Research Areas Projects About About Contact Explore
Personal AI Research Lab

Exploring AI. Building in Public.

SafeHarborAI is my personal research space for agentic AI systems, cybersecurity concepts, and intelligent automation. Independent work, personal time, publicly shared.

10+
Years AI & Cyber
100%
Independent Work
Open Research
0
Employer Resources Used
Research Areas

What I'm Exploring

Personal R&D across agentic AI systems, intelligent products, and AI-powered hardware concepts. All work developed independently using personal time and resources.

Agentic AI Systems

Personal research into how autonomous AI agents can plan, use tools, and coordinate complex workflows. Exploring multi-agent architectures, LLM orchestration, and agentic design patterns.

  • Multi-agent orchestration research
  • LLM planning and reasoning patterns
  • RAG and retrieval pipeline experiments
  • Security-first agent architecture
  • Open prototypes and experiments

Live Prototypes

Personal projects built to explore AI product design end-to-end. From idea to deployed product, learning what it takes to build intelligent tools people actually use.

  • GetJobDrop: AI job matching prototype
  • Exploring AI UX and product design
  • Multi-tenant backend architecture
  • Continuous model integration
  • Consumer-facing AI applications

AI Hardware Concepts

Conceptual exploration of AI at the edge: smart hardware, embedded intelligence, and autonomous machines. Research-stage ideas for combining physical systems with AI.

  • Autonomous outdoor robotics concepts
  • Edge AI and embedded inference
  • Computer vision prototypes
  • Remote monitoring concepts
  • Hardware + software co-design
Live Prototype

GetJobDrop
AI-Powered Job Matching

A personal side project exploring AI-powered job matching. Upload your resume and receive a daily curated shortlist of roles matched to your skills and preferences. Built independently to learn full-stack AI product development.

Free tier, no credit card
25 AI matches per month
Built with Python, OpenRouter, Cloudflare
View GetJobDrop Prototype
How It Works
1Upload your resume
2AI parses your skills and preferences
3Top matches delivered every morning
Experimental Features
Resume tailoring, cover letter generation, ATS scoring, interview prep. Everything you need to go from resume to offer.
Live Prototype

Voice Agent
Talk to Your AI, Out Loud.

A browser-based conversational AI voice interface. No install, no wake word. Just speak. Whisper transcribes in real time, the agent responds with a natural AI voice in under a second. Multi-client deployable with per-client personas, knowledge bases, and branding.

No install, runs in any browser
Sub-second first response via streaming
Built with Whisper, OpenAI TTS, Cloudflare
How It Works
1Open in any browser, tap the orb
2Whisper transcribes your speech live
3AI responds with natural voice in <1s
Embeddable
One script tag drops the voice widget into any website. Per-client voice, persona, and domain knowledge. Already running on safeharborai.ai and getjobdrop.com.
Our Team

Meet the Team.
The Operatives Who Run SafeHarborAI & GetJobDrop.

Eighteen operatives. Two sites. One mission. Each one has a defined role, a defined codename, and they are on the clock 24/7 across safeharborai.ai and getjobdrop.com. Security. Operations. Intelligence. Client services. No days off. No handoffs. No gaps in coverage.

CLAW
ACTIVE
LIVE
ORCHESTRATION & COMMAND
CLAW

Primary AI orchestrator and personal assistant. Coordinates the entire agent fleet, handles direct operations, manages memory and continuity, and serves as the central intelligence layer across all systems. The operator behind the curtain.

ORCHESTRATION COMMAND & CONTROL MEMORY
SENTINEL
ACTIVE • EVERY 30 MIN
LIVE
SECURITY OPERATIONS
SENTINEL

Blue Team guardian. Monitors infrastructure, validates defenses, and files incident reports every 30 minutes around the clock. Checks site uptime, SSL certificates, DNS, security headers, and content integrity across safeharborai.ai and getjobdrop.com. Part of the ArgusSOC pipeline.

