A public, open-source kit for cloud governance with a strict audit-only posture:
- IAM baseline checks and least-privilege patterns
- Compliance-aware evidence packs
- Threat-model driven playbooks
- GCP-first reference implementations, with multicloud awareness
I study ethics seriously. For me, ethics also includes loyalty and belonging with no expiration date. If you sponsor this work, you are supporting a long-term, credibility-first program: reproducible security governance assets, shipped in public, with transparent reporting.
I already hold a secured seat/offer for a Master’s in Technology. Sponsorship helps sustain the time and infrastructure required to keep this project shipping at a professional standard while advancing that degree.
There is also a required, discreet trip to Brazil for privacy and personal security reasons, to conduct stakeholder alignment and requirements gathering connected to: Cloud computing + governance + cybersecurity + IAM. The output of that fieldwork will be reflected as public deliverables in this repository, without exposing sensitive personal logistics.
- 1 new or upgraded playbook (with validation steps)
- 1 policy template or guardrail pattern
- 1 audit-only script improvement (reporting/evidence)
- 1 sponsor report in /reports
- /playbooks — reproducible security governance playbooks
- /policies — policy templates and rationale
- /scripts-audit-only — state collection and reports (audit-only)
- /evidence-packs — audit evidence structure
- /adr — architecture decisions
- /reports — monthly sponsor reports
- /assets — images used in the README