Engineering Portfolio

Nick Forshteyn
Security & AI Evangelist

I build production AI platforms and the secure enterprise infrastructure behind them. 20+ years shipping systems for Australian Government, Defence, healthcare, fintech, and critical infrastructure.

Cintelis — AI Platform Engineering & Security Architecture

AI Engineer · Security Architect · Founder

Engineering lead on production agentic AI for an enterprise client in aged care, one of Australia's fastest-growing platform businesses (450 staff → 2,000+, approaching $1B revenue). Working directly with the Technical CIO on a next-generation collaborative AI canvas integrated with 300+ enterprise data sources.

What I own:GPU compute infrastructure, AWS Bedrock integration, production cloud platform, multi-agent systems on frontier models, MCP server integrations, auth layers, guardrails, and observability
Security posture:Agent access boundaries and least-privilege tool scopes over sensitive data stores, LLM guardrails established and verified through Bedrock Guardrails, automated evaluation pipelines gating releases on measured guardrail effectiveness, and prompt and tool-call tracing supporting audit trails over autonomous actions.
Knowledge graph:Neo4j and Cypher in production at scale — daily work against a Neo4j Aura knowledge graph (553K+ nodes, 510K+ edges, 52 entity labels covering clients, care plans, audits, providers, drugs, conditions, and HCP levels), writing Cypher cohort queries for clinical and operational use cases.
Stack:Python, FastAPI, AWS (Bedrock, ECS, Lambda), Temporal, Neo4j Aura, Cypher, Docker, Terraform
In stealth:Sigilant — an agentic identity and governance platform: every AI agent gets a durable identity, an accountable human owner, short-lived credentials, per-action authorisation and an immutable audit trail. In early development.
01

Cintelis Workspace

github.com/cintelis/cintelis-workspace-showcase In Production

The multi-tenant business workspace Cintelis runs on — CRM and deals, outreach campaigns, projects, sprints and roadmaps, a docs wiki, and contract billing with Xero — with every client onboarded as an isolated tenant who sees their own projects, roadmap, documents, contract and invoices. One Cloudflare Worker, no framework, no build step.

CRM & outreach:Contacts, companies and a deals pipeline with stage totals and owners; a sales workspace of task queues, pipeline at a glance and guided next actions; contact records with a call / meeting / email timeline; multi-step and drip email campaigns through a signed-unsubscribe email gateway.
Tenancy:Customers are isolated tenants enforced in one place: every query on a customer-owned table goes through a single scoping helper with a /*SCOPE*/ marker, and CI fails the build on any query that bypasses it. A deny-by-default path allowlist plus per-entity ownership checks guard everything else.
Xero billing:OAuth 2.0 to Cintelis's Xero organisation with granular read-only scopes and rotating refresh tokens; a cron syncs each linked client's invoices incrementally (If-Modified-Since) into a tenant-scoped table, and clients see paid / awaiting / overdue invoices with the PDF previewed in place and a pay-online link. Nothing is ever written to Xero.
Delivery & docs:Jira-style projects, sprints and boards; a WBS + Gantt roadmap whose phases roll up their tasks' dates and hours; a Confluence-style wiki with wiki-links, Mermaid and server-side PDF export via Browser Rendering; LinkedIn page publishing, analytics and comment replies.
Platform:A single Cloudflare Worker on D1, R2, KV and Browser Rendering with a 5-minute cron; D1-backed sessions, optional TOTP 2FA, hashed and scoped API tokens for a public v1 API; GitHub Actions CI and deploys with a migration guard. Architecture diagrams are editable draw.io files generated from specs.
Screenshots:From the production app with a fictional demo tenant — all screenshots in the README.
Repo:github.com/cintelis/cintelis-workspace-showcase — public snapshot of the private production codebase.
Cloudflare WorkersD1R2KVBrowser RenderingCron TriggersJavaScriptMulti-tenancyXero APIOAuth 2.0LinkedIn APITOTP 2FAMermaiddraw.ioGitHub Actions
02

splunk-detection-poc

splunk-poc-demo.pages.dev Live Demo

Self-contained Splunk Enterprise security POC on AWS demonstrating five capabilities end-to-end: data ingestion, CIM Data Model Acceleration, detection engineering, Detections-as-Code CI/CD, and AI-drafted detections with a human review gate.

