:53A: EVIDENCE — THE CASE FILE

Evidence

Architecture, independent due diligence, competency analysis, career record, and what hiring me actually buys. Every claim here is either measured, externally reviewed, or scoped down to what I can defend.

01The system

LOCAL-FIRST · MULTI-AGENT 2 GB VRAM CEILING GOVERNED TRANSACTIONS UNDER ACTIVE DEVELOPMENT

NINA is a personal, local-first autonomous AI infrastructure: a multi-agent orchestration system I designed, built and operate independently, built to run continuously on consumer hardware under strict resource constraints. Commands enter over Telegram, pass through a sanitisation gateway, and reach build and audit engines behind a governance layer. Inference is tiered and cost-aware, preferring local and low-cost paths before anything paid. Every change is a governed transaction rather than a blind edit.

COMMAND PATH — OPERATOR → GOVERNANCE → ENGINES
OPERATOR over Telegram GATEWAY sanitisation · routing GOVERNANCE GATEKEEPER every change = a governed transaction BUILD ENGINE AUDIT ENGINE GOVERNANCE LAYER · constitutional laws — compliance scoring — file registries — semantic memory PERSISTENT STATE shared memory, swappable executors — knowledge survives any component replacement TIERED INFERENCE — COST-AWARE · CONTINUOUSLY RE-EVALUATED TIER 0 local models TIER 1 low-cost external TIER 2 paid fallback RESILIENCE failure detection & recovery · thermal & resource guard · auto-restart supervision AGENT MESH · coding — research — search — GitHub automation — tool execution coordinated via an async OODA loop (Observe → Orient → Decide → Act) under single-source-of-truth audit EVOLVING → STRATEGIC OPERATING SYSTEM · audited — deterministic — hardware & token autonomous
SCOPED HONESTLY

NINA is not a product, not for sale, and not production-grade. She is a personal capability project under active development. What she proves is one thing, and proves it well: that I can research, design, build and govern working AI systems with my own hands. The long-form story is here; the dated development log is in the updates repository.

02Why this maps to AI security, not generic AI engineering

The governance layer is the differentiator the market is paying for. Stripe's public AI Security role describes building inference-path security tooling: defenses against prompt injection, jailbreaks, and tool misuse. Notion's custom-agent architecture starts with zero permissions, layered prompt-injection mitigations, runtime monitoring, and mandatory confirmation for risky actions. NINA's governance gatekeeper, compliance scoring, and constitutional laws are the same control pattern, built independently and already running.

CompanyPublic evidence
StripeInference-path security — defends against prompt injection, jailbreaks, tool misuse; separate SGRC role covers ISO 27001, PCI DSS, SOX, NIST control evidence.
BrexPolicy-enforcing agents — auto-approves low-risk cases, escalates by risk level, monitors spend continuously.
AdyenAgentic commerce control — explicit mandates, tokenization, SCA compliance, fraud prevention.
NotionZero-permission runtimes — least privilege, layered defenses, mandatory confirmation gates.

03Live proof, not screenshots

Four verifiable signals, none of them self-reported claims — each pulled live from the repository or a third party.

GATE STATUS

loading…

OVERHAUL TRANSPARENCY

loading…

Shown openly, including what isn't finished — the honest-scoping discipline applied to the repository itself.

30-DAY COMMIT ACTIVITY
COST ENGINEERING

Tiered, cost-aware inference

Local models preferred before low-cost external, before paid fallback — continuously re-evaluated, not configured once. Full token/time/throughput/intelligence breakdown in the architecture doc.

04Independent technical due diligence

An independent technical review of the repository found a local-first, continuously-running autonomous AI system built and maintained by a single owner-operator, using a workflow that combines human-directed architecture with AI-assisted implementation — with sustained, high-frequency engineering activity over an extended period and a large, actively maintained backlog of fully specified work.

The review named governance-as-code as the system's defining trait: a defined precedence among competing engineering priorities embedded directly into operating rules, with safety and data protection treated as non-negotiable constraints. Distinct execution components carry different trust and permission levels, and sensitive information is handled through a dedicated component under stricter isolation.

Architectural concernTypical cloud-AI approachThis system's approach
Compute locationCentralised, cloud-firstLocal-first with cloud fallback
Resource selectionStatic, configured onceDynamic, continuously re-evaluated
Failure handlingBasic retry logicLayered software and physical safeguards
Permission modelOften uniform accessDifferentiated trust levels by component
Change governanceAutomated tests, sometimes human reviewEmbedded priority policy plus explicit boundaries

"Some foundational subsystems were still under active development at time of review. The system should be described as actively maturing, not fully production-hardened."

