AuditPilot
Manages the full SOC 1 / SOC 2 engagement lifecycle — role-scoped portals, a framework-agnostic control engine, and Claude woven through evidence review and report drafting. ~970 tests.
founder. former SOC auditor. builder. overlander. hunter.
Five years auditing SOC controls at Grant Thornton and Coalfire. Now in Denver building AuditPilot — an AI-assisted SOC 1 / SOC 2 audit platform.
AuditPilot, Keelix, and VoltForge — alongside a seven-agent automation org that works while I sleep.
Manages the full SOC 1 / SOC 2 engagement lifecycle — role-scoped portals, a framework-agnostic control engine, and Claude woven through evidence review and report drafting. ~970 tests.
Probes your host from the outside, runs 35 deterministic checks, scores your posture 0–100, and emits audit-ready evidence mapped to SOC 2 and ISO 27001.
One intake form returns a complete LiFePO4 electrical design — battery, solar, inverter, and NEC wire/fuse schedule. A tested rules engine does the math; the LLM only explains the tradeoffs.
A self-hosted agent deployment that runs my back office — a daily intelligence digest, a Garmin-wired health coach, and research scans across 29 cron jobs and seven agents.
Browser-based control plane over OpenClaw's on-disk state, projected into six operator views with a mutex-serialized, atomic-rename write pipeline. 47 tests.
MCP server exposing two no-API trail services as 19 structured tools — reverse-engineered auth, a provenance-aware SQLite cache, idempotent writes. An agent plans the route; it lands in GaiaGPS. 75 tests.
Slack and WhatsApp MCPs that read your existing desktop session instead of provisioning credentials — Keychain-derived AES decryption, per-workspace tokens, seven read-only tools.
Self-hosted Garmin Connect warehouse — sleep, HRV, body battery, training load and more, synced hourly with idempotent upserts. 2,300+ runs, zero errors, ~3,700 days of history.
A six-month, 16,000-mile journey across the US and Canada living out of a truck camper — two years in the planning. Highlights: a rocket launch at Cape Canaveral, beach camping in the Outer Banks, downhill in Whistler, and hot springs deep in the Idaho mountains.
SOC 1 / SOC 2 control assessments at two firms — the pain that became AuditPilot.
Led SOC 1 and SOC 2 Type I and II exams for mid-market clients — evaluating control design and operating effectiveness across all trust services criteria. Scoped engagements, ran fieldwork, and delivered final reports end-to-end while managing budgets, timelines, and junior staff. Presented findings and remediation guidance directly to client leadership.
Planned and executed SOC 1 / SOC 2 risk assessments across access management, encryption, incident response, and threat monitoring. Led teams delivering cybersecurity risk advisory projects aligned to NIST CSF and ISO 27001. Built written security policies and incident response plans, and presented findings to client leadership.
BSBA — dual emphasis in Information Management and Operations Management. Delta Sigma Pi; Alpha Delta Phi founding class.
Working on audit, security tooling, or an overland rig? Send a note.
Send a message