Detections:8 ATT&CK-mapped YAML rules in detections/aws/ (CloudTrail tampering, MFA bypass, login bursts, IAM key abuse, SG-open-to-world, S3 public write, root usage, AI-drafted password spray). Every rule is ES-compatible — drops into a licensed Splunk ES as a correlation search without rewrite.
DMA:3 accelerated CIM datamodels (Authentication, Network_Traffic, Change) with per-DM tags_whitelist and a benchmark dashboard comparing |tstats vs |search latency.
CI/CD:6-job pipeline. CI uploads payload to S3, sends one SSM SendCommand, the EC2 fetches + runs locally. OIDC AWS auth (zero static keys); Splunk :8089 never publicly exposed. DR rebuild from git verified in ~15 min.
AI workflow:Operator types ATT&CK technique + slug + description → Claude drafts schema-conformant YAML → validate CI passes → human merges PR → live as a scheduled saved search. End-to-end demonstrated in production.
Splunk EnterpriseCIMCloudTrailVPC Flow LogsTerraformGitHub Actions OIDCAWS SSMClaudeMITRE ATT&CK
03

agent-observability

agent-observability-demo.pages.dev Live Demo

Self-hosted infrastructure observability with zero-trust browser access. Grafana + Prometheus + yace CloudWatch exporter on ECS, fronted by Cloudflare Tunnel + Cloudflare Access (no public IPs, SSO-gated).

Dashboards:AWS cost tracking (MTD, daily trend, service breakdown, end-of-month forecast from Cost Explorer + sidecar), ECS health, RDS health, ALB/NLB latency, ElastiCache metrics.
Alerts as code:5 Grafana unified-alert rules provisioned from Terraform (ECS unhealthy, RDS CPU, ALB 5xx, monthly forecast over budget, scrape target down) using the A → B → C reduce-and-threshold pattern.
Access:Cloudflare Tunnel outbound from Fargate → Cloudflare edge → SSO challenge (Google / Microsoft / GitHub). No ALB, no public IP, no inbound firewall rules; tunnel token stored in AWS Secrets Manager.
Cost:~$55/mo per environment (ap-southeast-2)
GrafanaPrometheusyaceAWS Cost ExplorerCloudflare TunnelCloudflare AccessECS FargateTerraform
04

CISO AI

cisoai.au Live Site

Plain-language cyber intelligence briefings built from trusted public, vendor, and government sources. Turns high-signal advisories, vendor reports, and research notes into "what happened · why it matters · what to watch" summaries that busy teams and executives can scan in seconds, with one-click drill-down to the original source.

Feed:Five filterable categories on the homepage — Threat Intelligence, Security News, Government Advisory, Cybersecurity Research, Industry News. Live "last updated" indicator. Every summary preserves direct source lineage so practitioners can verify or dig deeper without hunting.
Briefings:Email subscription for ongoing intel. The subscription form posts to a Cloudflare Pages Function that proxies to a Cloudflare Email Worker, gated by Cloudflare Access service-token headers so the worker stays protected behind zero-trust auth.
Stack:Static HTML/CSS/JS landing on Cloudflare Pages, Pages Functions for the same-origin email proxy, dedicated intel feed at /intel/news.html, Cloudflare-fronted DNS + CDN.
Cloudflare PagesPages FunctionsEmail WorkerCloudflare AccessZero-trustHTML/CSS/JS
05

Open Runner

github.com/cintelis/open-runner Open Source

A web interface for running a coding agent on open-weight models — point it at a project folder and have it read, plan and edit code, with every file change and shell command waiting for your approval. Runs the OpenCode agent on GLM-5.3 by default, through open model infrastructure rather than a frontier vendor.

