AI engineering & backend architecture
I build LLM systems — and I build them so you can ship them.
RAG pipelines, agents and tool layers, self-hosted inference when your data can’t leave the building — and the engineering that makes them trustworthy in production: grounding and verification, evals, guardrails, and hard spend limits. Most AI demos work; the gap is everything between a demo and a system you’d put in front of customers — in Grant Thornton’s 2026 survey, 78% of leaders weren’t confident they could pass an independent AI-governance audit within 90 days. Thirty years in software — developer, then team lead, the last seven in security, governance and compliance. I design it, build it, and can run it.
- Building software since 1993
- CISOteria — GRC SaaS architect (7 yrs)
- National Cyber Directorate GRC portal — backend lead
- Flixel founder · 7 patents
- IDF Major (ret.)
- EOSIO StackExchange — #11 globally
- B.Sc. Math & Physics, TAU
What I do
LLM systems & RAG
Retrieval pipelines, agents, and typed tool layers over your own data — including fully self-hosted on open-weights models when nothing may leave your infrastructure. Built with the parts that decide whether it survives contact with real users: grounding and verification steps, evals against a golden set, and human approval gates on anything that changes state.
AI security & spend control
Hard spend caps and fail-closed limits for live LLM apps and agents — denial-of-wallet control I built and run as Guardrail, an AI gateway. Around it I design the rest of the stack — prompt-injection defense, PII redaction, output validation — from proven tooling, mapped to the EU AI Act / ISO 42001.
Audit-readiness & tamper-evident trails
The evidence an auditor, regulator, or board actually asks for: independently verifiable, tamper-evident audit trails for your AI systems and records — self-hosted, no third-party dependency. My blockchain background, pointed at AI governance.
GRC & compliance engineering
Seven years as backend architect for CISOteria (GRC / compliance SaaS); this past year, an app for the Israel National Cyber Directorate. I turn regulatory obligations into working, enforced controls — not slideware.
Fractional architect for regulated SaaS
Multi-tenant SaaS, API and data-layer design, legacy modernization, containerization — owned end to end. Available as a fractional architect when you need senior ownership, not just hands.
Selected work

CISOteria
Security-compliance (GRC) SaaS · backend architect, 2019–2026
Multi-tenant CISO / compliance platform, also powering the Israel National Cyber Directorate’s GRC portal. I own the API, data model, and architecture — Node.js + a modernized PHP core, MariaDB / Redis / Docker, vulnerability dashboards and analytics, SSO / SAML.

CISOteria — asset risk graph (D3)
Compliance data-viz · D3.js hierarchy
A D3 hierarchy I built for CISOteria: an asset’s risk score traced down to the systems and infrastructure it depends on — colour-coded by risk, so the weakest link is obvious.

Israel National Cyber Directorate — GRC portal
grc.cyber.gov.il · built at CISOteria · backend lead
The Israel National Cyber Directorate’s governance-risk-compliance portal, powered by CISOteria (“Cyber OS”). I led most of the backend and built parts of the front end.

IMS — interactive weather map
Israel Meteorological Service · front-end / data-viz
Map-overlay work I contributed to the Israel Meteorological Service (ims.gov.il) — data overlays on their interactive synoptic forecast maps.

ChainVault
Private-blockchain deal room
Tamper-proof real-estate closing platform with on-chain wire-fraud prevention — a 4-node Antelope / BFT chain and a client-side-encrypted document vault.

Verarta
Art provenance on a private chain
Immutable provenance records for artworks — no third-party dependency, full audit trail.
Smallest Business
Cloud & AI-cost engineering
My consultancy and a daily learn-in-public series on cutting cloud bills and controlling AI spend.
More from me
Controlling the AI you can’t fully trust — its cost, its abuse, and its compliance.
I write near-daily about the practical side — cutting cloud bills and keeping AI spend and abuse under control — at smallestbusiness.com . Get the posts by email, or read them there.
Or read at smallestbusiness.com →Not sure where your AI exposure is? Start focused: a fixed-price AI Security & Audit-Readiness Teardown — a written read on what’s exposed and what to fix first. Or book a call and tell me what you’re building.