Personal Website · GitHub · Duck Detector · me@eltavine.com
- Working on Duck Detector, a local-first Android security detection app.
- Building across Android / Kotlin / C++ / NDK and React / TypeScript / Go.
- Interested in device integrity, native probes, auth systems, platform engineering, and privacy-aware products.
- Currently learning deeper C++, Android internals, and production security architecture.
- Open to collaboration on Android, security tooling, and thoughtful full-stack products.
An Android security research and diagnostic app focused on local, on-device evidence collection.
- Built with Kotlin, Jetpack Compose, Material 3, Android NDK, C++, and low-level native probes.
- Detects signals across Root, Bootloader, Custom ROM, Dangerous Apps, Kernel Check, LSPosed, Memory, Mount, Play Integrity Fix, SELinux, System Properties, TEE / KeyStore, Virtualization, and Zygisk.
- Uses modular feature packages with separate
domain,data,presentation, anduilayers. - Includes native preload, JNI bridges, cross-process validation, isolated-process checks, and C++ / assembly probe paths.
- Privacy-first by default: core detection runs locally, with network use limited to explicit user-triggered refresh paths.
A private full-stack platform project where I work on production-grade web, backend, auth, deployment, and governance architecture.
- Monorepo with pnpm, Turborepo, React, Vite, Astro, TypeScript, and shared web packages.
- Backend built with Go, ConnectRPC, Protobuf, SQLC, PostgreSQL, Redis, and structured module boundaries.
- Auth and authorization work includes Ory Kratos / Hydra / Keto / Oathkeeper, browser auth flows, OAuth surfaces, tenant-aware access, MFA bootstrap, and audit trails.
- Deployment and operations cover Cloudflare Pages, Docker-based VPS services, migrations, runtime config validation, OpenTelemetry, SBOM generation, license checks, vulnerability scanning, and secret scanning.
- Frontend work spans separate admin, console, and landing applications with typed app config, generated RPC clients, i18n, and reusable UI/auth packages.
- Android device integrity and local security diagnostics.
- Native runtime visibility, JNI boundaries, C++ probes, and platform behavior under modified environments.
- Contract-first APIs with Protobuf / ConnectRPC and generated clients.
- Authentication, authorization, MFA, OAuth, tenant isolation, and auditability.
- CI quality gates, reproducible builds, dependency governance, and secure deployment workflows.



