The evidence, with the asterisk already attached.
I'd rather you trust the parts that are real than be impressed by parts that aren't.
I designed PANTHEON, multi-tenant isolation, governance, metering, agent safety, from first principles, then directed AI to build all of it: solo, to production, running real businesses' data. What I bring is the systems thinking to design it, and the discipline to make the machine prove it works.
Isaac Teague Frayling · Cardiff, UK · UK citizen · open to relocate worldwide (sponsorship needed outside the UK & Ireland) · one-page CV →
↑ The hero art, favicon, avatar and social card on this page were all generated by the system I built. The work made its own portfolio.
External credit. Credited reporter (one of seven) on CVE-2026-104850 (GHSA-6qxp-vccf-f47h), a high-severity advisory (CVSS 7.5) in the MCP TypeScript SDK: its OAuth client could send stored credentials to a server chosen by the MCP server; fixed in 1.31.0 and 2.2.0. Not a validation of PANTHEON; a check that someone else ran on my work.
No slides, no "trust me." The system is live, go break it, then have the code behind it reviewed under NDA. What I shipped is real and running, whether or not I typed a character of it.
the value
I designed strict multi-tenant isolation on Postgres row-level security, two-role, fails closed, that no audit has got through at the database. One leak was found outside it (chat history, July) and fixed. I didn't write the SQL. I designed the model: the failure modes, the blast radius, and drove the build until it held.
The governed agent loop, perceive → knowledge → tools → judge → meter, with guardrails, a crisis protocol, overdraft-proof metering and human-approval gates, is my design. The control-plane thinking is mine, AI wrote the code to my spec.
The substrate, a no-code Studio, bespoke generative art, a live Telegram channel (WhatsApp built, pending Meta approval), metering, auth, custom domains. All of it my idea, all of it built by directing AI, Postgres to pixels, shipped and running, solo.
Every change has to pass a purity boundary enforced in CI, the latest CI run's count of tests, repeated adversarial audits where every finding was refuted before it counted. Directing AI well means refusing to trust it, that's the actual skill.
I ship the honest version: every number on the audit page carries its own asterisk, the site says out loud what isn't solved yet, and safety: a crisis message reaches help even at zero credits, beats the metric. I'd rather be trusted than impressive.
Every new capability keeps the same invariants: a golden-file harness proves changes are byte-safe, an edit ledger makes every change undoable, and anything that adds new surface gets an adversarial security pass before deploy. I move fast without letting the machine cut corners.
the method
I decide what the system must guarantee, then make it prove it. I design the system and direct AI to build it, and PANTHEON is what that produces. I read, judge and debug everything the machine produces; I don't type the implementation from a blank file. Here's the shape of it:
Design the system from first principles → break it into pieces AI can build → direct AI to build each one → attack the result until it holds → ship it and keep it running in production. That's the loop, end to end.
Multi-tenant isolation & trust boundaries · governance tiers & human-in-the-loop · atomic metering & rate control · agent loops, tools & guardrails · prompt-injection defence · failure-mode & blast-radius thinking. I designed all of these. I just talk about them in plain English, not jargon.
Postgres with row-level security · FastAPI services · a governed agent loop · MCP, both directions · React frontends · Docker / nginx deploys. I directed the build and I know how every piece behaves.
CI purity boundaries · golden-file snapshot tests · the latest CI run's count of tests passing (latest CI run) · repeated adversarial audits: a 50-agent audit and a 14-lens re-audit, latest, where every finding is refuted before it counts. The instinct to distrust the machine's first answer is the whole job.
I'd rather you trust the parts that are real than be impressed by parts that aren't.
a judgement call I got wrong
Two weeks ago I chose to check English messages for crisis wording with a fixed phrase list only, to spare most messages an extra AI call. An audit on 25 September showed the list missed "I don't want to live anymore" and three other common phrasings. I reversed the call the same day: crisis wording now goes to the AI check, all four are tests that failed on the old code, and ordinary messages paying for the extra call fell from 4 in 32 to 1. The saving was right for most checks and wrong for the one where a miss matters most.
the honest deal
I own the systems thinking and the delivery through AI, deciding what to build, designing how it holds, and pushing it until it's shipped. Pair me with engineers who own the line-level craft I don't, and you get both halves covered.
Every change that matters gets adversarial review; I never trust the machine's first answer. Two things that instinct produced: the July cross-tenant leak, found by my own audit and now a regression test, and the MCP SDK advisory above, found in someone else's code.
One role: the person who owns your AI agent’s trust boundary. Tenancy, approvals, metering, the tool that trusts its caller: I draw where it can fail, build the guarantee in, and ship the test that proves it. A founding or early hire at a startup that has an agent touching real customers, or is about to. I'm open to relocate worldwide for the right one, and I care more about the problem and the people than the title.
Fair question. I could raise on PANTHEON, but I know exactly what it's short on, and it isn't the build. It's distribution: the network and reach to put it in front of the businesses it's built for, which I don't have and won't fake. I'd rather bring this to a team that already has that reach than spend years becoming a founder I'm not. Building it solo proved I can design and ship the whole thing. Taking it to market alone was never the plan, PANTHEON stays live as proof, not as a side project splitting my focus.
day one
Not "learn the ropes for a quarter." The method that built PANTHEON, pointed at your product:
Find the tenancy / authorization / blast-radius edges and work out how each one fails, before anything gets built. You can't govern what you haven't drawn, and drawing it is what I do.
Find the safety that was added after the fact: the overdraftable meter, the ungated action, the tool that trusts its caller, and redesign it so the guarantee is built in, not bolted on.
Spec it, direct AI to build it, and ship it with the check that proves it: a test, a snapshot, an invariant, so the next person can move fast without having to prove it all over again.
Tell me the role and what you're building. I read every email and reply within a few days, then a call, a live walkthrough of the system, and the code reviewed under NDA.
Prefer to poke before you write? Break the assistant, attack the isolation, or message the bot, it's all live.
No LinkedIn. The core system is private: the live system is the portfolio, but six components are published on PyPI and npm, the defect record is public, the method is replayable, and I am one of seven credited reporters on a high-severity MCP SDK security advisory. View / download my CV →
Hiring? Ask me what Isaac is good at, and where he is not the fit.