Web Design & Development
Fast, privacy-first websites and web apps. Static-first, no trackers, accessible, instant to load, exactly like this page: zero JavaScript, zero third-party requests.
Security Ops®/Post-Quantum Crypto /Self-Hosted Infra
IT analyst by profession, open-source builder by obsession. I write post-quantum backup, transport and audit tools, hardened GNU Guix systems, and privacy-first self-hosted services in C11, Rust, Python and Scheme, for a safer and more transparent internet.
In Code We Trust.
online · Brazil
I'm an IT Support Analyst in Caxias do Sul, Brazil, and a self-taught systems and security builder. Everything under the Security Ops® banner is written in my own time, released as free software, and run on infrastructure I administer myself, on clearnet and on Tor. The goal is simple: a safer, more transparent internet, protecting users through FOSS.
My focus is systems engineering, GNU Guix, applied cryptography, server administration and privacy tools. Requirements, threat models, tests and limitations belong in the documentation of each project and version. Publishing source enables inspection; it is not a security certification.
I ship in C11, Rust, Python, Bash, Scheme and Kotlin. I hold a technical degree in Information Security and am pursuing a postgraduate degree in Software Engineering. Commercial work runs through my registered Brazilian company (CNPJ in the footer) with the same standard: complete code, real tests, and NIST/RFC vectors wherever cryptography is involved.
I maintain original projects and also host third-party applications. The directory below distinguishes tools, services and documentation: hosting an instance does not imply authorship, an independent audit or a guarantee of anonymity.
Inventory reviewed on 2026-09-06. Aliases may lead to the same service. Screenshots do not prove continuous availability, authentication or every feature.
Independent free-software label: post-quantum backup, transport and audit tools, a hardened Guix distribution, a personal Guix channel, plus self-hosted Forgejo, search, wiki and Tor services.
Enterprise IT operations by day. All Security Ops work happens outside working hours, on my own hardware and infrastructure.
Plus vendor-issued, Credly-verified course badges, listed on my GitHub profile.
Websites, software and security work, delivered complete, documented and buildable, through my registered Brazilian company (CNPJ in the footer).
Fast, privacy-first websites and web apps. Static-first, no trackers, accessible, instant to load, exactly like this page: zero JavaScript, zero third-party requests.
Systems software in C11, Rust and Python: CLIs, daemons, libraries and protocol implementations. Zero-warning builds, sanitizer-clean, tested, packaged for real installs.
Cryptographic inventory, crypto-agility assessment and migration to ML-KEM / ML-DSA, with a tamper-evident audit trail if you are regulated. Find what breaks under a quantum adversary before it does.
Hardened deployments with defense-in-depth: Docker, GNU Guix, nftables, WireGuard, Tor and clearnet, reverse proxies and monitoring. Threat-modelled in plain language.
Reproducible system configuration, kernel and GPU tuning, custom channels and packaging. The same discipline behind my public guix-config (16★ on Codeberg) and Security Ops OS.
Several projects ship AGPL-3.0 with a commercial license option for enterprise use. Talk to me about dual-licensing, integration and support.
From backup to a music studio: each project has its own purpose, documentation and explicit limits. ZUPT is the backup archiver; VaptVupt is the codec, documented separately.
ZUPT 5.2.9 is the backup tool: compression, authenticated encryption, verification and restoration, with the bundled VaptVupt 2.65.11 codec.
Documentation for Evelin secure transport and remote-access tools.
An embedded SQL database with integration and encrypted-format documentation.
A daemon-free container runtime configured in Guile Scheme for GNU Guix.
A browser music studio with arrangements, instruments, a sampler and a DJ room.
A reading interface for Hacker News stories and discussions.
54 services. 69 public addresses. A visual library with context, first steps and paths to documentation — including third-party applications we host.
Open a category for screenshots, official addresses and first steps. Different domains may be aliases of the same application.
HTTPS uses the public internet. Onion addresses require Tor; b32.i2p requires an I2P router. Available routes are listed per service; missing addresses are not invented.
Private applications require authorization. Courses are in presale, with lessons beginning soon. Read the guide and validate permissions before uploading files; questions can be sent to sac@securityops.co.
Open a category to view its services. Images are real screenshots; click to enlarge.

Presale portal for systems, security, cryptography and privacy courses.
The page could not be captured correctly. Use the links and guide below; blank or error screens are not displayed as a service preview.
Video and document library for enrolled students with authorized access.
The page could not be captured correctly. Use the links and guide below; blank or error screens are not displayed as a service preview.
Guide to authorized access to the server lab using Tor and Evelin.

