Zyberpol — agentic security operations
An agentic SOC that investigates across every console and executes human-approved fixes from one screen — moving teams from monitoring to mitigation. Identity-first, human-approved, proof-native.
I build production ML and agentic security systems that don't stop at spotting the threat — they close it, with a human in command and evidence you can hand a regulator. Twelve years shipping real systems; now building the SOC that acts, not just alerts.
Most AI security stops at "we found something." At Vezran I lead the AI/ML behind Zyberpol — an agentic security-operations layer that takes an incident all the way to resolved, with a human approving the consequential moves and a tamper-proof record at the end.
Zyberpol sits on top of the security tools a team already runs — identity, endpoint, cloud, SIEM — correlates the noise into a handful of real incidents, recommends the safest containment, routes consequential actions through a human, then verifies the fix and exports proof an auditor accepts. The model is rented and swappable; the control layer and its governance are the moat.
From agentic security platforms to production ML at enterprise scale, to coordinated vulnerability disclosures in the tools everyone builds on.
An agentic SOC that investigates across every console and executes human-approved fixes from one screen — moving teams from monitoring to mitigation. Identity-first, human-approved, proof-native.
Coordinated disclosures in HuggingFace Transformers, and benchmarks probing prompt-injection robustness with DSPy and AgentDojo.
Production natural-language systems for a global contact-center operation — routing, understanding, and surfacing signal from millions of customer interactions.
Risk models across a logistics network at national scale — predicting and flagging shipment risk to protect operations and cost.
Long-form on the problems that actually bite in production — and short notes from the bench.
Defanging the dataset handed the model a shortcut that made it look multilingual. Strip the placeholder and non-Latin scripts collapse — Chinese 1.00 → 0.09, Arabic 0.98 → 0.04. The failure wasn't in the model. It was in the measurement.
Read the essay →A more capable model started following attackers' orders. Across eight models, nothing — size, vendor, or capability — predicted which would break.
Read →LureBench. Control for the dataset confound and telling AI-written fraud from human is close to a coin flip. The defensive problem is still open.
Read →Three regimes by base-model strength, with a practitioner decision rule — DSPy optimizers vs AgentDojo prompt-injection attacks.
Read →A device-placement ordering quirk between opacus, PEFT, and HuggingFace zeroed gradients while noise kept accumulating. What to check in your own setup.
Read →Optimizing prompts for accuracy tightens them to the training distribution — and can cost ~20 points of security on the harder attacks.
Read →I'm always up for a sharp conversation — agentic systems, LLM security, or turning a security team from monitoring into mitigation.