AI Governance · Azure · Regulated Enterprise
I build AI platforms that pass the audit.
Twenty years of Azure, AWS, identity and Kubernetes - and the control mappings that make a platform defensible to your risk committee. Most consultancies can write the mapping or ship the Terraform. I do both.
Services
Three ways this usually starts
Each one is scoped to produce something your risk function can read and your platform team can deploy - not a slide deck.
01
AI Landing Zone
An API gateway in front of your model endpoints: model allowlists, per-team token quotas and chargeback, prompt and response logging, tenant isolation. Terraform, from day one. Ends the era of API keys in config files.
What's included →02
AI Act readiness
Inventory what your teams have actually shipped, classify it against the Act, and map the Article 50 duties that already bite to concrete platform controls - with a runway to the December 2027 high-risk deadline.
What's included →03
Identity & Zero Trust review
Entra ID architecture, Conditional Access design, Global Secure Access and workload identity - reviewed against the access-control clauses every framework opens with, and remediated in code.
What's included →Writing
Notes from actually building this
Long-form, specific, and written while the terminal was still open. No gated PDFs.
-
Building an AI Landing Zone on Azure - Part 1: Why every enterprise needs an AI gateway
Teams are calling LLM endpoints directly with API keys in config files and nobody knows who is spending what. Here is the landing zone I built to fix that, and why.
-
Building a Cloud-Native PKI with HashiCorp Vault
I built an HA Vault PKI on Kubernetes to sign the subordinate CA that Global Secure Access needs for TLS inspection. Vault cannot issue a certificate that is both a CA and carries Server Auth EKU, so it could not be done. Updated September 2026: Microsoft now offers a managed certificate for GSA in preview, which removes the problem entirely.
-
GitLab CI/CD for Cloudflare Pages: Automated Deployments with Preview Environments
How to set up a GitLab CI/CD pipeline for Cloudflare Pages with preview deployments on merge requests and automatic production deploys.
-
Building a Raspberry Pi5 Cluster with Talos Linux and Cilium
A small, quiet, genuinely highly-available Kubernetes cluster on four Raspberry Pi 5 boards, running Talos Linux with Cilium - the full kit list, the build, and everything that bit back.
Is your AI platform defensible?
Thirty minutes, no deck. Tell me what your teams have shipped and where the audit pressure is coming from, and I'll tell you what I'd look at first - whether or not you hire me.