SITE MONITORING SSL HEALTH SECURITY HEADERS ARGUSSOC PIPELINE
WARDEN
ACTIVE • 3X WEEKLY
LIVE
OFFENSIVE SECURITY
WARDEN

Red Team penetration tester. Simulates adversary TTPs mapped to MITRE ATT&CK and OWASP WSTG, probes defenses for weaknesses, and generates exploitation reports three times weekly to harden the stack. Every finding feeds directly to FORGE. Part of the ArgusSOC pipeline.

ADVERSARY SIMULATION MITRE ATT&CK OWASP WSTG EXPLOITATION
FORGE
ACTIVE • HOURLY
LIVE
DETECTION ENGINEERING
FORGE

Senior detection engineer for the ArgusSOC pipeline. Proactively hunts MITRE ATT&CK coverage gaps, building and self-testing behavioral detections on a continuous loop, and forges Red Team findings from WARDEN into production-ready Sigma rules, Splunk SPL queries, and Microsoft Sentinel KQL, all mapped to MITRE ATT&CK.

SIGMA RULES SPL / KQL MITRE ATT&CK ATT&CK COVERAGE RULE VALIDATION
NEXUS
ACTIVE • HOURLY
LIVE
PIPELINE ORCHESTRATION
NEXUS

Purple Team orchestrator for the ArgusSOC pipeline. Coordinates the hourly cycle, queues tasks for WARDEN, validates detections from FORGE, and closes the loop between the core pipeline agents. The conductor of the ArgusSOC symphony.

CYCLE MANAGEMENT TASK QUEUING VALIDATION LOOP CLOSURE
SHEPHERD
ACTIVE • DAILY
LIVE
TALENT INTELLIGENCE
SHEPHERD

Powers GetJobDrop. Parses resumes, scrapes live job boards across 7,000+ listings daily, scores and matches candidates to roles, and delivers personalized job digests every morning without human intervention.

RESUME PARSING JOB MATCHING DAILY DIGEST
GUARDIAN
ACTIVE • EVERY 4H
LIVE
INFRASTRUCTURE OPS
GUARDIAN

DevOps operative. Watches safeharborai.ai and getjobdrop.com for uptime, SSL health, form functionality, and regressions every four hours. Every change is tested in staging against a 15-point safety gate, and production updates are executed by a deterministic non-AI script. Every action is logged.

UPTIME MONITORING SSL HEALTH CHANGE EXECUTION REGRESSION DETECTION
HERALD
ACTIVE • HOURLY
LIVE
INTELLIGENCE & COMMUNICATIONS
HERALD

Threat intelligence operative for the ArgusSOC pipeline. Runs hourly, monitoring NVD, CISA KEV, and external threat feeds, ingesting CVEs and active exploit reports, and surfacing critical findings to NEXUS for immediate tasking.

THREAT INTEL CVE MONITORING NVD / CISA KEV INTEL SYNTHESIS
COURIER
ACTIVE • ON-DEMAND
LIVE
VOICE INTELLIGENCE
COURIER

Real-time voice AI deployed across SafeHarborAI, GetJobDrop, and ArgusSOC. Handles live visitor conversations, answers questions, and represents the brand with sub-second response latency. Powered by Whisper speech recognition with per-client neural voices (Deepgram Aura, Kokoro, OpenAI, edge-tts).

REAL-TIME VOICE WHISPER STT <1s LATENCY MULTI-CLIENT
OVERSEER
ACTIVE • EVERY 15 MIN
LIVE
FLEET OPERATIONS
OVERSEER

ArgusSOC fleet monitor and change manager. Watches all pipeline agents every 15 minutes for errors, stalled tasks, and performance drift. Files structured change control tickets and Telegrams for human approval before executing fixes.

FLEET MONITORING CHANGE CONTROL TICKET WORKFLOW SELF-HEALING
VIGIL
ACTIVE • CONTINUOUS
LIVE
SOC OPERATIONS
VIGIL

Full-spectrum SOC analyst. Triages every alert, runs investigations, reconstructs timelines, and closes cases end-to-end without waiting for a human to pull the thread.

