SYS / ONLINE
/ root / identity / @canstralian

stephen.esteban_

solopreneur / systems builder / operator

Engineering creativity into systems that think. I build intelligent, governed software — AI agents, runtime governance, cybersecurity, automation, and experimental hardware — for environments where the boundary between what a model wants to do and what a system is willing to let it do actually matters.

github / canstralian ↗ huggingface / canstralian ↗ open to interesting control-plane work
◆ policy-engine/ ◆ runtime-posture/ ◆ governed-mcp/ ◆ decision-replay/ ◆ append-only-evidence/ ◆ openwrt-auditing/ ◆ adversarial-ml/ ◆ zero-trust/ ◆ control-plane/ ◆ edge-intelligence/ ◆ reverse-engineering/ ◆ harden-by-default/
// 01 / operating principles

A model may propose.
The system decides.

I build intelligent systems with the assumption that they will eventually be wrong, malicious, or both. So every capability boundary is gated, every decision is recorded, and every action is replayable.

principle / 001

deny by default

Capabilities are closed until policy says otherwise. Confidence is not authorization — explicit grants are.

principle / 002

append-only evidence

Decisions, posture transitions, and capability crossings are persisted as tamper-evident records — replayable into runtime state on demand.

principle / 003

zero trust across the stack

From ESP32 firmware to API gateways. Hardware isolation, signed control-plane operations, authenticated boundaries everywhere.

principle / 004

spec before claim

Architectures and proposals stay in separate documents from shipped behaviour. The repo is the source of truth — not the slide deck.

// 02 / architecture — rif runtime

Decision flow, drawn honestly.

source · github.com/canstralian/rif-runtime
agent / caller agent:orchestrator propose(action) POLICY ENGINE · deny by default · env-aware constraints · posture context · governance graph /v1/policy/evaluate deny allow governed capability mcp · http · tool decision · denied jsonl · append-only PERSISTENCE · JSONL · POSTURE HISTORY append-only decision log · supabase · jwt-verified tamper-evident · replayable replay / audit reconstruct state
inputs
actor · action · target · posture · env
outputs
decision · reason · evidence · posture delta
invariant
model output ≠ authorization
// 03 / projects

Evidence, not claims.

view full registry →
MOD.001 / flagship · agentic runtime
active development

rif/runtime

governance-first runtime for agent-driven systems

A policy and governance runtime that evaluates proposed actions before they cross a capability boundary, maintains runtime posture, and records decision history for inspection and replay. Built around a deliberately simple premise: a model may propose. RIF decides.

capabilities
policy · posture · replay
interfaces
fastapi · typer · mcp
storage
jsonl · supabase · plpgsql
python 3.12 · 3.13 docker mit deny-by-default mcp-governed
MOD.002 edge · hardware

beryl-ax-pineapple

Re-engineers the GL.iNet GL-MT3000 (Beryl AX) into an open, modular wireless auditing platform built on OpenWrt.

openwrt wifi audit shell
repository →
MOD.003 edge · package mgr

beryl-manager

A modern package and plugin manager built for GL.iNet Beryl AX routers — a control center for OpenWRT.

typescript openwrt plugin
repository →
MOD.004 finance · ml

aitradepro

AI-enhanced trading analysis platform with real-time market data, RAG-augmented analysis, and a Bloomberg-terminal-inspired interface.

rag realtime full-stack
repository →
MOD.005 security · recon

autorecon

Multi-threaded network reconnaissance tool that performs automated enumeration of services across targets.

python multi-threaded enum
repository →
MOD.006 security · os

bugbountyos

Modular security operating system for automated bug bounty hunting. A stack, not a single tool.

modular automation os
repository →
MOD.007 huggingface · model

pentest_ai

13B parameter transformer model focused on offensive and defensive cybersecurity tasks — pen-testing, recon, and task automation. Published as a capability probe, not a deployment claim.

13b causal-lm secops
model card →
MOD.008 security · corpus

wordlists

Curated wordlists for offensive and defensive security workflows — pen-testing, password strength, brute-force research.

corpus research hf dataset
dataset →
MOD.009 huggingface · spaces

hf spaces · registry

A live registry of Gradio spaces — agents, code generation, SQL-from-natural-language, exploit analysis. Mix of experimental and paused surfaces.

gradio agents sql-nl
full registry →

// note — module ids are arbitrary. the catalogue reflects publicly shipped work, not aspirations.

// 04 / operating envelope

Where I take work seriously.

DOM.A · ai agents & runtime governance

Designing the policy layer between intelligent systems and the capabilities they can reach. Deny-by-default, posture-aware, replayable.

policy-engine mcp-governance decision-replay posture-management agent-loop
DOM.B · cybersecurity · full spectrum

Offensive research, defensive tooling, and the automation that closes the loop. CTF-rooted, zero-trust throughout the stack.

recon wireless-audit adversarial-ml ctf reverse-engineering
DOM.C · automation & orchestration

Self-optimising infrastructure loops — detection → remediation, drift → tuning, threat → adaptation. Workflows that survive operator absence.

github-actions control-loops observability ci-gates
DOM.D · experimental hardware · edge

Edge intelligence on Raspberry Pi and ESP32. Custom firmware, sensor systems, and devices that bridge physical signals into governed software loops.

esp32 raspberry-pi edge-ml openwrt firmware
// 05 / snapshot

Honest telemetry.

as of public profiles · static
github / repos
306.
public
hf / models
1.
pentest_ai
hf / spaces
~90.
mixed state
since
2014.
github joined

// numbers are a snapshot, not a score. they describe the surface area of what's been put into the world.

// 06 / connect

If you're building systems
that need a control plane — let's talk.

I take on a small number of engagements where the work involves governed AI, agentic runtimes, security automation, or edge intelligence. Reach out through the channels below.