An introduction to Security Ops projects, services, learning and contact channels.

Portfolio of systems engineering, security, free software and research.

Directory of public services and practical ecosystem guides.

Documentation for Evelin secure transport and remote-access tools.

A daemon-free container runtime configured in Guile Scheme for GNU Guix.

An embedded SQL database with integration and encrypted-format documentation.

Presentation and installation guide for the Security Ops GNU Guix system and live image.

A desktop environment accessed through a web browser.

A source forge with projects, documentation and development history.

A second public instance for Git repository hosting and collaboration.

A GNU Guix substitute server with a public signing key.

Portal and specification for the experimental BTP protocol, with a connection guide.

An HTTPS gateway for reading BTP documents from allowed origins.

Password generator with configurable length and character groups.

A password-management interface with sign-in and server selection.
The page could not be captured correctly. Use the links and guide below; blank or error screens are not displayed as a service preview.
An interface for managing two-factor authentication codes.

Inspection of a website’s public information, including DNS, TLS and headers.
The page could not be captured correctly. Use the links and guide below; blank or error screens are not displayed as a service preview.
FORKBOMB’s file-encryption interface, hosted by Security Ops.

Configuration guide for the public filtered-DNS profile and its endpoints.

Project website and wiki for temporary rooms with chat, calls, drawing and sharing.

The Keywave temporary-room application, accessed through an invitation link.
The page could not be captured correctly. Use the links and guide below; blank or error screens are not displayed as a service preview.
Browser video calls started through an invitation.

A terminal-style chat interface using a handle and passphrase.

A Matrix homeserver with a public Synapse discovery page.

A Matrix homeserver with a public Continuwuity page.

A web client for connecting to the IRC network configured on the service.

Documentation for the GNU Emacs WhatsApp client and its local bridge.

Screen and audio recorder with installation, capture, mixing and streaming documentation.

Text sharing with password, expiry and burn-after-reading options.

Short URL creation with an anti-spam check.

ZUPT 5.2.9 is the backup tool: compression, authenticated encryption, verification and restoration, with the bundled VaptVupt 2.65.11 codec.

Documentation for the C11 LZ and tANS compression codec.

Web interface for ZUPT compression, extraction, key generation and archive verification.
The page could not be captured correctly. Use the links and guide below; blank or error screens are not displayed as a service preview.
Sign-in page for an authenticated file service.

Speed measurement between the browser and the test server.

Private files, synchronization and collaborative documents. An authorized account is required.

YouTube video discovery and playback through a separate interface.

Pinterest image search through an alternative frontend.

An alternative Pixiv frontend for illustrations, rankings and artist discovery.

A browser music studio with arrangements, instruments, a sampler and a DJ room.

An alternative YouTube frontend with dark defaults, adaptive quality and two operator-owned Companion backends.

A web search interface operated by Security Ops.

A reading interface for Hacker News stories and discussions.
Redlib keeps its local interface available, but Reddit is refusing content access. The feed returns HTTP 503; an error screen is not used as a preview.
Local settings availableAn alternative reading interface for public Reddit content.
The page could not be captured correctly. Use the links and guide below; blank or error screens are not displayed as a service preview.
Geographic visualization of public sources, maps and observed data.

Independent publication of a theoretical physics proposal, with references and hypotheses.

A statistical-analysis article distinguishing observations, estimates and reported accounts.

Daily biblical message, editorial reflection and reading reference.

A listings and messaging portal for local trading.

An atelier website for custom pieces, sewing, repairs and alterations.

A simulated shop and casino using fictional credits, with no real payments or deliveries.
Screenshots show public pages without an authenticated session. Some applications may be unavailable or depend on JavaScript and external services; this portfolio uses no JavaScript. Tor/I2P access does not guarantee anonymity if you identify yourself or follow external links. Check status before relying on a service.
The design rationale behind BTP: why a clean break from HTTP+TLS, and how identity is anchored by cross-witness attestation instead of certificate authorities.
DOI 10.5281/zenodo.20278231An independent theoretical framework exploring quantum cosmology across dimensions. Source in TeX at git.securityops.co/cristiancmoises/oqct.
SSH usage with a high level of security and obfuscation: tunnels, hardening, tradecraft.
Full research record, preprints and identifiers.
A website, a piece of software, a hardened server, or a post-quantum migration. Send a message. I read every one.
sac@securityops.co