← Projects
Private library · never public

Experience, made repeatable.

Methodology is my private operator knowledge system: 22 specialist security domains built on one shared contract for authorization, evidence, false-positive rejection, proof of impact, adversarial review, and reporting.

22specialist domains
1,300+working notes
1shared operating contract
Knowledge architecture

The domain changes. The proof standard does not.

A domain explains what to test. The shared core controls how the operator behaves—from scope and execution tier to the exact point where a signal earns the word “finding.”

Binding operator loop
01ScopeConfirm authority and exact boundary.
02HypothesisState oracle and counter-oracle.
03TierClassify execution and approval need.
04EvidenceCollect the minimum defensible proof.
05ReviewChallenge impact and false positives.
06ReportWrite a reproducible, bounded finding.
Why it exists

A library that behaves like an operating system.

It keeps deep specialist knowledge usable without letting every assessment invent a different evidence standard.

01

Progressive loading

The operator loads only the shared safety contract, the active domain, its tools, standard mapping, and the current phase—keeping context deep without making it noisy.

02

Evidence maturity

Raw output remains a signal. Oracle quality, negative controls, false-positive review, and proof of impact determine whether it can become a finding.

03

Model independence

The rules are written for the operator role rather than one AI vendor. Stronger or weaker models still inherit the same scope, approval, evidence, and reporting gates.

Library boundary

Reusable knowledge stays separate from live work.

The system remains valuable because engagement data and private evidence never become reusable methodology content.

Methodology contains

  • Domain-specific assessment phases and decision routes
  • Shared authorization, execution-tier, and evidence contracts
  • Standards mapping, reporting anatomy, and remediation guidance
  • Cross-domain links that preserve specialist context

Methodology excludes

  • Customer names, scope files, credentials, tokens, or PII
  • Raw traffic, screenshots, exploit evidence, or live findings
  • Automatic target execution without an operator decision
  • A public repository, downloadable playbook pack, or hosted reader