Public portfolio · verified build · synthetic data

Cyber-exposure management reference implementation by Alfe CoronaSecurity architecture · engineering · automation

Make closure
verifiable.

Exposure Control turns fragmented security signals into normalized exposure records, business context, explainable policy, accountable remediation, owner and team routing, and evidence-based closure.

  1. SignalsFragmented findings
  2. Canonical ModelNormalized records
  3. Business ContextApps, assets, owners
  4. PolicyExplainable decisions
  5. OwnerAccountable routing
  6. EvidenceValidated closure
Verified capabilities and assurance summary
SYNTHETIC PROVING GROUND

Atlas Meridian makes the architecture concrete.

This entirely fictional banking environment supports the architecture with realistic applications, assets, teams, ownership gaps, source quality issues, and scale without using employer, customer, production, or real bank data.

100
Applications
1,000
Assets
20
Engineering teams
~10,000
Correlated exposures

Validated synthetic scale model; not a production benchmark. The dashboard makes all 10,000 sanitized records filterable and keeps 12 representative cases for readable detail.

THE CONTROL PATH

One visible chain from source signal to enterprise decision.

A source finding is normalized, enriched with business context, evaluated through policy, routed to an accountable owner, tracked through remediation, and only closes when current validation confirms the exposure changed. A failed gate returns the work.

Swipe to follow all five stages →
Exposure Control control pathFive stages connect detection, deterministic prioritization, accountable ownership and routed remediation, validation, and closure. Failed validation returns work to remediation.INPUT & POLICY BOUNDARYACCOUNTABLE REMEDIATIONVALIDATION GATE1DETECTNormalized signal fromscans and file input2PRIORITIZEContextual risk andgoverned priority3ROUTE & REMEDIATEOwner and team resolved;work routed and tracked4VALIDATEFreshness and tenantidentity checked5CLOSEOnly after evidenceproves the fix heldGATE FAILS: RETURNTO TRACKED REMEDIATIONGATE PASSES: CLOSEWITH NEWER EVIDENCE
DEMONSTRATION BOUNDARY

Atlas Meridian is the fictional enterprise proving ground for this model. It is synthetic, non-production, and not real bank data or customer telemetry.

PRODUCTION BOUNDARY

A real deployment requires separately permissioned identities, authoritative scanner retests, operating controls, and measured reliability.

WHAT I BUILT

Architecture carried through to working controls.

I designed the lifecycle and implemented the vertical slice: schemas, scoring, replaceable adapters, ownership resolution, remediation routing, persistence, a GitHub Issues adapter, validation gates, tests, and deployment references.

01 / MODELCanonical schemas and workflow invariants
02 / DECIDEDeterministic contextual risk and a versioned remediation-priority policy
03 / ACTOwnership resolution, remediation routing, and an idempotent GitHub Issues adapter
04 / STORESQLite persistence and a PostgreSQL adapter with forced tenant row-level-security policies
05 / ASSURETests, scanners, workflow permissions, and deployment references
WORKING TODAY

Runnable portfolio MVP

Local-only CSV ingestion, deterministic risk scoring, accountable routing, a GitHub Issues adapter, two persistence adapters, repository scanners, a dashboard, and a safe lifecycle demo.

PRODUCTION EXTENSION

Authoritative sources and operations

IAM, EDR, CSPM, CMDB, Jira, and ServiceNow integrations are extension points for production integration. Production also needs recovery, security, reliability, and scale controls.

ROUTING CONTROL

No silent assignment

Asset-to-application and application-to-team context resolve ownership. Missing, stale, or conflicting ownership is held for governance review and escalation instead of being routed silently.

Inspect the technical architecture Try the private decision engine
IMPLEMENTATION REVIEW

Material claims with direct review paths.

This portfolio shows a working reference implementation using synthetic data. It is intended for technical and hiring review.

CONTROL / LIFECYCLE

Working synthetic lifecycle

The public decision dashboard demonstrates the finding-to-closure model with synthetic systems, owners, remediation states, and validation records.

Demonstrated
CONTEXT / ATLAS

Synthetic enterprise proving ground

Atlas Meridian is a fictional, non-production enterprise context used to reason about applications, assets, teams, owners, source quality, and decision routing.

Modeled
ASSURANCE / VERIFIED

Quality gates completed

Architecture validation and the portfolio build, type, lint, test, security, and smoke-test gates completed successfully before publication.

Verified
BOUNDARY / CONTROLLED

Bounded, protected implementation

Synthetic data demonstrates the design, implementation source stays private, and the dossier states what production adoption would require.

Bounded
PROJECT FIT

Built for a hiring conversation.

Exposure Control demonstrates Alfe Corona’s approach to cybersecurity architecture, secure automation, cloud security engineering, and clear communication across security, engineering, and risk stakeholders.

Alfe Corona, creator of the Exposure Control cybersecurity architecture portfolio
Designed and built byAlfe CoronaSecurity architecture · engineering · executive risk communication