TonyAI

TonyAI ShieldTonyAI Security Portfolio

Zero Trust doesn't slow AI down. It makes AI trustworthy.

Principal Software Engineer · AI Force Multiplier · Architecture · Zero Trust · Identity · Compliance

Zero Trust BAA HIPAA SOC2 PCI DSS FIPS 140-3
Running Demos
Secure RAG — Zero Trust Demo IETF A2A Trust PoC — Live Demo TonyAI Portfolio demo menu Last Mile demo — ALLOWED Last Mile demo — DENIED
Co-piloted by Claude Code  ·  🎓 Certifications
Cuts AI Token Costs
AI Cost Engineering
RAG pre-filter — retrieve only what's needed
Prompt caching — stop paying for repeated context
Spend caps — hard limits, no surprise bills
Model tiering — Haiku for simple tasks, Opus for hard ones
Context budgeting — 2k tokens, not 100k
💳 Zero Trust Payments with AI 📷 Preview demo

How do you put AI in a payments pipeline without letting it move money on its own confidence?

The AI recommends. A hard policy engine decides. The money never moves on AI confidence alone. ReBAC enforces identity at every layer boundary — revoke one relationship, the entire chain is blocked.

Prompt Evaluation Gate (PEG) sits between Claude's output and execution — deterministic Python, no LLM. Checks amount coherence, duplicate detection, frequency anomaly, reasoning validity. Fail any check = hard block, no override. Hash-chained audit trail ties every hop — ReBAC check, AI recommendation, PEG verdict, human approval, execution — to one correlation ID.

PythonClaude SonnetZero Trust ReBACPrompt Evaluation Gate RedisDynamoDBS3 KMSJWT RS256HMAC-SHA256 TerraformCloudWatch
PCI-DSSSOC2NIST 800-207OWASP A03OWASP A09
🔐 Secure RAG — Zero Trust Demo Cuts AI Token Costs

Same AI. Same query. Different identity. Different answer. Zero Trust enforces it — not the prompt.

Jill asks about Q1 revenue — gets the numbers. Jack asks the same question — gets nothing. Enforcement happens at retrieval, before Claude sees a single token. PHI never leaves the trust boundary.

Builds on Last Mile Zero Trust — JWT → ReBAC → Bedrock KB pre-filter → DynamoDB audit. Same stack, swappable backend.

Every request carries a correlation ID from JWT validation through ReBAC, retrieval, and response — traceable end-to-end in CloudWatch. Full observability built in, not bolted on.

PythonAWS Bedrock Knowledge Base PineconeS3DynamoDB CloudWatchSQSIAM RedisReBACMCP Resources MCP PromptsClaude CodeJWT RS256Terraform
HIPAASOC2 NIST 800-207FIPS 140-3OWASP A01
📡 IETF Internet-Draft — Agent-to-Agent Trust
★ IETF AUTHOR

How do you establish trust between AI agents when no standard exists?

Defining the standard for agent-to-agent identity and trust. IETF Security Area Director responded day one. First author.

Draft backed by a working PoC — JWT chains, HMAC message integrity, X.509 PKI, CRL, dual-signature policy governance. Every pattern in the spec runs as code.

draft-tonyai-a2a-trust-00Agent Identity Trust FrameworkAI GovernancePoC on GitHub
Python 3.12FastAPIX.509 PKIJWT Chains HMACCRLCedarAWS KMS S3Replay PreventionDockerTerraform
OWASP Top 1050/50 Conformance Vectors 34/34 Security Attacks Blocked33 Smoke Tests
IETFRFC TrackSecurity Area
🛡️ Last Mile Zero Trust

How do you give an AI agent secure access to on-prem data without static credentials or opening firewall holes?

Zero static credentials. Zero inbound firewall rules. Full cryptographic audit trail on every access.

PythonFastAPIAWS SQS IAMHashiCorp VaultPostgreSQL 16 RedisReBACJWT RS256 MCPTerraformDocker
SOC2PCI DSS v4 FIPS 140-3NIST 800-207
MCP tools: query_patient_records · get_patient_records
🔒 Sentinel FIPS — AWS-Native FIPS 140-3

How do you prove an AI system's decisions are tamper-proof in a federally regulated environment?

AWS-native FIPS 140-3 security boundary. KMS-signed decisions. Tamper-proof audit trail in S3 Object Lock COMPLIANCE mode — root cannot delete the evidence. FedRAMP-ready.

PythonAWS LambdaAPI Gateway KMSDynamoDBCedar/AVP CloudTrailS3 Object LockEventBridge SNSSecretsManagerCloudWatchSAM
FIPS 140-3FedRAMP High SOC2NIST 800-53
Sentinel MCP — AWS Ops Toolkit Cuts AI Token Costs

How do you cut security investigation time from 45 minutes to 60 seconds?

Plain-English in, forensically verified answer out. Conversational DevOps — CloudTrail, CloudWatch, DynamoDB, and KMS through natural language with full audit trail.

PythonFastMCPBoto3 DynamoDBCloudTrailCloudWatch KMSLambdaIAM
SOC2OWASP A05OWASP A09
MCP tools: verify_setup · check_chain_status · get_full_chain · get_signing_history · get_denial_history · get_chain_changes · verify_signature
🧠 RAG Knowledge Assistant — Enterprise AI Adoption Cuts AI Token Costs

How do you roll out enterprise AI safely — and onboard into a new role faster without sensitive data leaving the org?

Hard spend caps. Local-first retrieval. Sensitive data never reaches an external API. Onboarding accelerator — ingest docs, ADRs, runbooks. Ramp fast, stay secure.

TypeScriptNode.jsAnthropic SDK JSON knowledge storeToken budgeting
SOC2OWASP A01OWASP A09
🎓 Anthropic Academy Certifications

Production Impact — Henry Schein One (HSO) · 14 Years  |  State of Utah