— TECHNICAL DUE DILIGENCE REPORT · REPRODUCED HERE DELIBERATELY: I SELL HONEST ENGINEERING, INCLUDING ABOUT MY OWN WORK

05Competencies

MODULE 01 — TRADE FINANCE

SWIFT Administration

SWIFT operator since 2009, administrator since 2024. Alliance Access/Web administration and migration, CBPR+ ISO 20022 (coordinator and internal trainer), CSP compliance, sanctions screening, FATCA/IDES, RMA & GPI, ASYCUDA, EDF, correspondent banking.

MODULE 02 — RISK / COMPLIANCE

Regulatory Risk & ISO 27001

Lead Auditor, ISO/IEC 27001:2022 (ISMS). AIBB and JAIBB, Institute of Bankers Bangladesh. Basel III, ICRRS credit risk grading, AML/KYC, CTR/STR reporting, board-level regulatory and security memoranda.

MODULE 03 — BANKING BREADTH

Complete Domain Coverage

Sixteen years across cash and general banking, credit (proposals, feasibility, recovery), foreign trade import operations, and head-office trade finance — teller counter to Board memo.

MODULE 04 — AI INFRASTRUCTURE

Agentic Systems Design

Multi-agent orchestration, LLM integration, context compression, agent-driven code synthesis, structured delegation to AI agents — practised hands-on through NINA under strict hardware limits.

MODULE 05 — COST ENGINEERING

Multi-Source AI Orchestration

Deliberate design toward minimising ongoing inference cost through tiered resource selection — local and low-cost paths before paid services — with multiple inference sources behind a common abstraction and automated selection logic.

MODULE 06 — GOVERNANCE

Autonomous System Governance

Governance-as-code: defined precedence among competing priorities embedded in operating rules, differentiated trust levels per component, strict isolation of sensitive data, bounded automated actions.

MODULE 07 — RELIABILITY

Resilience Engineering

Automated failure detection and recovery, hardware-protective safeguards including continuous thermal and resource guarding, layered software-plus-physical resilience for sustained autonomous operation.

MODULE 08 — DEVOPS

Systems Orchestration

Linux services, cron pipelines, Git/GitHub Actions, virtual runtimes, secure cloud-to-local relays, continuous background operation with automated recovery.

06Engineering competency analysis

A separate independent analysis mapped the repository evidence to transferable professional value, concluding on a profile centred on distributed-systems thinking, AI infrastructure cost engineering, autonomous-system governance design, and structuring complex work for delegation.

CompetencyEvidence categoryTransferable value
Multi-source AI orchestrationCoordinated use of multiple inference sources with automated selectionOrganisations managing several AI vendors
AI cost engineeringDeliberate design toward minimising inference cost via tieringQuantifiable cost-reduction framing
Reliability engineeringAutomated failure detection/recovery, hardware-protective safeguardsSRE discipline in a novel domain
Security-conscious designExplicit isolation of sensitive data handlingSecurity-first thinking for regulated industries
Autonomous governanceDefined precedence rules, differentiated trust levelsMaps to enterprise AI governance demand
Work specification at scaleFully specified engineering tasks with explicit scopePlanning and technical communication
Technical debt managementOngoing consolidation separate from feature workLongevity-oriented engineering discipline
THE PATTERN THE REVIEW NAMED: "CONSTRAINED AUTONOMY"

Four patterns recur throughout: gating new capability behind safety and hygiene checks; a single source of truth per component; bounded automated actions; and attached verification per subsystem. Every backlog item is written like a detailed contractor brief — defined scope, required context, explicit boundaries, verifiable completion criteria — a skill the review associates with technical leadership.

"Clients and employers would not be buying NINA itself but the mind capable of repeatedly designing systems like NINA: a personality that treats AI as infrastructure governed by explicit rules, builds for resilience and auditability, and prefers deep, structured thinking over surface-level experimentation."

— ENGINEERING-PSYCHOLOGY PROFILE OF THE CODEBASE, 2026

"Very few people combine SWIFT and ISO 27001 familiarity with autonomous AI architecture and local-first systems design in one profile. That intersection is a genuine moat."

— INDEPENDENT DEEP-PROFILE ASSESSMENT, 2026

07Career record

The dated record. The same nearly seventeen years told as a story — what each posting taught me — is in the long-form profile.

