ForewordPreface

Curriculum Vitae

Contents
Biography
Positions
Selected work
Systems built
Competencies
Publications and findings
Contact

A typeset copy of this page is served as a PDF (September 2026). The page is the canonical version.

Biography

Ryan James York was born in Makiki, Honolulu, Hawaiʻi, in 1995. He is a security engineer and the founder of SSX360 Corp., where he builds cryptographic provenance and independent audit tooling for AI-agent payment systems, and leads authorized security assessments and vulnerability research across the logistics, finance, and climate domains. His hands-on work spans post-quantum signatures (FIPS 204 ML-DSA and FIPS 205 SLH-DSA), hardware signing devices, adversarial evaluation of machine-learning models, and hardened container infrastructure. He built a control plane that governs and audits what development teams ship, with software and hardware mapped ahead of multiple compliance layers.

Positions

PeriodPosition
2024 – presentFounder & Chief Executive Officer, SSX360 Corp. (Delaware; Honolulu, Hawaiʻi)
2019 – 2024Chief Real Estate Officer, CPY Partners; opened and ran the firm's research and development wing, a quantitative investment team drawn from MIT and Northeastern University

Selected work

Designed the full system architecture for AP2 agent-payment policy enforcement: mandate chain verification, cryptographic audit trails, and hardware-signed approvals. Flashed, penetration-tested, and patented an encrypted internal hardware signing device built on an NFC/SE050 secure element. Implemented post-quantum signature support targeting FIPS 204 ML-DSA and FIPS 205 SLH-DSA alongside Ed25519. Fine-tuned internal machine-learning prediction models for production use across finance, logistics, and climate workloads. Authored MCV-1, an open and versioned set of criteria for machine-verifiable evidence (§2.6), and the Matrix Scroll provenance protocol (Software). Leads the 2D carbon thin-film programme described in Chapter 3.

Systems built

Encrypted Team Workspace. Zero-knowledge Kanban, chat, and file sharing. The server stores only ciphertext; client-side libsodium encryption with Argon2id key derivation, 1 MiB secretstream chunks with reorder and truncation detection, and single-use invites bound to keyed BLAKE2b digests.

ZERO_G. Hardware security appliances for regulated work: AES-256 at rest, air-gapped USB workflows, on-device semantic search, and tamper-evident audit logs. The Electron boundary is hardened by treating the renderer as untrusted. Configurations aligned to CMMC, HIPAA, and SOC 2 use cases.

LAMBDA_ANGELS. MCP safety gate for autonomous coding agents. Converts natural-language goals into DAG plans and blocks unsafe dispatches before any model token is spent; enforces repository policies on paths, egress, and execution limits. 209 unit tests, property-based fuzzing, Pyright strict at zero errors.

CRUCIBLE. CI-ready adversarial evaluation harness for tabular machine-learning models. Runs YAML-defined attack cards in Docker workers with no network access, emits schema-validated JSON reports, and gates GitHub Actions releases on regression diffs.

RECON_MCP. OSINT and threat-intelligence MCP server: twenty tools across GitHub, arXiv, SEC EDGAR, USPTO, and a local vector corpus, with per-source rate limiting.

Matrix Scroll. Open-source provenance protocol (Apache-2.0, PyPI): commit-time Ed25519 signing, a trust scanner for MCP servers that reached the top of Show HN on release, and continuous-integration gating (Scroll Gate).

Research platform. The cryptographically provenanced modelling and verification environment described in Finding 2026.4: append-only Ed25519 ledger, instrument-signed journals, release gates, and a compiled preprint.

Competencies

AreaDetail
Post-quantum and applied cryptographyFIPS 204 ML-DSA, FIPS 205 SLH-DSA, Ed25519, AES-256, libsodium, Argon2id, end-to-end encryption, tamper-evident audit logs, hardware secure elements (NFC/SE050)
Security engineeringThreat modelling (STRIDE), secure SDLC, application security, secure code review, SAST/DAST, supply-chain security, secrets management, CI security gates
AI and agent securityAdversarial ML evaluation, red-team harnesses, policy-as-code, MCP server security, autonomous-agent safety gates, AP2 payment policy enforcement
Infrastructure securityDocker isolation and egress control, air-gapped workflows, Linux hardening, IAM, structured audit logging
Intelligence and OSINTGitHub, arXiv, Semantic Scholar, SEC EDGAR, USPTO, Hugging Face, vector-corpus search, rate-limited collection, incident-response readiness
Compliance and governanceNIST SP 800-171, CMMC, HIPAA, SOC 2, FIPS 140-3 awareness, audit-evidence workflows
Materials characterisationRaman spectroscopy of sp² carbon, Ferrari–Robertson analysis, synthetic-corpus benchmarking of inversion pipelines (Chapter 3)

Publications and findings

Findings are listed under Findings and preprints under Publications. Citation forms are given under Citing.

Contact

mission@ssx360.com · ORCID iD 0009-0007-5979-7949 · LinkedIn · ssx360.com