SECURITY OPS // SOVEREIGN SOFTWARE LAB
I build software that can be inspected, reproduced, self-hosted and owned.
privacy engineering · systems · GNU Guix · post-quantum experiments · free software
Most software asks you to trust it. I prefer systems that give you evidence.
I am an IT Support Analyst from Brazil and an independent open-source builder. Outside work, I design privacy-conscious tools, experiment with secure systems, maintain self-hosted infrastructure and contribute fixes upstream.
▸ boot.log — open operator profile
operator Cristian Cezar Moises
base Brazil
mission user-controlled, auditable software
runtime GNU/Linux · GNU Guix · self-hosted infrastructure
signal privacy · reproducibility · security · open development
status building in public
Security claims should be testable. Infrastructure should be reproducible. Users should remain in control.
NODE 01 // SELECTED ORIGINAL WORK
Only the projects most representative of my current work are listed here. Mirrors are not shown as separate projects.
| Project | Focus | Repository | Live |
|---|---|---|---|
| WhatsAppel | Emacs client with a Node/Baileys bridge | GitHub | Open |
| SecurityOS | Web-based environment for security, privacy and education | GitHub | Open |
| Guix Config | Reproducible GNU Guix system configurations | Forgejo | Open |
| TurboRec | High-quality screen recording powered by FFmpeg | GitHub | Open |
| ZUPT | Authenticated encrypted backup with post-quantum key encapsulation | GitHub | Open |
| VaptVupt Codec | Lossless LZ + tANS compression codec | GitHub | — |
| Xmonad-Wayland | XMonad window-management policy for the River compositor | GitHub | — |
| Mirim | Embedded SQL database encrypted at rest by default | GitHub | Open |
| BTP | Berkeley Transport Protocol | Forgejo | Open |
| Evelin | Post-quantum secure transport protocol | Forgejo | Open |
| Zupt Web | Post-quantum backup directly in the browser | GitHub | Open |
| Zupt Android | Offline post-quantum encrypted file compression | Forgejo | — |
| SecurityOps Channel | Custom GNU Guix channel | GitHub | — |
| VaptVupt Linux | Userspace conformance and Linux kernel-integration tooling | GitHub | — |
| GuixVis | Interactive GNU Guix package and dependency explorer | GitHub | — |
NODE 02 // MERGED CONTRIBUTIONS
These are external repositories I contributed to — listed separately from my own projects and backed by merged pull requests.
cabelo/libzupt — cryptographic hardening, key handling and release engineering
SciPhi-AI/R2R — service and CLI robustness
zen-browser/desktop — build configuration and scripts
Ahwxorg/Binternet — safer output handling
emmabostian/developer-portfolios — community directory
NODE 03 // STACK AND PRINCIPLES
▸ toolchain
Systems: GNU/Linux · GNU Guix · Gentoo · FreeBSD
Languages: C · Rust · Scheme/Guile · Python · Shell · JavaScript
Operations: self-hosting · Forgejo · Docker · Tor · FFmpeg
Current orbit: reproducible systems, encrypted storage, compression, post-quantum migration and user-controlled infrastructure.
▸ operating principles
- Prefer evidence over security theatre.
- Make the source inspectable and the limits explicit.
- Keep infrastructure reproducible whenever practical.
- Design for user autonomy, not user lock-in.
- Learn in public and send useful fixes upstream.
cristiancezarmoises.com · sac@securityops.co
Website GitHub Forgejo Codeberg LinkedIn Email
if trust > evidence: inspect(source)
Security Ops® · free software · sovereign infrastructure






