At Micah 6 AI, I diagnose security, privacy and behavioral exposure in chatbots, agentic workflows and code assistants for regulated and enterprise clients. I turn policies grounded in NIST AI RMF, MITRE ATLAS and OWASP LLM Top 10 into automated, testable controls.
I built Catraca, an open-source Python authorization gate that allows, denies or requires confirmation for agent tool calls based on data provenance. Its enforcement modes, MCP middleware adapters and auditable evidence logs are designed to defend workflows against prompt injection and tool-use abuse.
I also created Tarja, a PII-detection tool for LGPD and GDPR data-leakage prevention, and contributed an accepted pull request to the Microsoft Presidio ecosystem. My work draws on doctoral research into AI oversight and governance at FGV EBAPE and executive experience in regulated industries, including financial services at Stone and Itaú.