Runner:Drive the agent in build mode (edits and shell) or read-only plan mode. Markdown replies, collapsible tool calls and reasoning, per-turn token counts, and a Changes view of exactly what the agent edited.
Playground:Chat with any model directly — tool-calling, JSON mode, an embeddings-backed knowledge base, and browser voice.
Sandboxed:An optional Docker setup keeps the agent in its own container with a login, isolated API key and approval gates, so it can work on a copied-in repo without touching the host.
Repo:github.com/cintelis/open-runner — MIT licensed.
TypeScriptReactExpressOpenCodeGLM-5.3Open-weight modelsDockerMIT
06

Ads Optimiser

adsoptimiser.com.au Live App

An AI-powered creative platform that helps advertisers generate, manage and publish ad creatives — images and videos — with AI models from xAI (Grok), OpenAI and Luma, then publish across TikTok, Instagram, YouTube, Google Ads and Meta Ads from one place.

Create:Generate images from text prompts with style presets and brand reference photos, and videos from text, images, or by editing existing videos. AI ad copy writes headlines, descriptions and hashtags tailored for each platform.
AI characters:A consistent person with their own face, voice, scripts and gallery, who can speak on camera in a designed voice.
Captions & variants:Timed text cards and captions timed to the speech on any video, and A/B variants to compare several creative options side by side.
Pipelines:Chain steps such as prompt refinement, image, video and voiceover into one repeatable run — build it once, then reuse it for any product by changing only the prompt.
Publish & manage:Publish and schedule posts across TikTok, Instagram, YouTube, Google Ads and Meta Ads; manage campaigns; view content libraries with engagement metrics; and collaborate with team members in workspaces.
Create from Claude:Describe what you want in a conversation with Claude and it generates it in your workspace, via the Ads Optimiser connector or MCP package on the web, desktop or in Claude Code.
GrokOpenAILumaTikTokInstagramYouTubeGoogle AdsMeta AdsClaude connectorMCPCloudflareStripe
07

xBullRadar

xbullradar.com Live App

AI-native equity research terminal — multi-signal stock analytics, real-time X/Twitter sentiment, conversational AI co-pilot with investment-school voice personas (Buffett · Lynch · ARK · quant), voice-activated portfolio rebalancing, and tokenized trading via Ondo Finance. ~$100/mo serverless infra vs $24K/yr per-seat Bloomberg.

Signals:Four independent analytical signals per ticker — Sentiment (Grok x_search on X/Twitter), Technical (SMA / EMA / RSI / MACD / Bollinger majority vote), Fundamental (FMP valuation / profitability / growth / health / consistency), Equity Risk Premium (earnings yield minus 10Y treasury). Combined into a single actionable verdict.
AI co-pilot:xAI Grok (Responses + Realtime API, text + voice) reads your actual holdings, switches between investment philosophies, executes portfolio rebalancing through a two-stage commit pattern — bot proposes, you confirm.
Trading:Ondo Finance integration — 263 tokenized US stocks available on-chain as of April 2026.
Stack:Next.js 15 App Router on Vercel Edge, 17 API route handlers, 22 lib modules of business logic, Upstash Redis for per-user data + multi-TTL caches, Cloudflare Worker for magic-link auth, daily cron for scans.
Next.js 15React 19TypeScriptVercel EdgexAI GrokPolygonFMPOndo FinanceUpstash RedisCloudflare WorkersPWA
08

ISM Gap Analyser

irap.cintelis.ai Live App

Side-by-side ISM diffing tool for IRAP assessors. Compares the latest Australian Government ISM PROTECTED baseline against prior releases — surfacing new, removed, and modified controls with word-level diffs so assessment-prep scope is clear at a glance. Entirely client-side: no backend, no tracking.

