AI Governance · Azure · Regulated Enterprise
I build AI platforms that pass the audit.
Twenty years of Azure, AWS, identity and Kubernetes - and the control mappings that make a platform defensible to your risk committee. Most consultancies can write the mapping or ship the Terraform. I do both.
Services
Three ways this usually starts
Each one is scoped to produce something your risk function can read and your platform team can deploy - not a slide deck.
01
AI Landing Zone
An API gateway in front of your model endpoints: model allowlists, per-team token quotas and chargeback, prompt and response logging, tenant isolation. Terraform, from day one. Ends the era of API keys in config files.
What's included →02
AI Act readiness
Inventory what your teams have actually shipped, classify it against the Act, and map the Article 50 duties that already bite to concrete platform controls - with a runway to the December 2027 high-risk deadline.
What's included →03
Identity & Zero Trust review
Entra ID architecture, Conditional Access design, Global Secure Access and workload identity - reviewed against the access-control clauses every framework opens with, and remediated in code.
What's included →Writing
Notes from actually building this
Long-form, specific, and written while the terminal was still open. No gated PDFs.
-
Building an AI Landing Zone on Azure — Part 2: The platform underneath
Before the gateway and the metering there is a private AKS cluster, a hub-and-spoke network and a GitOps setup where no application ever holds a secret. This is how that foundation is put together.
-
Building an AI Landing Zone on Azure - Part 1: Why every enterprise needs an AI gateway
Teams are calling LLM endpoints directly with API keys in config files and nobody knows who is spending what. Here is the landing zone I built to fix that, and why.
-
Building a Cloud-Native PKI with HashiCorp Vault
I built an HA Vault PKI on Kubernetes to sign the subordinate CA that Global Secure Access needs for TLS inspection. Vault cannot issue a certificate that is both a CA and carries Server Auth EKU, so it could not be done. Updated September 2026: Microsoft now offers a managed certificate for GSA in preview, which removes the problem entirely.
-
GitLab CI/CD for Cloudflare Pages: Automated Deployments with Preview Environments
How to set up a GitLab CI/CD pipeline for Cloudflare Pages with preview deployments on merge requests and automatic production deploys.
Is your AI platform defensible?
Thirty minutes, no deck. Tell me what your teams have shipped and where the audit pressure is coming from, and I'll tell you what I'd look at first - whether or not you hire me.