freundcloud
▶ Listen & watch · 10 episodes

The projects, out loud.

Two hosts talking through what I've built and why — plus one short video — generated with Google NotebookLM from the projects' own documentation. If you'd rather listen on a commute than read a showcase page, start here: every episode has a download link, and each one is also embedded next to the project it covers.

▶ Video · 7:27 The journey of a commit

The short one, and the only one with pictures: a single commit followed all the way to production — built, scanned, attested, checked against policy — and what the "digital passport" it accumulates is actually for.

Read about Fides → · Download 38 MB

▶ Video · 7:09 CFactory: the control tower

The pipeline from the cockpit — the PARR loop running across PFactory, AIFactory and TFactory, and the point it keeps coming back to: the human always clicks.

Read about The Factory suite → · Download 33 MB

▶ Podcast · 20:51 Ending the audit nightmare with SARC

Why compliance evidence belongs in a tamper-evident ledger inside your own cloud rather than a SaaS token you have to trust — and what changes when the CAB chair and the regulator are looking at the same dashboard.

Read about SARC → · Download 16 MB

▶ Podcast · 13:39 Fides turns software compliance into code

The evidence ledger underneath SARC, on its own terms: provenance from commit to running runtime, four-eyes approval, hash-chained audit log, and why "we'll compile the evidence at quarter end" is the thing to kill.

Read about Fides → · Download 10 MB

▶ Podcast · 18:58 Hecate replaces vibes with cryptographic evidence

Flux makes a cluster match git but has no opinion about what should be in git next. What it takes to make cross-environment promotion a reviewed, evidenced thing instead of hand-rolled CI nobody reads.

Read about Hecate → · Download 14 MB

▶ Podcast · 26:41 Governing AI agents in regulated industries

The longest one, and the argument underneath all the rest: no model in the gate, evidence as a by-product rather than a reconstruction, and why a gate verified only by passing is indistinguishable from one that cannot fail.

Read about Agentic SDLC → · Download 20 MB

▶ Podcast · 21:38 Governing AI agents with PFactory blueprints

The planning half of the Factory suite — taking a plan, enriching it with live org and cloud context, running architecture, security and feasibility gates over it, and emitting governed work an agent can actually execute.

Read about The Factory suite → · Download 16 MB

▶ Podcast · 21:35 Software development as an autonomous assembly line

The whole pipeline end to end — PFactory plans it, AIFactory builds it, TFactory tests it, CFactory watches it — and the human gate at every seam that stops it being a machine that ships whatever it likes.

Read about The Factory suite → · Download 16 MB

▶ Podcast · 20:27 Janus: a secure gateway for enterprise AI

What it takes to put an MCP gateway in front of internal APIs and have it survive a security review — fail-closed on misconfiguration, secrets the model never sees, an SSRF guard, and redaction before anything reaches the LLM.

Read about Janus → · Download 16 MB

▶ Podcast · 15:35 Bifrost automates safe enterprise pipeline migrations

The last 10% of an Azure DevOps to GitHub Actions migration that the importer leaves to you — why it stays review-first, never auto-commits, and can run entirely on local models inside an air-gapped network.

Read about Bifrost → · Download 12 MB

These are machine-generated from each project's own documentation, so treat them as a readable summary rather than my own words — the written pages are the authoritative version. Audio is 96 kbps mono AAC and the video is 720p H.264; the files live in the repo, so a download is a plain HTTP fetch with nothing tracking it.