ALERT TRIAGE INVESTIGATION CASE MANAGEMENT
CIPHER
ACTIVE • CONTINUOUS
LIVE
THREAT HUNTING
CIPHER

Hypothesis-driven threat hunter. Forms a theory about how an attacker behaves, searches for matching patterns across telemetry, and hands confirmed findings to FORGE.

HYPOTHESIS GENERATION PATTERN MATCHING THREAT INTEL
PROCTOR
ACTIVE • WEEKLY
LIVE
COMPLIANCE & AUDIT
PROCTOR

Weekly compliance monitor. Tracks controls against NIST, SOC 2, ISO 27001, and PCI-DSS, collects evidence automatically, and surfaces gaps with remediation guidance before they become audit findings.

NIST / SOC 2 EVIDENCE COLLECTION GAP ANALYSIS
LEDGER
PILOT • FOUNDING COHORT
PILOT
CASH FLOW & RECEIVABLES
LEDGER

Cash flow watchdog for small businesses. Syncs Square and Stripe activity, drafts invoices and payment follow-ups for approval, and forecasts cash position weeks ahead. Currently in pilot with founding customers.

INVOICE AUTOMATION CASH FORECASTING PAYMENT SYNC
BREACH
ACTIVE • ON-CALL
LIVE
INCIDENT RESPONSE
BREACH

First responder. When an incident fires, BREACH contains it, preserves evidence, reconstructs the attack timeline, and drives recovery. Closes incidents with full root cause and lessons learned.

CONTAINMENT FORENSIC TIMELINE ROOT CAUSE ANALYSIS
VAULT
ACTIVE • WEEKLY
LIVE
IDENTITY & ACCESS
VAULT

Identity is the new perimeter. VAULT runs weekly scans for privilege creep, orphaned accounts, and suspicious authentication patterns, enforcing zero trust before access anomalies become breaches.

ZERO TRUST PRIVILEGE MONITORING ACCESS REVIEWS
SIGNAL
ACTIVE • 3X WEEKLY
LIVE
SOCIAL & BRAND
SIGNAL

AI content engine that never misses a posting window. Generates on-brand thought leadership for LinkedIn and X, schedules intelligently, and keeps the brand visible while you focus on the actual work.

CONTENT GENERATION SMART SCHEDULING MULTI-BRAND
VENDOR
ACTIVE • ON-DEMAND
LIVE
MARKETPLACE & SALES
VENDOR

Snap a photo, let VENDOR do the rest. Analyzes inventory, writes optimized marketplace listings, sets competitive prices from real-time comparisons, and pushes them live across multiple platforms automatically.

AI LISTING COPY PRICE INTELLIGENCE MULTI-PLATFORM
VAULTER
ACTIVE • NIGHTLY
LIVE
DISASTER RECOVERY
VAULTER

Nightly disaster recovery agent. Commits workspace changes, bundles the full git history, encrypts secrets, and ships everything off-site to Google Drive. Verifies every upload and creates CM tickets on any failure.

GIT BUNDLE ENCRYPTED SECRETS OFF-SITE GDRIVE
The Agent Fleet

The SafeHarborAI Agent Fleet.
Personal Research Agents.

Personal research into autonomous AI agents running across different domains. Cybersecurity. Content. Operations. All agents run on personal infrastructure for R&D purposes.

Argus by SafeHarborAI
ArgusSOC™  ·  LIVE at argussoc.app
ArgusSOC
Watch. Attack. Detect. Defend. Repeat. Forever.

A fully operational agentic SOC platform, named for the Greek titan with 100 eyes. ArgusSOC does not wait for alerts. It ingests the global threat landscape, attacks its own defenses, engineers new detections from what it finds, and validates the results. On a loop. With live findings published as they happen.

The core loop runs five specialized agents. HERALD ingests threat intel hourly from NVD, CISA KEV, and external feeds. WARDEN, the red team, simulates adversary TTPs and produces exploitation reports. FORGE, detection engineering, hunts MITRE ATT&CK coverage gaps and forges findings into tested Sigma, SPL, and KQL rules. SENTINEL, the blue team, validates defenses and files incident reports every 30 minutes. NEXUS, the purple team orchestrator, runs the cycle: tasking WARDEN, validating FORGE, closing the loop. Live at argussoc.app.

