LIVE SYSTEM STATUS reading deployment… not a static page — read the raw feed ↗
M. Baizid Alam
M. Baizid Alam
AGM & Deputy Head, Trade Finance Division
BASIC BANK PLC · DHAKA, BANGLADESH
🎓Mechanical engineer, IUT · MBA summa cum laude, NSU · NDC 02 · Ideal 00
💼Full-stack banker: cash · general banking · credit · trade finance · compliance
🛡️SWIFT admin · ISO 20022 trainer · ISO/IEC 27001:2022 Lead Auditor
Then: autonomous AI infrastructure — alone, 2 GB VRAM laptop, evenings
ONE PERSON · SIX DISCIPLINES · NEARLY 17 YEARS
Bankers can't build. Builders never answered to a regulator.
ALL RACE TO ADOPT AI. ALMOST NONE TO GOVERN IT.
↓ SCROLL FOR THE FULL STORY
:72:

Why this niche

The market is paying for governed agents, not generic model-building.

Public hiring and product evidence from Stripe, Notion, Brex and Adyen shows the highest-value AI roles inside fintech are about guardrails, auditability, policy enforcement, fraud and risk controls, and secure agent execution — not pure model-building. That is precisely the discipline a bank’s SWIFT administrator, ISO 27001 lead auditor and trade-finance compliance owner already practises every day.

I design and implement governed autonomous agents for high-trust financial operations: scoped permissions, approval gates, audit trails, policy engines, runtime monitoring, and secure fallback on constrained infrastructure.

— THE THESIS, STATED PLAINLY
STRIPE

Inference-path security

AI Security team builds tooling against prompt injection, jailbreaks and tool misuse; a separate SGRC role covers ISO 27001, PCI DSS, SOX and NIST control evidence.

BREX

Policy-enforcing agents

Agents enforce expense policy, auto-approve low-risk cases, escalate exceptions by risk level and monitor spend continuously — compliance experts become “workflow designers and policy engineers.”

ADYEN

Agentic commerce control

Framed around explicit mandates, tokenization, SCA compliance, authentication and fraud prevention for merchant-controlled agent transactions.

NOTION

Zero-permission runtimes

Custom agents start with zero permissions, layered prompt-injection mitigations, runtime monitoring and mandatory confirmation for risky actions.

:21:

About me

SWIFT ALLIANCE ACCESS ADMIN ISO/IEC 27001:2022 LEAD AUDITOR CBPR+ ISO 20022 TRAINER AGM · BASIC BANK PLC B.SC. MECHANICAL ENG (IUT) MBA (NSU · 3.80)

I am a mechanical engineer by training. For nearly seventeen years my machines have been a bank's — cash and general banking, credit, foreign trade, SWIFT, compliance — and today, as Assistant General Manager, I am the sole SWIFT administrator for the entire bank network.

Mechanical engineers mechanise things. I did not learn to code my way into AI; I mechanised DevOps. The substrate changed from steel to pipelines, agents and runtimes — the discipline did not change at all. That is how a trade finance AGM came to build his own autonomous AI infrastructure, alone, in the evenings, on a 2 GB VRAM laptop.

:23B:

About NINA

LOCAL-FIRST · MULTI-AGENT 2 GB VRAM CEILING GOVERNED TRANSACTIONS UNDER ACTIVE DEVELOPMENT

NINA is a personal, local-first autonomous AI infrastructure: a multi-agent orchestration system I designed, built and operate independently, built to run continuously on consumer hardware under strict resource constraints — every change passing through a governance layer as a governed transaction rather than a blind edit.

Live data — machine-read, re-synced every 30 min
loading live stats…

Stated plainly: NINA is not a product, not for sale, and not production-grade. She is a capability project under active development. What she proves is one thing, and proves it well — that I am tech-native: able to research, design, build and govern working AI systems with my own hands. I research, build, repeat.

— HONEST SCOPING IS THE FIRST SKILL OF ANYONE SELLING GOVERNANCE
:32A:

What it is worth

Every tier of what I deliver, from operational survival to competitive moat.

The hierarchy is the argument: this profile operates at every level at once, not just the top or the bottom.

05 · SELF-ACTUALISATION

Competitive moat and intellectual legacy

Organisations working with me build intellectual property that cannot be bought off a shelf. Governed autonomous AI plus custody-grade compliance in one architecture is a moat most companies will spend years trying to acquire.

04 · ESTEEM

Credibility with regulators and boards

ISO 27001 Lead Auditor. SWIFT administrator. Seventeen years of board-level memoranda. I give enterprises the language and the evidence to defend an AI deployment to auditors, central banks and risk committees — not just to engineers.

