Selected work

Shipped, in production.

A sample of delivered engagements across trading, self-hosted infrastructure, identity, deployment and the web. Some detail is kept deliberately light; the work is real.

Selected work

A sample of delivered engagements.

Development-led, ordered by weight. Some clients are confidential; the studio's own projects are named.

01

KapiPalpiBot

Full-stack · Trading · 24/7
$SIGNALSRISK GATEORDERBROKER

An automated crypto trading bot that filters three independent signal sources through one central risk gate and executes on Binance futures and spot. Roughly 45k lines of Python with 2,300+ tests, engineered observe-first: every change ships flag-gated and shadow-logged until out-of-sample validation proves its edge. Runs 24/7 as a systemd service on Oracle Cloud, behind a TLS-secured dashboard and read-only JSON API, with a multi-provider AI classification layer, and a parity-proven Python 3.9 to 3.12 migration.

PythonAPI ManagementRisk engineBacktestingAI classificationsystemdOracle Cloud
02

minisko

Self-hosted · Security · AI
HOME · KEYSSPECSANDBOXPR

A production-grade, private-by-default homelab running 20+ containerized and native services on a single Mac mini M4, defined end to end as version-controlled infrastructure-as-code. A native Caddy reverse proxy fronts every service on its own subdomain with automatic HTTPS over ACME DNS-01, reachable only across a Tailscale tailnet and never publicly exposed. Its flagship, vibecode, is an always-on autonomous-coding console driving the Aider agent on local Ollama models or any OpenAI-compatible API — each task isolated in its own git worktree behind a human review gate, pull requests opened under a dedicated bot identity. Security is the core of the work: every agent run is sealed in a macOS Seatbelt sandbox that blacks out the home directory and exposes only the active project, so even a third-party API key can read no other secret, key or repo — verified empirically, with egress pinning, symlink-escape detection and a write-tamper canary.

Apple SiliconDocker / ColimaCaddyTailscaleOllama / local LLMsAiderSeatbelt sandbox
03

Identity & login framework

Security · Back-end
OAuthSAML · eIDAPPBROKER

A generic authentication broker giving applications one integration surface to multiple Dutch and European electronic identity (eID) schemes, delegating each login over SAML while applications connect via OAuth 2.0. Built in C# on ASP.NET Core around a provider model, so new identity providers drop in by configuration, and shipped with a full testbed that mocks the providers to make authentication verifiable outside production, packaged for reuse via NuGet. Delivered for a European IT-services company as a TU Delft software project.

.NETC#ASP.NET CoreSAMLOAuth 2.0Identity ProviderScrum
04

Software deployment platform

DevOps · Tooling
ROLLOUT → v1.3DEVTESTPRODDEPLOYED

Software for deploying and managing different versions of an application across hardware. A Django back end drives the orchestration; an Angular front end gives operators a control surface over what runs where.

PythonDjangoAngularVersioningDeployment
05

Lecture scheduling platform

Back-end · Microservices
TIMETABLE

A pandemic-era lecture-scheduling system that assigns lectures to halls by capacity and time-slot, and students to online or on-campus seats under a rule that everyone attends in person at least once a fortnight, with every threshold left dynamically configurable as government rules shifted. A headless, API-only microservice build: Java 11 / Spring Boot services (gateway, schedulers and room/lecture/course/user managers) assembled with Gradle, secured with Spring Security and NetID auth, over a MySQL database on AWS. Hardened with unit and mutation testing plus static analysis. A TU Delft CSE2115 team project.

JavaSpring BootMicroservicesMySQLAWSSpring SecurityMutation testing
06

Campus management platform

Full-stack · Desktop
ROOM · BIKE · MEAL

A campus-management desktop application for booking rooms and bikes and ordering food across the TU Delft campus, with role-based access for students, lecturers and administrators. A Java client-server build: Spring (MVC, Security, JPA/Hibernate) over a MySQL database on the back end, a JavaFX desktop client on the front, talking over a standardised JSON protocol, with token-authenticated login and rich filtering across rooms, facilities and restaurants. Built by a seven-person team for the Object-Oriented Programming Project.

JavaSpringSpring SecurityHibernateMySQLJavaFXREST API
07

Tailored Projects

Full-stack · Web
BESPOKE BUILD

Bespoke applications, websites and projects, designed and built end to end: fast, hand-built, with no template underneath. Not everything is listed here; feel free to get in touch to explore and discuss the rest.

Full-stackWeb developmentResponsiveDatabase ManagementDesign

Want something built to the same standard?

Start a project