Solutions / Delivered

Architectures we built, running in production.

Five AI applications designed, engineered, and delivered to production for clients in online retail and managed security services. Each one solves a problem that rule-based systems structurally cannot.

These are not reference diagrams or proposals. Each is a system that shipped: the services it runs on, the way the pipeline is wired, the guardrails that hold it inside its contract, the risks we still track, and what changed for the business after it went live.

Every one of them was designed secure by default. Adversarial input handling, output contracts, least-privilege tool grants, and audit trails are part of the architecture rather than a hardening pass at the end. Where an LLM touches untrusted text, there is a control between the two.

Delivered
5 production systems
Clouds
AWS · Azure · Google Cloud
Sectors
Online retail · MSSP
Common thread
Secure by design
Architectures / 05 delivered

Five systems, three clouds, two sectors.

Each write-up covers the same ground: the problem the client actually had, the services the system runs on, how the pipeline is wired end to end, the guardrails, the risks we still watch, and the outcome.

Architecture 01 Online retailer
Mid-size fashion retailer

Behavioral Inventory Demand Forecasting

A fine-tuned time-series foundation model on SageMaker, fed by a Bedrock enrichment pipeline that turns raw social trend content into structured features the forecaster can actually use.

CloudAWS, fully cloud-native
Forecast modelFine-tuned Chronos FM
LLM layerBedrock, Claude Sonnet
Read the architecture
Architecture 02 MSSP
200+ enterprise clients

Autonomous Threat Triage Agent

A LangGraph agent that gathers its own investigation context across SIEM, threat intelligence, and asset data, under least-privilege tool grants and an append-only audit log, with a human gate before anything reaches a client.

DeploymentHybrid, Azure plus on-prem SOC
OrchestrationLangGraph state machine
ModelAzure OpenAI GPT-4o, sovereign tenant
Read the architecture
Architecture 03 Online retailer
High-volume e-commerce

Return Fraud Detection at Scale

A custom graph neural network that scores return authorizations in-line, with an LLM second opinion reserved for the ambiguous band, all inside a hard VPC Service Controls perimeter with differential privacy on training.

CloudGoogle Cloud, fully cloud-native
Primary modelCustom GNN on Vertex AI
Escalation modelGemini Pro, gray-zone only
Read the architecture
Architecture 04 MSSP
Security awareness practice

Adaptive Phishing Simulation Engine

Per-target phishing simulations generated on Bedrock and independently reviewed by a second Claude endpoint before anything is queued, with HR data treated as untrusted input and every prompt and response written to an audit log.

CloudAWS, fully cloud-native
GenerationBedrock, Claude Sonnet
ReviewSecond Claude, safety persona
Read the architecture
Architecture 05 Online retailer
Large marketplace operator

Supplier Contract Anomaly Detection

A retrieval pipeline that compares every incoming supplier document against the clauses of the contract that governs it, with supplier-controlled text kept out of the instruction context and output locked to a strict anomaly schema.

CloudAzure, fully cloud-native
PatternRAG clause-level comparison
ModelAzure OpenAI GPT-4o
Read the architecture
Architecture 06 Yours

The one we have not built yet.

If your problem looks like these, meaning it needs judgment across signals no rule can enumerate, it is worth a conversation.

Most engagements start with a short, paid R&D sprint so both sides can decide if it is a fit. If we are not the right call, we will say so early.

Start a conversation

On client identity. Client names and any identifying detail are withheld under NDA. Sector, scale, and architecture are described accurately; the specifics that would identify an organization are not. Metrics are stated as direction and materiality rather than as figures we are not free to publish.