Maths background. I build tools that measure whether systems protect the data they claim to protect.
PDF Changer — 21 browser-only PDF tools. Files never leave the tab. CSP-enforced connect-src 'none', triple-monitor integrity chain, cryptographic audit trail. 32k lines, 303 tests. Live at pdfchanger.org.
beacon — Business security surface scanner. Checks TLS, headers, email auth, exposed files, third-party tracking, form security. Maps every finding to a documented breach. 100 breach precedents with cited sources. 50 tests.
vault — Encrypted document exchange. AES-256-GCM client-side, HKDF key expansion, zero-knowledge server. The encryption key lives in the URL fragment — never sent to the server. 9 research documents written before any code. 23 tests.
threadr — Reconnaissance tool for security teams. Dempster-Shafer evidence fusion, spectral clustering via Fiedler vector, Lévy-stable request timing. 17 plugins, 5 analytics engines.
degauss — Identity exposure quantification. Shannon entropy scoring, Fellegi-Sunter record linkage, data broker supply chain graph, attack feasibility assessment. 303 tests.
ε-tx — Cryptocurrency privacy analysis. 8 attack surfaces, Dempster-Shafer fusion, inverse-OSPEAD for Monero, Boltzmann entropy for CoinJoins. 18 papers cited.
Everything is MIT. giuseppegiona.com