Work
What I have actually built
Everything marked live is something you can open right now and use. Nothing on this page is a concept, a roadmap or a landing page for a product that does not exist yet — if it is not built, it is not here.
Security practice
TSCM Risk
LiveAuthor and engineer
The governance layer for technical surveillance risk: assessment, policy, programme design and compliance mapping, published openly rather than gated behind a sales call.
- Published mappings from TSCM practice to NIS2, ISO/IEC 27001, the UK Cyber Governance Code, UK GDPR, NIST SP 800-53 and DTSA.
- Policy skeletons, risk register wording, assessment frequency guidance and board reporting templates, given away in full.
- The six-stage methodology in its operational form.
Next.jsCloudflare WorkersD1TypeScript
Author and engineer
Speech privacy and acoustic leakage control: measuring how far confidential conversation actually travels, then treating the paths that matter.
- Home of the four Speech Privacy Levels and the diagnose-then-prescribe method.
- Covers retuning and maintaining masking systems the client already owns, including systems whose original vendor has gone.
- Solutions engine that matches a described problem to a level rather than to a product.
Next.jsCloudflare WorkersTypeScript
SAPP Security
LiveFramework author
Where PASM and PRMS were developed. Physical and proximity attack surface work: the parts of an office where cyber security stops working. The site is still up and the frameworks are still published; the company behind it is not.
- Full published treatment of Proximity Attack Surface Management and the maturity score.
- Interactive diagrams for the framework, zone floor plans and tier connection mapping.
- The company, Security and Privacy Partners Ltd (16271231), was set up with Raili Maripuu in February 2025 and dissolved on 25 August 2026 following compulsory strike-off. It is on the register and I would rather say so here than have you find it. The frameworks are published under my own name on this site and do not depend on it.
Next.jsStatic exportTypeScript
Product and platform
GoYoga
LiveCo-founder and technical lead
A Tallinn wellness studio and the largest system I have built end to end: public site, payments, teacher portal and a private media portal, running since 2014.
- Several hundred routes generated across four languages (Estonian, English, Finnish, Russian) from a Python build pipeline, with per-locale slugs, hreflang and structured data. The exact count is whatever the public sitemap says today.
- Payment and operations layer on Cloudflare Pages Functions: Wise webhook handling, invoice and confirmation email flow, and a server-side proxy to the Stebby wellness-benefit API.
- Separate teacher application on Cloudflare Workers with a D1 database, KV-backed sessions, CSRF protection, field-level change-request diffs, and alerting on failed logins and logins from new countries.
- Passcode-gated media portal for partner and press material.
- In 2026 I also applied analytical turnaround work and made my way into SEO and digital sales for the business — a skills path alongside the engineering artefacts above.
Cloudflare PagesCloudflare WorkersD1KVHonoPython
WeCare
LiveTechnology, security and operations
Estonian home care services for the elderly, with an operational application behind it for the caregivers actually doing the visits.
- Care operations application covering visit logging, client records and care plans.
- Role-based access across caregiver, care manager, administrator and analyst, with a documented permission matrix and server-side enforcement.
- Health data handled under a defined organisational boundary; I hold the information security lead role.
ReactFirebase AuthFirestoreCloud Functions
Mobilewatch
No longer tradingDirector from September 2017
Indoor positioning and detection of mobile devices in controlled environments. The company has ceased trading and its Companies House entry shows a proposal to strike off, which I am happy to talk through if it matters to you.
- Sensor and radio-frequency work: detecting personal mobile devices in areas where policy prohibits them, which is the control that every other control gets circumvented by.
- This is where the radio-frequency grounding behind the current TSCM practice comes from.
Sensor hardwareRF analysis
Client work
Founder
The studio the web and search work runs through. Bilingual, Tallinn and London, and the reason the security sites are built properly rather than bought from a template.
- Case studies covering the projects listed on this page and client work beyond them.
- Bilingual static export with a full structured data graph.
Next.jsCloudflare PagesTypeScript