$ whoami --production-context

Security, infrastructure, and AI automation that stays inspectable under production pressure.

I am Easin Arafat, an Application Security Engineer at Startise working on xCloud. I build and harden the systems around a product, from the application boundary and release path to controlled AI workflows that keep important decisions visible.

$ work --production

One operating model, shown as three readable paths.

Start with the signal. Follow what I do next. See the proof or operational outcome that should remain inspectable afterward.

01

[SECURE THE BOUNDARY]

Find the assumption before it becomes an incident.

Application behavior, identities, permissions, and exposed attack surface.

What happens next

Threat modeling, authorization review, vulnerability research, and reproducible security verification.

What stays visible

Clear risk context, remediation paths, and public research across access control and sensitive-data failures.

02

[OPERATE THE PLATFORM]

Keep the release path explainable when production gets noisy.

Infrastructure changes, deployment procedures, server symptoms, and operational handoffs.

What happens next

Build deployment and recovery paths with logs, health checks, visible failure modes, and practical documentation.

What stays visible

Repeatable operations that make diagnosis and recovery less dependent on one person remembering the steps.

03

[AUTOMATE WITH CONTROL]

Turn repeated engineering work into bounded, reviewable systems.

Repeated development, QA, research, documentation, and terminal workflows.

What happens next

Harness approved AI tools with constrained inputs, evidence capture, test checks, and explicit approval points.

What stays visible

Faster technical work without pretending that the human decision-maker has disappeared.

$ trajectory --builder-to-operator

A security foundation that grew into systems work.

01

Builder

Full-stack projects made the product context tangible.

02

Researcher

Offensive security and disclosure work made risk concrete.

03

Operator

Platform reliability and AI workflows made the delivery system the product.

$ next --real-work

Bring the system, not just the symptom.

We can map what is failing, what needs to stay controlled, and the shortest useful path to a verified result.