AI & systems engineer in Vienna.
I build autonomous software with clear boundaries, inspectable behavior, and reproducible infrastructure.
Declarative infrastructure for self-hosted AI agents.
Tentaflake turns NixOS hosts into constrained agent fleets. Runtimes, storage, network access, secrets, observability, and lifecycle are declared as infrastructure instead of being assembled by hand.
Autonomy should increase capability, not implicit authority.
NixOS Rust isolated runtimes brokered egress audit trails
Repository · Documentation · Website
| Project | Purpose | Core |
|---|---|---|
| Igris Guardian | Capability-bounded prompt-injection firewall for agent systems. | Rust · TypeScript · NixOS |
| Memorycreep | Hardened NixOS workstation for policy-bound AI pentesting and isolated malware analysis. | NixOS · Python · security |
| Commitell | Turns a dirty Git worktree into one AI-written, DCO-signed commit. | Go · Git · local tooling |
| lazy-allrounder | Cross-platform voice AI for dictation, reading, and speech workflows. | Rust · egui · OpenRouter |
I work where agent behavior meets the operating system: capability boundaries, reproducible deployment, retrieval, security tooling, and focused products that remain useful without a platform around them.
declarative over implicit · capabilities over ambient authority · evidence over claims
Conversations about secure agent infrastructure, unusual systems problems, open-source collaboration, and technically ambitious products.
hello@timwitter.com · Vienna, Austria