Shipyard / Security Manifest

Security Projects and Capabilities

Security work in progressAI security and red-team work

Runnable AI security research, red-team practice, and the application security and response work that surrounds them. Platform and product engineering is the depth underneath, not the headline.

01

Active focus

AI Security LabAI Security Research

Ten runnable vulnerable agents, one per OWASP LLM Top 10 category, with an attacker payload library, an evaluation harness, a spotlighting defense toggle, and a writeup for each.

  • OWASP LLM Top 10
  • Prompt injection
  • Agent tooling
  • Security writeups
02

Flight proven

Red TeamRed Team and Offensive Security

Internal red-team operations, application-layer penetration testing, vulnerability research, and proof-of-concept exploit development that turns findings into engineering priorities.

  • Penetration testing
  • Vulnerability research
  • Exploit PoCs
  • Secure code review
03

Flight proven

AppSec and ResponseApplication Security and Event Response

Threat modeling, trust-boundary analysis, CI/CD hardening, and the triage, containment, and postmortem work that follows a security event.

  • Threat modeling
  • Trust boundaries
  • Incident triage
  • Postmortems
04

Supporting evidence

Platform DepthPlatform and Product Depth

Two decades of distributed IoT, smart-access, cloud, mobile, and API systems in Swift, Kotlin, C++, TypeScript, Go, Python, and GraphQL. This is the working knowledge behind the security work, not a separate practice.

  • Distributed systems
  • IoT and cloud
  • Native mobile
  • GraphQL and APIs