AI Governance · Azure · Regulated Enterprise

I build AI platforms that pass the audit.

Twenty years of Azure, AWS, identity and Kubernetes - and the control mappings that make a platform defensible to your risk committee. Most consultancies can write the mapping or ship the Terraform. I do both.

20+ yearscloud & platform architecture
Azure · AKS · Entra IDprimary stack, AWS/GCP secondary
DORA · NIS2 · PCI DSSmappings that survive review
ARB to terraform applygovernance and build, one person

Services

Three ways this usually starts

Each one is scoped to produce something your risk function can read and your platform team can deploy - not a slide deck.

01

AI Landing Zone

An API gateway in front of your model endpoints: model allowlists, per-team token quotas and chargeback, prompt and response logging, tenant isolation. Terraform, from day one. Ends the era of API keys in config files.

What's included →

02

AI Act readiness

Inventory what your teams have actually shipped, classify it against the Act, and map the Article 50 duties that already bite to concrete platform controls - with a runway to the December 2027 high-risk deadline.

What's included →

03

Identity & Zero Trust review

Entra ID architecture, Conditional Access design, Global Secure Access and workload identity - reviewed against the access-control clauses every framework opens with, and remediated in code.

What's included →

Writing

Notes from actually building this

Long-form, specific, and written while the terminal was still open. No gated PDFs.


  1. 8 min read
    AI Landing Zone on Azure

    Building an AI Landing Zone on Azure — Part 3: One front door for many models

    How a single, VNet-injected API Management instance becomes the only way to reach Azure OpenAI, Mistral OCR and Azure Maps, with policy fragments as composable building blocks and an identity per hop.


  2. 10 min read
    AI Landing Zone on Azure

    Building an AI Landing Zone on Azure — Part 2: The platform underneath

    Before the gateway and the metering there is a private AKS cluster, a hub-and-spoke network and a GitOps setup where no application ever holds a secret. This is how that foundation is put together.

  3. AI Governance

    7 min read
    AI Landing Zone on Azure

    Building an AI Landing Zone on Azure - Part 1: Why every enterprise needs an AI gateway

    Teams are calling LLM endpoints directly with API keys in config files and nobody knows who is spending what. Here is the landing zone I built to fix that, and why.

  4. Identity & Zero Trust

    17 min read

    Building a Cloud-Native PKI with HashiCorp Vault

    I built an HA Vault PKI on Kubernetes to sign the subordinate CA that Global Secure Access needs for TLS inspection. Vault cannot issue a certificate that is both a CA and carries Server Auth EKU, so it could not be done. Updated September 2026: Microsoft now offers a managed certificate for GSA in preview, which removes the problem entirely.

All writing →

Is your AI platform defensible?

Thirty minutes, no deck. Tell me what your teams have shipped and where the audit pressure is coming from, and I'll tell you what I'd look at first - whether or not you hire me.