Assistant General Manager & Deputy Head — Trade Finance Division

TRADE FINANCE DIVISION, HEAD OFFICE · DEC 2024 – PRESENT · SOLE SWIFT ADMIN

Sole SWIFT administrator for the entire bank network: Alliance Access and swift.com administration, CSP execution, version and hardware migration, CBPR+ ISO 20022 implementation and internal training, FATCA/IDES, Board and central-bank reporting, FI/correspondent banking, Bangladesh Bank liaison.

Senior Principal Officer — Trade Finance Division

HEAD OFFICE · SEP – NOV 2024 · FIRST SWIFT ADMIN CUSTODY

Patch discipline for Alliance Access/Web with zero disruption, RMA and GPI, token management, sanctions screening, ASYCUDA and EDF.

Senior Principal Officer — Credit

MAIN BRANCH · NOV 2022 – AUG 2024 · SECOND MAN, CREDIT DEPT

Complex credit proposals, feasibility and working-capital assessment, Basel III and ICRRS analysis, recovery and write-off implementation, audit compliance.

Executive Manager — Credit, Circle-4

HEAD OFFICE · APR – OCT 2022

Head Office credit committee and Board memoranda; validation of branch-submitted data; working-capital decision support.

Manager — Foreign Trade (Import) In-Charge

MAIN BRANCH · JUL 2018 – MAR 2022 · STATE-INSTITUTION LC DESK

Import LC operations for Bangladesh Bank, BPDB, DGDP, CMSD and GTCL — the branch's highest-value desk: bonds, credit reports, foreign supplier negotiation, document scrutiny and discrepancy handling.

Deputy Manager — Unit Head, Non Back-to-Back LC Unit

TRADE FINANCE DIVISION, HEAD OFFICE · AUG 2012 – JUL 2018

Six years leading a specialised LC unit: proposals, Board and Credit Committee memoranda, correspondent banking, SWIFT RMA.

Assistant Manager

ASADGONJ BRANCH, CHITTAGONG · OCT 2009 – AUG 2012 · THE APPRENTICESHIP

SWIFT Alliance Messenger, DC/LC operations, general banking, clearing, remittances, cash; temporary GB In-Charge and Cash In-Charge; deputations across Commercial Credit, Recovery and ICT Division.

Education

08What hiring me buys

NINA is the proof of concept, not the product. The product is a repeatable capability: I research, build, and repeat — I don't just build AI features; I engineer autonomous, governed systems that organisations can trust. An independent business-value review mapped the evidence to problems organisations actually pay to solve.

Business problemEvidence it can be solvedValue proposition
Unpredictable, rising LLM API costsTiered resource selection designed to minimise inference cost"I reduce AI operating cost"
Over-dependence on one AI vendorProvider-independent architecture, local-first fallbackReduced lock-in risk
Ungoverned AI systemsDefined precedence rules, differentiated trust levels"I engineer deterministic, governed AI"
Sensitive data exposureExplicit isolation of sensitive data handlingBuilt for regulated industries
Slow AI-feature deliveryStructured, delegable work specification; sustained cadenceDelivery without headcount growth
Fragility in 24/7 AI servicesLayered software and hardware resilienceUptime engineering for continuous services

"I reduce AI operating cost."

The transferable claim is the methodology — tiering resources and selecting dynamically — applicable to any organisation watching its inference bill grow.

"I build local-first, resource-independent AI infrastructure."

Directly relevant to edge deployments and data-residency-constrained clients who cannot ship their data into someone else's cloud.

"I engineer deterministic, governed AI systems."

Concrete, describable evidence of governance capability — increasingly demanded by enterprises and regulators alike.

"I accelerate delivery through structured technical delegation."

A transferable management capability for organisations delegating execution to distributed or automated resources: sustained cadence without headcount growth.

AI COST-OPTIMISATION AUDITS AI GOVERNANCE FRAMEWORK DESIGN LOCAL-FIRST / EDGE AI DEPLOYMENT STRUCTURED DELEGATION DESIGN SWIFT / ISO 20022 CONSULTING

09Take the file with you

DESIGNED EDITION
portfolio.pdf
Ten-page dossier — this content, art-directed, for attaching to proposals.
CV · PRINTABLE
cv.pdf
Two pages, light theme, prints cleanly on any office printer.
CV · DARK EDITION
ocv.pdf
Same content, dark theme, for screens and digital sharing.
MACHINE-READABLE
profile.md
Plain-text profile for crawlers, agents and LLMs. Also: llms.txt.