03 · BELONGING

The bridge between engineering and governance

Most organisations have people who understand one side. The translation between “we built it” and “we can prove it is safe and auditable” is where projects die. That translation is the work.

02 · SAFETY

Governed, deterministic AI — no surprises

Defined precedence rules. Differentiated trust levels per component. Explicit isolation of sensitive data. Bounded automated actions. Every change a governed transaction rather than a blind edit. Built for organisations that cannot afford a rogue agent.

01 · SURVIVAL

Immediate ROI: reduce AI operating cost

Tiered inference — local models first, low-cost external second, premium providers only as fallback, re-evaluated on every call. The claim is simple: I reduce the inference bill from day one, and I can prove it from my own system’s logs.

:71A:

What hiring me buys

NINA is the proof of concept. The product is a repeatable capability.

I research, build, repeat — governed, auditable systems an organisation can both trust and defend. Six problems that show up in every serious AI programme, and what I do about each.

PROBLEM · RISING LLM COST

Tiered resource selection

Local and low-cost paths are preferred before anything paid, and the choice is re-evaluated continuously rather than configured once.

PROBLEM · VENDOR LOCK-IN

Provider-independent architecture

Nineteen providers behind one abstraction with local-first fallback. No single point of commercial or technical failure.

PROBLEM · UNGOVERNED AI

Governance as code

Precedence rules, differentiated trust levels and bounded actions, enforced at runtime rather than written in a policy nobody reads.

PROBLEM · DATA EXPOSURE

Explicit isolation

Sensitive data handled through a dedicated component under stricter isolation; local-first deployment for data-residency constraints.

PROBLEM · SLOW DELIVERY

Structured, delegable specification

Work specified precisely enough to dispatch and verify. Sustained delivery cadence without growing headcount.

PROBLEM · FRAGILE 24/7 AI

Layered resilience

Automated failure detection and recovery, thermal and resource guards, auto-restart supervision. Software plus physical safeguards.

:53A:

Proof

Same question, three frontier models, three independent answers — none of them written by me. Each panel is raw output from a live CLI session, asked to assess the system without disclosing its internals. Computed system metrics — repository age, module and test counts, backlog, governance — are published separately in the NINA updates log.

Computed system evidence snapshot from a live session
PROOF 01 · CLAUDE CODE CLIAsked what the system is and what is uncommon about it, with an explicit instruction to name no tools and reveal no internals. Its answer: an AIOS whose architecture enforces exactly one canonical source of truth per domain — no duplication, no drift.
Independent model assessment, Codex CLI
PROOF 02 · CODEX CLIThe same question, asked independently of the first. Classifies the system as a governed, personal, agentic AIOS under active development — a judgment it bases on implemented capability rather than branding.
Independent model assessment, Gemini CLI
PROOF 03 · GEMINI CLIA third model, reporting from inside the agent layer: the architectural tiers it sees as wired and operational. The most enthusiastic of the three — which is precisely why measured metrics live in the updates log, not in a screenshot.
NINA live architecture graph — 119 nodes, 225 edges, 7 planes
PROOF 04 · LIVE ARCHITECTURE GRAPHNot a mockup — a screenshot of the real, running graph, regenerated from the same registries on every publish. Open it live and click any module to walk four tiers deep: subdomains, functions, parameters.
Published essay: I have 9,576 commits and I hand-wrote almost none of them
PROOF 05 · PUBLISHED THINKING“9,576 commits and I hand-wrote almost none of them” — the number in that title was already stale the day it published. It's 9,576+ now. Written for people who hold budgets rather than compilers.
Published essay: Your AI Pilot Will Not Fail on Accuracy
PROOF 06 · PUBLISHED THINKING“It will fail the first time someone asks who approved what.” Explaining governance to a non-engineer is the thing being sold, so here it is demonstrated rather than claimed.
:77B:

The full picture

Honest scoping is the first skill of anyone selling governance.

Strengths that are genuinely rare, weaknesses named rather than buried, opportunities that are time-sensitive, and threats already mitigated in the architecture.

STRENGTHS

A combination that is hard to assemble

Unique intersection. SWIFT administration, ISO 27001 lead audit and autonomous AI architecture in one person — this does not exist off a shelf.

Governance as runtime. Not a document. Enforced, auditable, versioned.

Constrained-environment mastery. A real commit history under a 2 GB VRAM ceiling proves resource discipline rarely found in cloud-native engineers.

WEAKNESSES

Stated plainly, before you ask

NINA is not production-grade. A personal capability project under active development.