Diffing:Fetches OSCAL catalogs from the ASD/ACSC repository and diffs current vs. historical PROTECTED baselines in the browser. Flags added / removed / modified controls with word-level highlighting; embedded ASD guideline text expands inline per control.
Architecture:100% client-side React 19 + Vite SPA — no server ever holds the data. A Cloudflare Worker proxies the GitHub-hosted catalogs to avoid API rate limits while staying stateless. IndexedDB caches catalogs with ETag revalidation; localStorage persists UI state.
Export:Findings export to TXT, CSV, JSON, and PDF for assessment workpapers.
Self-host:Forkable for air-gapped use — npm run deploy to a private Cloudflare Worker keeps PROTECTED content inside your own boundary. CI/CD via GitHub Actions; tested with Vitest + React Testing Library.
React 19JavaScriptViteCloudflare WorkersOSCALIndexedDBVitestGitHub ActionsIRAP / ISM
09

Buyer Outreach Platform

buyer-outreach.eqr.vc Live Demo

A human-in-the-loop M&A buyer-outreach platform for sell-side advisory teams: buyers move through one pipeline — identify → enrich → sequenced email → reply triage → NDA → meeting — with every outbound email, enrichment spend, and NDA counter-sign behind an advisor approval gate. AI does only deterministic work (classifying replies, diffing signed NDAs), never generating outbound copy. Shipped as an interactive prototype; the production design specifies a Java 21 / Embabel backend on PostgreSQL behind the same UI.

Highlights:A tiered enrichment + verification waterfall (RocketReach → Apollo → Hunter → Clay; verify via NeverBounce) with source attribution, a templated 4-touch sequence in an advisor review queue, AI reply triage (Claude, OpenAI fallback) into six buckets, and a DocuSign / wet-ink / Word-redline NDA flow text-diffed against the OneDrive template. Full detail in the repo.
React 19TypeScriptesbuildCloudflare PagesWranglerJava 21EmbabelSpring BootPostgreSQLClaudeOpenAIDocuSignMicrosoft GraphApolloHubSpotVertex AI
10

H4Graph

h4graph.vercel.app Live Demo

"Ask your literature. Get cited answers." H4Graph turns thousands of research papers into a knowledge graph a team can question in plain English. Every answer comes with its citations — the exact passage, DOI and date — including connections across papers that keyword search never finds.

How it answers:Four layers work together, each covering the others' blind spot: one finds passages by meaning rather than exact words, one follows citations and methods from paper to paper, one pins every claim to its source text, and an AI agent plans the search and writes the cited answer.
Why it matters:"Chat with your PDFs" tools only find text that sounds like the question. Ask "which methods beat transformers on long documents, and has anyone contradicted those results?" and H4Graph follows the trail to the later paper that disagrees — then answers both halves, cited.
Trust:Citations are built in, not requested: the answer can't include a value it can't trace back to a source, and any answer can be reproduced on demand. Your papers are never used to train a model, and publisher licences are respected.
Status:The website and an interactive 3D knowledge-graph explorer are live; the answering engine is designed and in build, with an API for developers alongside the app.
Knowledge graphCited answersClaudeNeo4jNext.jsJavaAWSVercel

Web platform for red-teaming and probe-based vulnerability scanning of LLM applications, run locally via Docker. Orchestrates two open-source engines — garak (NVIDIA's probe-based LLM scanner) and promptfoo (adversarial, LLM-judged red teaming) — as subprocesses, streams their output live over SSE, and normalises both engines' native reports into one Finding schema bucketed by the OWASP Top 10 for LLM Applications (2025). Point it at a chatbot or hosted model, pick a profile (quick, standard, deep), and get one comparable resilience score — percentage of attacks defended — plus a per-category breakdown, regardless of which engine produced the finding. Runs an A/B comparison against two targets from one shared attack plan — for example, before and after a guardrail change. Authorized testing only: secrets never persist, PII and keys are redacted before storage, and env-var allow-listing blocks key exfiltration.

Engines:garak (NVIDIA) + promptfoo, normalised to OWASP LLM Top 10 (2025).
Features:Live SSE log streaming, resilience scoring, OWASP radar / severity / trend charts, findings drill-down to individual adversarial attempts, A/B target comparison, self-contained HTML reports.
PythonFastAPIReactViteTypeScriptTailwindRechartsSQLiteDocker
12

GuardStein Data Room and Notes

www.guardstein.com Live App

A secure data room and notes workspace that cannot read your deal: Markdown notes, draw.io diagrams and real-time boards, with end-to-end encrypted vaults where the server only ever holds ciphertext. Runs local-first with no account, or as a multi-tenant cloud with shared workspaces and per-seat billing.

