End-to-end web platforms
Production systems from architecture to deployment. Auth, billing, infra, observability — the parts most projects underestimate.
I design and build scalable full-stack systems, integrate cutting-edge AI models into real products, and secure infrastructures against modern threats. From architecture to deployment — end to end.
About me
I'm a computer engineer based in Italy with a deep interest in the intersection of software craftsmanship, artificial intelligence, and digital security. I care as much about how things are built as about what they do.
I started coding at 14, dissecting old computers and writing my first scripts to automate the boring parts of life. That curiosity never left. Today I build full-stack applications that scale — from system design to the last pixel on screen.
Over the past few years I've shifted a significant part of my work toward AI engineering: designing RAG systems, integrating LLMs into production workflows, and building the guardrails that make them actually safe to ship.
Cybersecurity is my second lens on every project. I approach each system as both builder and attacker — threat modelling, pen testing, and writing code that doesn't apologise for existing in a hostile environment.
First freelance projects — small business sites, internal tools. Year one was about learning to ship, not to perfect.
Joined a product team building SaaS for European mid-market. Owned the auth, billing, and infra side.
Shifted focus to LLMs in production — RAG pipelines, evals, and the unglamorous work that makes them ship.
Security stopped being a side interest. Active CTF player, offensive-security mindset baked into every project.
Available for full-stack, AI integration, and security work. Response within 24 hours.
Experience
From the Italian Ministry of Justice and AgID-CERT to independent clients across the EU — a track record built at the intersection of cybersecurity, AI engineering and software development.
Ministry of Justice (Ministero della Giustizia) · Rome
Working alongside the Head of Technological Innovation to drive digitalization and security of ministerial systems. Azure Global Administrator managing VPN, SharePoint and videoconferencing. Member of the International Digital Justice Working Group — coordinating EU-level projects including EPO, LEILA, EIO and e-evidence regulations.
AgID — Agency for Digital Italy · Rome
Security analyst within CERT-AgID protecting Italian Public Administration infrastructure. Analysed phishing and malware campaigns via sandboxing and IoC extraction, distributed through official threat intelligence feeds. Conducted threat hunting, forensic analysis and incident coordination across critical PA systems.
Freelance · Remote
Designing and shipping web applications, AI systems and automation workflows for companies, startups and professionals. Specialised in LLM integration, RAG pipelines, REST APIs and secure cloud deployments on Vercel, AWS and Firebase.
Higher School of the Judiciary (SSM) · Florence
Selected as IT Manager for Villa di Castel Pulci, the SSM educational campus. Managed the full IT infrastructure — servers, VLANs, Azure domain, A/V and videoconferencing. Oversaw the classroom modernisation project as DEC and developed an AI-based user support module for the institutional website.
Ministry of Justice — DAP · Milan
Winner of the national competition for IT Assistant roles within the Penitentiary Administration. Supported 200+ users, managed second-level tickets and maintained ministerial applications. Designed VLANs, configured switches and participated in national Active Directory management.
Trust & Recognition
I've been entrusted with critical infrastructure by Italian public institutions and EU working groups, and with full-stack product builds by independent founders. Same engineering standards, same security mindset — regardless of the logo on the contract.
Italian Government
National Cybersecurity
Italian Judiciary
Penitentiary Administration
EPO · LEILA · EIO
EU, US, remote
MVPs & product launches
Law, finance, healthcare
Production systems from architecture to deployment. Auth, billing, infra, observability — the parts most projects underestimate.
LLMs that actually ship: evals, guardrails, retrieval that retrieves the right thing. Built to survive the boring parts.
Threat modelling, code review, and pentest of web apps and cloud infrastructure. Findings you can act on, not a 60-page PDF.
For organisations modernising legacy stacks. Strategy backed by hands-on engineering, not slides.
30-min call, scoping doc within 48h, fixed price or T&M — your choice.
Weekly demos, shared repo, decisions documented as we go.
Production handoff, 30-day stabilisation window, retainer if needed.
Selected Work
A curated set of work across full-stack engineering, AI and security. Most projects are under NDA or private to clients — get in touch and I'll walk you through what's relevant to your case.
Writing & Research
Long-form writing on cryptography, AI security, prompt engineering and the systems I build. Not deliverables under NDA — public research and analysis, free to read and share.
More on the way
New writing on AI security, full-stack engineering and the intersection of the two — published when there's something worth saying, not on a schedule.
Get in touch
Full-stack products, AI integrations, security reviews — or anything that sits at the intersection. Reply within 24 hours.
Portfolio Guide
● Live · curated answers