Hire Me
These are fixed-price packages under the terms on this page; they are not billed under the weekly model described on /work. 50% up front. One decision-maker and a written scope sheet before kickoff.
Remote/async. Two calls: kickoff and handoff.
The $10,000 review is credited in full against any package below if you proceed within 60 days.
Attestation & Integrity Review
Price
$10,000 -- 1 week
What it is
A written review of one system: what is actually attested, what is assumed, where the verifier trusts an operator instead of a proof, and which fixes come first.
Who it is for
When the question is chain of custody: what this system proves, what it assumes, and where that distinction matters -- including defense and dual-use systems.
You get
A 10-15 page report, prioritized fixes with effort estimates, and a 45-minute readout. Credited in full against any package below if you proceed within 60 days.
Attested Execution on Intel TDX
Price
$85,000 -- 6 weeks
What it is
An implementation engagement for one workload: establish an attestation verifier, Remote Attestation CA, and policy you operate, without using Intel Trust Authority as the quote-verification service. Intel remains the hardware endorser: quote verification still relies on Intel-signed collateral, Intel’s root CA, and Intel TCB information.
Who it is for
When one TDX workload must show attestation to a customer, a chain, or an auditor, but the operator needs to apply its own verification policy rather than send quotes to Intel Trust Authority.
You get
A TDX remote-attestation verifier that does not use Intel Trust Authority as the quote-verification service; your own Remote Attestation CA and policy for approved measurements and images and for accepted Intel TCB statuses and advisories; attestation checks in CI and deploy; a sealed profile with no SSH or console and documented break-glass; an operator runbook; and a written trust-model statement for a customer or auditor.
Prerequisites & acceptance
One supported Intel TDX deployment; access to the workload, build and deployment path, and relying-party configuration; and a customer decision-maker. Acceptance is limited to the listed deliverables working against the agreed workload and environment. Exact platform support, evidence inputs, and test cases are set in the written scope sheet.
Excludes
Application code changes beyond the attestation boundary, multi-cloud, and hardware procurement.
Tamper-Evident Audit Trail
Price
$60,000 -- 4-5 weeks
What it is
An integration for one system that makes its record trail independently verifiable without replacing existing storage.
Who it is for
When agent actions, evals, ledger events, or legal-hold records may be compared or disputed, but the current trail is a database the DBA can rewrite.
You get
Hash-chained, Merkle-committed records with external RFC 3161 anchoring; an ATL-based Apache-2.0 core; offline-verifiable receipts with the agreed trust material; frame-bound records for AI outputs covering model, prompt template, inputs, and config; and an export package for auditor or counsel.
Prerequisites & acceptance
The written scope sheet names in-scope event types and integration responsibilities, the anchoring provider and cadence, responsibility for provider fees, the receipt-verification and trust-material boundary, and the storage design. Acceptance is limited to records emitted by the agreed integration and verified under that stated receipt policy; it does not establish coverage of events the source system never emits. No new application database is included unless the agreed storage assessment requires one.
Excludes
Retention operations (available separately as a managed service), legal opinion on admissibility.
Verified Parser / No-Panic Proof
Price
$50,000 -- 4 weeks
What it is
A bounded verification engagement for one stated component: establish a machine-checked no-panic property, or the stated formal property, and keep it checked in CI.
Who it is for
When a panic in one critical Rust component is an incident and “we fuzzed it” is not an answer.
You get
A machine-checked no-panic proof using Charon → Aeneas → Lean 4, or bounded formal verification of the stated property; a fuzz corpus and harness; CI gates that keep the proof green; and a short report naming exactly what is proven and what is not.
Excludes
Proofs of cryptographic correctness (Ed25519, RFC conformance), components outside the stated boundary.
Name the package and the system. I’ll confirm fit and request the inputs needed to prepare a written scope sheet.