  5. context-synapse context-synapse Public

    Local-first Bayesian prompt engine for human-AI context negotiation — Swift, no remote transmission

    Swift 2 1

  6. secure-pride secure-pride Public

    Privacy-first cybersecurity tools and standards for LGBTQ+ communities and high-risk groups, built for adversarial threat models where exposure has real consequences.

    JavaScript 2