$ whoami
Samurai — AI, cybersecurity & full-stack engineer · founder @N3xusD3v · São Paulo, BR
$ cat focus.txt
Secure AI · AppSec & Pentesting · SaaS · Data Governance (LGPD)
$ cat domains.txt
Aviation ops · Offensive security · Sustainable infrastructure
$ cat principles.txt
Security-first · Evidence-driven · Human-in-the-loopPublic repositories where the engineering can be inspected end-to-end.
| Project | What you can verify in the repo |
|---|---|
| CyberJust · live ↗ | Next.js + TypeScript · Vitest unit tests · Playwright E2E · 2 CI workflows · SECURITY.md · 140+ issues/PRs with conventional commits · rate-limiter XFF-bypass fix & hardened security headers |
| GreenPulse · live ↗ | React + Vite · CI pipeline · SECURITY.md / CONTRIBUTING.md · dependency-vulnerability remediation · explicit demo-data boundaries |
| Data Sentinel | Python · LGPD sensitive-data analysis · Google Drive integration · Plotly · Docker delivery |
Production work under client or product confidentiality. Architecture walkthroughs available on request.
authenticated APIs billing validation Firebase isolation AI resilience CI
🛡️ CPTS Report AI Enterprise — self-hosted penetration-testing workspace · live workspace ↗
Authorized scope, evidence, findings, CVSS scoring, compliance mapping and human-reviewed AI reporting.
authorized-use boundaries evidence confidence remediation tracking
🔎 Public-sector security assessment (2026) — authorized recon & vulnerability assessment
Scope control, attack-surface mapping, sanitized evidence with integrity hashes, risk matrix and remediation roadmap.
defensive & authorized use only
| Repository | What it is | Stack | Last push |
|---|---|---|---|
| hotlead | plataforma para Scrapp de Leads quentes | Python | 2d ago |
| CyberJust | Cybersecurity media and education experience exploring Brazilian cybercrime cases, specialists and digital protection. | TypeScript | 16d ago |
| GreenPulse | Sustainable datacenter monitoring for energy, carbon impact, SRE health and idle-resource optimization. | TypeScript | 1mo ago |
| VoltEra-Nexus-The-Energy-Consciousness-Protocol | Interactive digital-art experience connecting clean energy, decentralized infrastructure and speculative technology. | TypeScript | 3mo ago |
| MRP | Public architecture, documentation and reference assets for the Marola RP FiveM roleplay ecosystem. | JavaScript | 3mo ago |
- Security before spectacle — authentication, authorization, isolation and sensitive-data handling are architectural concerns.
- AI assists; humans remain accountable — uncertain output stays explicit, reviewable and correctable.
- Evidence over claims — tests, CI, docs, hashes and known limitations carry the story.
- Domain context matters — aviation, pentesting and infrastructure have different failure models.
- Production is a gate, not a vibe — a working demo is not a production-ready system.
Technology map
| Layer | Tools |
|---|---|
| Frontend | TypeScript, React, Next.js, Vite, Tailwind CSS, shadcn/ui, Motion |
| Backend & APIs | Node.js, Express, Python, FastAPI, REST, webhooks |
| AI & Data | Gemini, LLM integrations, structured extraction, Pandas, Plotly |
| Cloud & Platform | Firebase, Supabase, Docker, Google Cloud, Azure, Vercel, self-hosted homelab |
| Security | Threat modeling, OWASP ASVS/Top 10, CVSS, recon, evidence integrity, LGPD |
| Delivery | Git, GitHub Actions, Vitest, Playwright, CI/CD, technical documentation |
Helicopter flight instructor and DJ. Aviation reinforces checklists, risk awareness and calm decision-making; music sharpens timing and the ability to read a live system. Both shape how I build.
Let's build something trustworthy. → samurai@n3xus.dev
AI products · Cybersecurity · Aviation technology · Data governance · Sustainable infrastructure




