Secure AI systems
Mohsen Bahremani
Gateways, policies, audit trails, and detection content that make LLM traffic safer and more visible.
AIWall
OpenAI-compatible proxy · secret scanning · policy · audit · agent guardrails · cost tracking
A self-hosted AI security gateway for developers and teams. Sits between your apps and AI providers — visibility and controls on infrastructure you own.
- OpenAI-compatible proxy for clients, scripts, and coding tools
- Secret scanning before prompts reach a provider
- YAML policies — allow, warn, block, or redact — with a control panel
- Agent tool guardrails (risky shell/file actions → approve/deny)
- Privacy-preserving audit log and cost tracking
- Alerts via Telegram, webhook, or ntfy
MedSecLab
Results 6 attack classes detected · 2 gaps closed · 10 Wazuh rules · 14 CI case-groups
Reference architecture for securing clinical AI end-to-end — built and tested on synthetic healthcare data only.
- Hardened FastAPI gateway with RAG, PHI de-identification, and structured audit logging
- 10 Wazuh detection rules mapped to MITRE ATLAS, plus 3 Grafana dashboards
- 6 red-team attack classes — all detected; 2 gaps found and remediated
- 14 detection case-groups validated offline in CI
- STRIDE threat model with every finding mapped to a control
- Controls mapped to HIPAA §164.312, OWASP LLM Top 10, and NIST AI RMF
Tools I work with
- Backend & security
- Python, FastAPI, policy engines, audit logging, Docker
- AI / LLM
- Gateways & routing, embeddings, vector search, privacy-aware filtering, PyTorch, NLP
- Detection
- Wazuh, Sigma, Grafana / Loki-style pipelines
- Frontend
- React, TypeScript, MUI, Refine, Vite
- Data
- SQL, Pandas, NumPy
Get in touch
Open to conversations about secure AI systems, LLM gateways, and detection engineering.