Curriculum Vitae
| Biography | |
| Positions | |
| Selected work | |
| Systems built | |
| Competencies | |
| Publications and findings | |
| Contact |
A typeset copy of this page is served as a PDF (September 2026). The page is the canonical version.
Biography
Ryan James York was born in Makiki, Honolulu, Hawaiʻi, in 1995. He is a security engineer and the founder of SSX360 Corp., where he builds cryptographic provenance and independent audit tooling for AI-agent payment systems, and leads authorized security assessments and vulnerability research across the logistics, finance, and climate domains. His hands-on work spans post-quantum signatures (FIPS 204 ML-DSA and FIPS 205 SLH-DSA), hardware signing devices, adversarial evaluation of machine-learning models, and hardened container infrastructure. He built a control plane that governs and audits what development teams ship, with software and hardware mapped ahead of multiple compliance layers.
Positions
| Period | Position |
|---|---|
| 2024 – present | Founder & Chief Executive Officer, SSX360 Corp. (Delaware; Honolulu, Hawaiʻi) |
| 2019 – 2024 | Chief Real Estate Officer, CPY Partners; opened and ran the firm's research and development wing, a quantitative investment team drawn from MIT and Northeastern University |
Selected work
Designed the full system architecture for AP2 agent-payment policy enforcement: mandate chain verification, cryptographic audit trails, and hardware-signed approvals. Flashed, penetration-tested, and patented an encrypted internal hardware signing device built on an NFC/SE050 secure element. Implemented post-quantum signature support targeting FIPS 204 ML-DSA and FIPS 205 SLH-DSA alongside Ed25519. Fine-tuned internal machine-learning prediction models for production use across finance, logistics, and climate workloads. Authored MCV-1, an open and versioned set of criteria for machine-verifiable evidence (§2.6), and the Matrix Scroll provenance protocol (Software). Leads the 2D carbon thin-film programme described in Chapter 3.
Systems built
Encrypted Team Workspace. Zero-knowledge Kanban, chat, and file sharing. The server stores only ciphertext; client-side libsodium encryption with Argon2id key derivation, 1 MiB secretstream chunks with reorder and truncation detection, and single-use invites bound to keyed BLAKE2b digests.
ZERO_G. Hardware security appliances for regulated work: AES-256 at rest, air-gapped USB workflows, on-device semantic search, and tamper-evident audit logs. The Electron boundary is hardened by treating the renderer as untrusted. Configurations aligned to CMMC, HIPAA, and SOC 2 use cases.
LAMBDA_ANGELS. MCP safety gate for autonomous coding agents. Converts natural-language goals into DAG plans and blocks unsafe dispatches before any model token is spent; enforces repository policies on paths, egress, and execution limits. 209 unit tests, property-based fuzzing, Pyright strict at zero errors.
CRUCIBLE. CI-ready adversarial evaluation harness for tabular machine-learning models. Runs YAML-defined attack cards in Docker workers with no network access, emits schema-validated JSON reports, and gates GitHub Actions releases on regression diffs.
RECON_MCP. OSINT and threat-intelligence MCP server: twenty tools across GitHub, arXiv, SEC EDGAR, USPTO, and a local vector corpus, with per-source rate limiting.
Matrix Scroll. Open-source provenance protocol (Apache-2.0, PyPI): commit-time Ed25519 signing, a trust scanner for MCP servers that reached the top of Show HN on release, and continuous-integration gating (Scroll Gate).
Research platform. The cryptographically provenanced modelling and verification environment described in Finding 2026.4: append-only Ed25519 ledger, instrument-signed journals, release gates, and a compiled preprint.
Competencies
| Area | Detail |
|---|---|
| Post-quantum and applied cryptography | FIPS 204 ML-DSA, FIPS 205 SLH-DSA, Ed25519, AES-256, libsodium, Argon2id, end-to-end encryption, tamper-evident audit logs, hardware secure elements (NFC/SE050) |
| Security engineering | Threat modelling (STRIDE), secure SDLC, application security, secure code review, SAST/DAST, supply-chain security, secrets management, CI security gates |
| AI and agent security | Adversarial ML evaluation, red-team harnesses, policy-as-code, MCP server security, autonomous-agent safety gates, AP2 payment policy enforcement |
| Infrastructure security | Docker isolation and egress control, air-gapped workflows, Linux hardening, IAM, structured audit logging |
| Intelligence and OSINT | GitHub, arXiv, Semantic Scholar, SEC EDGAR, USPTO, Hugging Face, vector-corpus search, rate-limited collection, incident-response readiness |
| Compliance and governance | NIST SP 800-171, CMMC, HIPAA, SOC 2, FIPS 140-3 awareness, audit-evidence workflows |
| Materials characterisation | Raman spectroscopy of sp² carbon, Ferrari–Robertson analysis, synthetic-corpus benchmarking of inversion pipelines (Chapter 3) |
Publications and findings
Findings are listed under Findings and preprints under Publications. Citation forms are given under Citing.
Contact
mission@ssx360.com · ORCID iD 0009-0007-5979-7949 · LinkedIn · ssx360.com