What I'm building

Score the change,not the appearance.

In security and spam, how something looks is a dead signal — the real invoice looks fake, and the fake one looks real. So I build local-first tools that judge a thing by how far it deviates from your own history, not its surface. Your data never leaves your machine.

// Projects

Two sensors, one engine

Email · local-first

nodary

Connects read-only to your mailbox and learns each sender's normal behavior, then flags the message that deviates — a trusted contact suddenly acting off, a look-alike domain, a cold outreach that redirects your reply. All analysis runs on your machine. No cloud, no telemetry, ever.

IMAP read-only· per-sender baselines· zero telemetry
Threat intel · public feed

Honeypot blocklist

The same engine pointed at attackers. A honeypot I operate logs real SSH/Telnet break-in attempts; a recency-scored blocklist publishes the confirmed, currently-active offenders — including the ones that broke in and ran shell commands. Original sensor data, not a re-aggregation.

honeypot-confirmed· recency-scored· CC0
// Not slideware

I run the infrastructure this comes from

5,368,409
Attacks logged
4,918,469
Credentials captured
1,832
On the trained blocklist
// Talk

Building something adjacent, or just want to nerd out about it? [email protected]