Solo operator. No team and no institutional backing; velocity depends on one person’s evening hours.

Bandwidth. A full-time executive role limits me to structured, scoped engagements.

OPPORTUNITIES

Time-sensitive, and open now

Enterprise AI governance. Regulators increasingly require documented frameworks; few practitioners can build one from first principles.

Banking-sector adoption. Every bank is building AI. Almost none have someone who understands both the SWIFT network and the model layer.

Data-residency pressure. Local-first architecture expertise is scarce and getting scarcer.

THREATS · MITIGATED

Named, then answered

“Just use a cloud vendor.” Local-first architecture proves vendor-independent capability; the moat is methodology, not model weights.

Credential inflation. Everyone claims AI expertise. Answered with a public dated repository and independent assessments, not slides.

Role conflict. Answered with structured, scoped engagements and clear boundaries.

:79:

How to verify this

The repository is private. That limits what a stranger can independently check, so here is the honest split rather than an implied claim that everything is auditable.

VERIFIABLE RIGHT NOW — NO TRUST REQUIRED

Third-party sourced

The deployment clock at the top of this page is fetched from GitHub’s public API by your browser, not served from mine — open developer tools and watch the request. The live architecture graph, the raw metrics feed, and the two published essays are all open to inspection. So is the GitHub profile behind them.

SELF-REPORTED — TAKE ON TRUST, OR TEST ME

Generated from a private repository

Commit counts, module and element totals, and gate results are computed by a script inside a private repo and published here. You cannot audit them from outside, and I am not going to pretend otherwise. What I will do is walk any of it live in a screen-share, in whatever depth you want, and answer questions from the code rather than from a slide.

A number you cannot check is worth exactly what you paid for it. I would rather name that limit than let it be discovered.

— THE SAME DISCIPLINE APPLIES TO MY OWN CLAIMS AS TO THE SYSTEM’S
:23E:

Canonical Links

These addresses are permanent. Content is updated in place, so the links never expire or change.

CV · DARK EDITION
DEMO · SELF-HOSTED
PROOF · 3 CLI MODELS
proof1 · proof2 · proof3.jpg
SCAN TO OPEN THIS CARD
data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAlAAAAJQAQMAAAB7LMgGAAAABlBMVEXw+P/f9/qW9KPOAAAAAXRSTlMAQObYZgAAAkZJREFUeNrt3ctuwzAMRNGg///PzaIIJD6EdmHTXRwCaQQ7vihmMRApSn69hBBCCCHE5fEd4nNt3Vu/WVfqM1/X/UNQUFBQR7+q4x9P2n1qeVT/DNmhoKBm/OrjRMuN6kwrzrfyM2SHgoJ6yq9iDhhzR34FBQX1P/wqz6jirKrmivwKCgpq0q/yePetvcZ+fobsUFBQE34V1/r+9rE+CAUFNe9Xv/tXrbGTHQoK6im/yn1We5fVniHGHiyyQ0FBTftV7rLaa1V1hbD3LbJDQUHd71ddT2i/Khh7RqN3kR0KCmrCr3Lveu5tqFWr6Ftkh4KCms0Hc397nXfFX6pfQUFBzftVrFfFPqvc6ZBnZmSHgoJ6wq/Ou23qOM+wyA4FBTWZD+6dDNWj+rqW9UEoKKhpv4qjXK2K9+qH7FBQUHP5YPwb51vdTsJ8l+xQUFD3+1WttPdZX61g7SOyQ0FBTfhVt/6XT2joruzfZIeCgprxqz0PjB516nSPMzKyQ0FBTeWD3XlX3Spg71lkh4KCmvGr6Ex133N3mkytZZEdCgpqwq+6zqv6Bq/O3cgOBQU1nQ+ecsN67/SuQrJDQUHN5IPZv+r+5v3OmpUtPyM7FBTUxPyq29Xc7R+M2aHzGaCgoJ7OB3MHaa2557tkh4KCmvOr7n2pp/c8d2eQkh0KCuoJv+ocqTpY3pFDdigoqCf8qj8Lufa7kx0KCmrer+K4O5ev2+O8P0N2KCioCb+qdfV6Nt+eDXY7pMkOBQV1v18JIYQQQojL4g1EDznhxmRW9wAAAABJRU5ErkJggg== code for aibony.github.io
aibony.github.io
EVIDENCE / CASE FILE
MACHINE-READABLE
WRITING
:57A:

Reach the Operator

HIRE ME · FIVERR
CALL / WHATSAPP
YOUTUBE CHANNEL
GITHUB · NINA UPDATES
LOCATION
Dhaka, Bangladesh