Skip to the content.

Elias Leslie — AI, Security Automation, and Infrastructure Tooling

I build practical automation systems at the intersection of AI automation, security automation, cyber security, agentic developer tooling, and full-stack infrastructure. My work emphasizes local-first control planes, secure defaults, reproducible release paths, and operator-focused interfaces that turn complex workflows into auditable tools.

I use agentic AI heavily, but I keep the engineering bar concrete: documented setup, real tests, runtime smoke checks, secret hygiene, clean install verification, and honest limitations.

Portfolio project showcase overview

Background

25+ years in IT and security, spanning hands-on engineering and executive leadership. I grew from Director of IT to Chief Information Security Officer at a managed services provider serving 200+ client environments, building the security program and automation framework that became a primary strategic asset in the company’s 2024 acquisition by Integris — then spent the following year as Security Services Architect refactoring that tooling into platform-agnostic frameworks and mentoring engineers on AI-augmented development.

Alongside that, I served as incident commander on ransomware and breach engagements referred through Lloyd’s of London cyber insurance underwriters — seven-figure-ransom recoveries across 26 states and multiple countries, directing client engineering organizations, outsourced IT providers, and third-party vendors. OSCP certified.

The projects below are what that experience looks like when I build in the open.

Projects

Seven public platforms released under Apache-2.0, each a standalone repository with documented setup, real checks, CI, a security policy, and honest limitations.

Agent Hub — self-hosted control plane for multi-provider AI agents

Repository · Security policy

Agent Hub model catalog — tracked models, live pricing, ingest provenance, and external-model discovery

Security Hardening Automation (SHA) — bounded control plane for endpoint hardening

Repository · Security policy

SHA infrastructure and endpoint compliance console, running in demo mode against an invented fleet

Ominull — autonomous cyberops and ring-0 threat nullification platform

Repository · Security policy

Ominull web console in demo mode — multi-tenant fleet hierarchy with ring-0 enforcement badges, seeded synthetic data

SummitFlow — task orchestration and evidence capture for AI-assisted development

Repository · Security policy

SummitFlow execution board — task lanes, priorities, and agent-session counters for a single project

Portfolio AI — self-hosted investment, household, and rewards intelligence workspace

Repository · Security policy

Portfolio AI investing watchlist

A-Term — browser workspace for AI coding agents

Repository · Security policy

A-Term browser workspace

Aico — desktop companion for terminal AI agents

Repository · Security policy

Aico lantern — a floating desktop widget running a Claude Code session on Linux

Private work

BlackBox — zero-knowledge encrypted media archive. A private household archive spanning a Kotlin/Jetpack Compose Android client and a Go vault service, built around nine documented security invariants that a change may not weaken without a recorded decision. Media is sealed with AES-256-GCM under Android Keystore (StrongBox where available) before it is written to disk, so plaintext never reaches storage; there is no write path to MediaStore or any shared collection, no exported provider or FileProvider, allowBackup=false, and FLAG_SECURE on every window. The vault server never holds a media decryption key.

Every device generates a P-256 key at first run and its identity is the SHA-256 of that public key, so listeners present a self-signed certificate whose key is the identity key and pinning an invitation fingerprint authenticates the specific device rather than a name a CA could reissue. Recovery runs through a five-word EFF-long-list passphrase (64.6 bits) stretched with Argon2id (64 MiB, t=3), with the archive publishing only salt, cost parameters, and a public key. Storage is content-addressed and immutable with additive mirroring, copy-census-gated eviction, and tombstoned deletes that still reach an archive drive that was offline at the time.

Source is private, but I am happy to walk through the architecture and threat model on request.

Capability areas

Contact

Last updated: 2026-08-24