Skip to content

Security architect & indie developer · Germany

By day I’m a cyber security architect. In my own time I build small web apps and browser extensions for developers, founders and hobbyists, kept simple and secure from the first line.

JP

I'm a cyber security architect from Germany. My day job is designing systems that stay safe when things go wrong. On the side, I build my own products and like to own the whole thing: research, product, design, code, tests and the deploy button.

Most of what I build starts with a small annoyance: forty open tabs (TabTTL), a singing app that wants a subscription before you've sung one note (Singler), brands and creators who don't trust each other's screenshots (Promotler) store screenshots that take an afternoon in Figma (Storeshot) and a cabinet that has to fit a 30 cm gap (Nischler). I write the plan down, cut it to the smallest useful version and ship it.

A few principles show up in every project:

  • Security first: it's my day job, so for me it's something of an occupational hazard. Threat model before features, least privilege everywhere, secrets never in the client.
  • Your data stays with you: audio, images and browsing habits are processed on your device whenever possible. If a tool gets cloud sync, it uploads only what's necessary, and only when that actually helps you.
  • Simple architecture: static sites and edge functions, Postgres where state matters, running costs close to zero.
  • Tests where it hurts: money, merges and permissions get property tests and database tests, and the unhappy paths get tested too.
  • Words matter: clear copy and good defaults beat another settings toggle.

Tools I reach for

  • SvelteKit
  • Svelte 5
  • TypeScript
  • Tailwind CSS
  • Postgres
  • Supabase
  • Cloudflare Workers
  • Web Audio
  • Canvas 2D
  • WebExtensions
  • Playwright
  • Vitest
  • Stripe Connect
  • i18n

Say hello