View Concept Architecture Fully operational  ·  Running 24/7  ·  Real findings  ·  argussoc.app
THREAT INTEL Watch. Enrich. Feed. RED TEAM Attack. Expose. Report. DETECTION ENG. Build. Engineer. Deploy. BLUE TEAM Detect. Alert. Respond. PURPLE TEAM Orchestrator
The Support Layer
The loop never runs alone.

Beneath the five-agent core sits a second tier of agents that keeps the platform honest, healthy, and recoverable. They watch the watchers, govern every change, and guarantee the whole system can survive a bad day.

CIPHER
Threat Hunter

Hypothesis-driven threat hunter. Reacts to high-risk intel the moment it lands and proactively hunts MITRE ATT&CK techniques across the environment.

OVERSEER
Fleet Health & Change Manager

Watches every agent in the fleet, tracks health and drift, and files change-management tickets the moment anything needs to move.

GUARDIAN
Governed Change Executor

Nothing reaches production without validation and approval gates. GUARDIAN enforces those gates and executes every governed change.

VAULTER
Disaster Recovery

Encrypted backups of everything that matters, so the platform can be rebuilt from scratch if the worst ever happens.

Underneath it all sits the change-management system itself: every action ticketed, every ticket carrying a backout plan, every step captured in a full audit trail.

Every agent runs on your infrastructure, on your terms. No vendor lock-in. No black boxes. Full control.

View Research Concepts
Research Principles

How I Approach This Work

Principles that guide every project: security-first thinking, honest prototyping, and building things that actually work.

01

Security-First by Design

Built on a cybersecurity foundation. Every system is architected with data privacy, access control, and threat modeling baked in, not bolted on after the fact.

02

Real-World Grounding

10+ years in cybersecurity informs every design decision. Research is rooted in how real systems behave under pressure, not just theory.

03

No Off-the-Shelf Shortcuts

Every prototype is purpose-built from first principles. The goal is understanding how things actually work, not wrapping existing APIs with a thin veneer.

04

Full-Stack Exploration

Research spans software agents, deployed products, and hardware concepts. The goal is understanding AI across the full stack, not just one layer.

05

Privacy by Default

Personal data handled in research is kept local, minimal, and never sold or shared. Privacy-first is a design constraint, not an afterthought.

06

Working Code, Not Slides

Research that ships. Every idea ends as running code, a deployed prototype, or a documented finding. No vaporware.

About

Personal R&D Lab.

SafeHarborAI is my personal AI research and development lab. I use this space to explore agentic systems, cybersecurity AI concepts, and intelligent automation. All work is developed independently, on personal time, using personal infrastructure and publicly available resources.

The research here spans real deployed prototypes to early-stage concepts. Some things work well. Some are experiments that taught me what not to do. All of it is honest R&D with no employer confidential information, no proprietary systems, and no client data.

This site is not a commercial services business, consulting firm, or product sales platform. It is a personal learning and building space, shared publicly because building in the open makes the work better.

MT
Mark Thomas
Founder, Cybersecurity Professional & AI Researcher
10+ years in detection engineering, threat hunting, and agentic AI
Get in Touch

Get in Touch

Interested in discussing AI research, agentic systems, or cybersecurity concepts? Reach out. Happy to connect with researchers, builders, and curious people.

CISSP CERTIFIED
256-BIT SSL
SECURED BY CLOUDFLARE
DATA NEVER SOLD

Send a Message

Happy to connect with fellow researchers and builders.

Something went wrong. Your message wasn't delivered. Please try again, or email us directly at hello@safeharborai.ai.
Message Received!

Thanks for reaching out. We'll be in touch within one business day.
Looking forward to building something great together.

SafeHarborAI is a personal research and development lab. This site represents independent work developed outside of any employment, using personal time, personal systems, and publicly available resources. No employer confidential information, proprietary systems, internal tools, customer data, or non-public business information is used in any project shown here. This site is not affiliated with, endorsed by, or connected to any employer, customer, vendor, or partner organization.