Data room:M&A disclosure staged on the encrypted vault, where access is a wrapped key rather than a permission check; guests need both an invitation link and a separately delivered passphrase, so a stolen link opens nothing.
Encryption:AES-256-GCM in the browser with workspace keys wrapped by hybrid post-quantum ML-KEM-1024 + P-384 and signatures by ML-DSA-87 + ECDSA P-384; unlock by passkey, password, recovery code or organisational escrow.
Notes & boards:Wikilinks, backlinks and a graph view; editable draw.io diagrams with an AI assistant; Yjs real-time boards; and an MCP server (@cintelisai/brainstorm-mcp) that connects Claude with an OAuth device grant.
Next.js 16React 19TypeScriptYjs CRDTDurable ObjectsNeon PostgresWebCryptoML-KEM-1024ML-DSA-87WebAuthn PRFdraw.ioMCPStripe
13

Graph Query Agent

graphagent.eqr.vc Live Demo

A controlled, auditable agent — not a chatbot — that turns operations questions into reviewed, parameterized Cypher over a Neo4j knowledge graph plus registered external tools, with every returned value traceable to the query, node IDs, and tool call behind it. Current delivery: hi-fi product design (eight live screens + a WebGL graph explorer) on a scaffolded FastAPI / Neo4j / Postgres backend; the orchestration core is a phased build.

Highlights:Versioned, injection-safe Cypher templates over a Neo4j 5.26 asset-maintenance model (read-only by default, writes behind an approval gate); an append-only Postgres 16 trace store that makes every field's lineage tamper-evident and runs deterministically replayable by request_id; a manifest-based tool registry (Snowflake, SAP, CMMS) with timeouts, retries, and circuit breakers; and a WebGL graph explorer (Sigma.js + graphology). Full detail in the repo.
Neo4j 5.26CypherFastAPIPythonasyncpgPostgreSQL 16Sigma.jsgraphologyWebGLesbuildDocker ComposeCloudflare PagesWrangler
2020 — PRESENT
Founder & Engineer
Totally Wild AI / Cintelis AI
Closed-loop multi-agent delivery platform. 3 shipped AI platforms. Full AWS infrastructure (ECS, RDS, Neo4j, Langfuse, Terraform). GPU compute, AWS Bedrock, production agentic AI on frontier models, MCP servers. 300+ enterprise data sources.
2022 — 2024
Security Architect
ACCC Consumer Data Right · Australian Government
Essential Eight uplift, OpenCTI, Entra ID PIM, EPAC automation, MITRE ATT&CK BAS.
2021 — 2022
Security Architect
AustralianSuper · APRA-regulated
Microsoft Sentinel SIEM/SOAR, Prisma Cloud, CI/CD security pipelines.
2020 — 2021
Security Architect
Australian Government — Defence CIOG
Architecture Branch (TOGAF ADM, SABSA). Defence Container platform. ISM/PSPF compliance.
2018 — 2020
Cloud Solution Architect
Thales Australia · Defence
KMaaS cloud offering, JP2060 Smart Field Hospital IoT, Health Aide digital-health experience (Sonitor RTLS · Cisco networking — showcased at MilCIS 2017), OneSky ATM IRAP readiness, FIPS 140-2 HSMs.
2012 — 2017
Senior Technical Consultant
Dell EMC · Defence / Government
Large-scale Defence infrastructure (100K+ users). EDLAN deployable private cloud. Navy JACKSTAY ICT modernisation.
20+
Years Engineering
13
Live Applications
3
AWS Infra Repos (IaC)
4
Gov & Defence Engagements
Education:Master of Information Systems Security — Charles Sturt University
Certs:CISM (ISACA) · ISO 27001 Lead Auditor (PECB) · IRAP Readiness Delivery
Clearance:Baseline (AGSVA)
Location:Sunshine Coast, QLD · Open to relocation