I build AI-powered security automation: GenAI agents paired with deterministic tooling that detect, attribute, fix-guide and fix-verify issues from code change to production, running on AWS infrastructure I build with CDK, plus the evaluation harnesses, benchmark suites and CI release gates that keep those agents honest. Twelve-plus years of mobile application security and iOS reverse engineering underneath, which is why MobHunt exists: an agentic mobile bug bounty system whose validation gates kill most of what it finds. An agent's output is a claim to be verified, not a result to be trusted.
Start here
- MobHunt: agents plus strict validation gates for mobile bug bounty; Claude Code today, Codex CLI support in progress (2026)
- RE-iOS-Apps: free course on reverse engineering iOS apps (2.9k★)
- nuntius: end-to-end encrypted messaging library (Swift/Kotlin/Java ports in progress)
Writing: ivrodriguez.com · Talks: QCon SF 2019 · OWASP Toronto 2018