About Founder

17 yearsPrincipal ArchitectCTOAI security

First the constraints, then the AI.

Seventeen years, from infrastructure analyst to Principal Architect for AI, ML and Data — and CTO of an AI security product I led and built myself. I didn't arrive at AI from a strategy deck. I came up through the infrastructure it runs on, which is why I design it assuming someone will take it apart.

Capability 17 YRS
Enterprise Architecture AI ML Data LLMs Agentic AI RAG Multi-Cloud AI Security Governance Compliance DevOps Python
PRINCIPAL ARCHITECT · CTO
UAE · KSA · EU · US
01

Trajectory

Seventeen years, eight roles, one direction of travel — from individual systems to organisational direction, and then to owning a product outright.

SeqRoleArcScope of accountabilityReach
01Technology Consultant Run itIndividual systems and client requests
02Infrastructure Analyst Run itServers, networks, the estate as it actually runs
03Senior Analyst Run itPlatform ownership, incidents, capacity, standards
04Cloud Architect Design itLanding zones, migration, hybrid topology
05Enterprise Architect Design itCross-domain landscape, integration, security posture
06Lead Domain Architect — Data & AI Own itDomain strategy, standards and delivery for data and AI
07Principal Architect — AI, ML & DataCurrent Own itDirection, governance and architecture across the organisation
08CTO — AI Security ProductConcurrent Build it aloneProduct direction, architecture, engineering and release — as the entire team
02

Position

Where I work, and why the constraints come first.

I work at the point where AI ambition meets the constraints that usually kill it: regulation, data residency, security review, and legacy systems that were never designed to be queried by a model.

Most of my work has been in high-stakes environments — public sector and regulated industry — where a proof of concept that cannot pass audit is worth nothing. So I build for the audit first, then scale.

Alongside that I am CTO of an AI security product: head of the function, technical lead, and the entire engineering team, all at once. I set the product direction, designed the architecture, wrote the code and shipped the releases. Nothing was delegated, so nothing is second-hand.

That gives me a rare vantage point on governance. I have answered the hard questions from both sides — as the architect proposing the system, and as the person whose product scores it.

Experience
17 years
Role
Principal Architect
Also
CTO — AI security
Domain
AI · ML · Data · Security
Regulatory models
UAE · KSA · EU · US
Pipeline scale
Millions / yr

Swipe to read the full drawing →

Zone A — under your control Zone B — under someone else's On-premise · trusted Source systems Identifiable data Legacy estate Raw Redact Policy Audit Control boundary Safe Model plane · cloud Retrieval Reasoning Agent action Never receives what it does not need
Drawing no.A-01
TitleControl boundary — redaction at source
ScaleNTS
Rev2026.08

Most enterprise AI programmes fail at this line. The design question is never whether to use the cloud — it is what is allowed to cross, and what has already been made safe before it does.

03

Selected work

Four systems, and the constraint that shaped each one.

WRK-01
Public sectorRAG platformData governance

Enterprise RAG

Constraint

Officers needed answers from decades of legislation, rulings and internal guidance. A wrong answer here is not an inconvenience, it is legal exposure. And none of the corpus could leave the authority's control.

Decision

Retrieval-grounded architecture where every answer traces back to a source document and passage. Role-aware access so an officer only ever retrieves what they are entitled to see. An evaluation harness for grounding and refusal behaviour before anything reached a real user.

Outcome

A platform an officer can defend in front of a taxpayer, because it shows its working.

WRK-02
Privacy by designHybrid cloudScale

Redaction at the boundary, not after it

Constraint

Millions of images a year needed cloud-scale processing. The images contained identifiable faces. Shipping them to a public cloud as-is was never going to survive review, and should not have.

Decision

Face detection and redaction run on-premise, before anything crosses to Azure. The cloud only ever receives data that has already been made safe. Privacy stopped being a policy document and became a network boundary. Drawing A-01 above is this system, generalised.

Outcome

Full cloud processing economics without ever moving identifiable data.

WRK-03
Real timePython middlewareObservability

Live SIP audio to decisions, while the call is open

Constraint

Call audio arriving over SIP needed transcription and analysis fast enough to be useful during the call, not the next morning. Off-the-shelf connectors did not fit the telephony estate.

Decision

Custom Python middleware to bridge the SIP stream into the speech service, handling reconnection, back-pressure and ordering, then pushing results straight to a live operations dashboard.

Outcome

Supervisors intervene while it still matters.

WRK-04
CTO · sole builderAI securityUAE / KSA / EU / US

An AI security product — as CTO, and as the whole team

Constraint

Organisations were deploying AI systems with no consistent way to answer two questions: is this vulnerable, and is it compliant here? Existing tooling secured the infrastructure around the model, not the model's own behaviour. There was no team and no precedent to inherit.

Role

CTO, head of function, technical lead and sole engineer. Product direction, architecture, implementation, release and support — every decision and every line of it mine.

Decision

Built end to end: vulnerability scanning and scoring for AI systems, plus a compliance scoring model mapped separately against UAE, Saudi, EU and US expectations, because "compliant" means four different things depending on where the workload runs.

Outcome

One view of an AI system's risk posture, per jurisdiction. I design the guardrails, then I grade them.

04

Capability

Four layers. Accountable across all of them.

LayerDisciplineDetail
L1Strategy & operating model AI strategy and roadmap across ITSM and engineering · target operating model for an automation and AI function · business case, value tracking and adoption planning · alignment across global stakeholders and delivery teams.
L2Solution architecture Agentic and multi-agent system design · retrieval architecture and knowledge grounding · multi-cloud and hybrid topologies · data platform architecture · integration into existing ITSM, engineering and legacy estates.
L3Build & run Python and custom middleware · DevOps and CI/CD · LLMOps: evaluation harnesses, tracing and observability, cost and latency control · production ownership rather than handover at the pilot.
L4Security & governance Threat modelling for AI and agentic systems · guardrail and policy design · data governance, residency and classification · compliance mapping across multiple regulatory regimes · product-grade vulnerability and compliance scoring.
Azure AI FoundryFoundry Agent ServiceAzure AI Search LangGraphLangChainSemantic KernelAutoGen CrewAIMCPA2AServiceNow AI Agents GitHub CopilotOpenTelemetryPythonTerraform
05

Method

How an idea becomes something running in production.

01

Discover

Find where the work actually hurts — volume, cycle time, error rate — not where AI sounds impressive. Qualify hard, early.

02

Solution

Architect against the real constraints: residency, security posture, the existing estate. Decide what is agentic and what should not be.

03

Sell

Make the case in the language of whoever signs — cost, risk, capacity. Bring security and compliance in before they can block it.

04

Deliver

Ship in increments with evaluation gates. Every release carries a measurable claim someone can check.

05

Run

Own it live: observability, drift, cost, incident paths. Feed what production teaches back into the roadmap.

Building an AI function that has to hold up under scrutiny?

That is the work I want. Strategy through to production, with the governance built in rather than bolted on afterwards.

Subha — Head of Data & AI · CTO, AI Security

Rev 2026.08