Software development service

Privacy & Secure Systems Engineering

I design software around the data it should protect and the metadata it should avoid collecting.

What this service covers

I design software around the data it should protect and the metadata it should avoid collecting.

  • Privacy-first application architecture
  • End-to-end encrypted communications
  • Secure authentication and identity boundaries
  • Tor or P2P integration where appropriate
  • Local-first storage and data clearing
  • Threat modeling and failure-path review

How I build it

The first question is what the system can learn about a user and what happens when a component is compromised. That guides choices about central servers, transport, storage and logs.

Gumnam routes traffic through Tor hidden services, uses a Rust core for encrypted messaging and keeps local state in SQLite. Its design also considers peer availability with a libp2p Kademlia fallback.

Engineering decisions

Metadata can leak even when message content is encrypted. Identity verification, message validation, retention and backup behavior must be addressed alongside the cipher suite.

A privacy design should state its limits. Tor, local storage and encryption reduce specific risks; they do not eliminate all operational or endpoint threats.

Related project work

The Gumnam case study provides a concrete privacy-focused project example and links to its public source.

Technology and scope

Rust, Tor hidden services, libp2p, SQLite, Ed25519, X25519, ChaCha20-Poly1305 and HKDF are represented in Gumnam.

Getting started

Describe your users, sensitive data, threat model and acceptable operational trade-offs. We can then scope protections around real risks.

Have a project in mind?

Let’s talk about privacy & secure systems engineering.

Share your goals, current system and timeline. I can help scope the architecture and implementation.