In security and spam, how something looks is a dead signal — the real invoice looks fake, and the fake one looks real. So I build local-first tools that judge a thing by how far it deviates from your own history, not its surface. Your data never leaves your machine.
Connects read-only to your mailbox and learns each sender's normal behavior, then flags the message that deviates — a trusted contact suddenly acting off, a look-alike domain, a cold outreach that redirects your reply. All analysis runs on your machine. No cloud, no telemetry, ever.
The same engine pointed at attackers. A honeypot I operate logs real SSH/Telnet break-in attempts; a recency-scored blocklist publishes the confirmed, currently-active offenders — including the ones that broke in and ran shell commands. Original sensor data, not a re-aggregation.
Building something adjacent, or just want to nerd out about it? [email protected]