positioning
I build trust infrastructure where decentralized identity, encrypted storage, blockchain anchoring, cryptographic signatures, and regulatory compliance are not separate products but one composed system.
Most people in this space specialize in a single layer. My differentiator is the seam: making a verifiable credential, a national PKI signature, an on-chain anchor, a privacy-preserving disclosure, and a data-protection requirement work as one coherent flow that a regulator, a CTO, and an end user can each trust for their own reasons. I design the architecture, write the code, engage the regulator, and shape the model that makes it sustainable.
capabilities
Decentralized identity & VCs
Full lifecycle: DID method selection and authoring, issuance, holder wallets, presentation, verification, and graded assurance. W3C DID/VC, OpenID4VC, ISO 18013-5 (mDL), eIDAS 2.0 / EUDI.
Cryptography, PKI & signatures
Applied crypto and national PKI integration, bridging classical X.509 into the DID world. PAdES verification, point-in-time authority, Ed25519, Shamir recovery.
Decentralized storage & vaults
Encrypted personal stores plus peer-replicated durability under an anchor-not-store discipline. Recovery separated from custody so it never becomes impersonation.
Blockchain anchoring
Public chains as neutral timestamping and tamper-evidence, deliberately token-free and securities-aware, with users never holding chain keys.
Privacy engineering
Privacy as an architectural property: zero-correlation via pairwise identifiers, data minimization, selective disclosure, consent receipts.
Compliance & legal-technical
Mapping a feature to its legal basis and its security and privacy obligations in one register a regulator and a CTO can both read. SOC 2, NIST CSF, CIS v8, data-protection regimes.
The spine is systems integration: owning the contracts between identity, storage, crypto, chain, privacy, and law so the composed system holds. That is the reason to hire me over a set of specialists.
things few people can do
- Reconcile unlinkable-by-default identity with legally-attributable-on-demand signatures in one architecture.
- Anchor to a public chain while staying compatible with a legal right to deletion.
- Bridge a national X.509 PKI into a DID / VC verification flow.
- Author a DID method specification and take it through a standards process.
- Produce one feature-by-feature register that satisfies a technical reviewer, a privacy officer, and a regulator at once.
- Design a token-free blockchain trust layer that survives securities scrutiny.
- Separate recovery from custody so recoverability never creates an impersonation path.
selected work
Attestto
Decentralized identity and trust infrastructure for institutions and citizens: per-site pairwise sign-in, verifiable-credential issuance, verification of Costa Rica's national digital signatures (PAdES), blockchain anchoring, and encrypted vaults. Two DID method specifications authored (did:sns, did:pki) and a live did:pki resolver bridging national PKI into DID-based verification. Designed against Costa Rica's Ley 8454 (digital signature) and Ley 8968 (data protection); security program targeting SOC 2 with NIST CSF controls in operation.
earlier experience
Fifteen-plus years at the intersection of engineering and business across financial services and government, before founding Attestto.
-
AccentureDigital platform lead · BBVA Americas (CO, AR, CL, MX, US)2020
-
Hangar WorldwideTech lead · Citibank, government services APIs2013 – 2019
-
SourceTraceSoftware architect · banking & mobile POS2011 – 2012
-
Sigma One / US Department of StateWeb developer & team lead · CAFTA-DR, on-site Washington DC2009 – 2011
-
Hewlett-PackardSupport engineer · enterprise servers & archiving2006 – 2010