SYSTEMS // SECURITY // OWNERSHIP

UNDERSTAND THE SYSTEM. PROTECT THE DATA.

Adrian Hernandez builds security-minded systems by asking what they do, why they work, and what happens when they fail. The goal is simple: keep information private, keep control with the owner, and understand every layer involved.

ACTIVE PROJECT INDEX

These projects grew out of curiosity, practical problems, and the need to keep learning. They are built to be useful and understandable, with information kept local whenever possible and every connection made for a reason.
EMBEDDED SECURITYACTIVE
01 // SENTINEL

Sentinel is an owner-controlled ESP32-C6 recovery device. It stores part of the information needed to restore encrypted data, protected by separate primary and recovery PINs that can never match. Recovery material remains on the device. Its dead-man check-in is the one exception: when the owner misses a defined check-in window, Sentinel connects long enough to send a chosen contact instructions for handling the recovery information.

LOCAL STORAGE // SEPARATE PINS // NETWORK ONLY FOR ALERT

ESP32-C6 · SECURE RECOVERY · OWNER CONTROL
WIRELESS OBSERVATIONCONCEPT
02 // WATCHER

Watcher is an ESP32-S3 concept for seeing what is happening on a wireless network without trying to control it. It focuses on passive observation—recognizing devices, traffic volume, destinations, protocols, and patterns—so network behavior is easier to see and understand.

PASSIVE OBSERVATION // NETWORK AWARENESS

ESP32-S3 · DEVICES · TRAFFIC · PROTOCOLS
CONVERSATIONAL DEVICECONCEPT
03 // AYVUM

AYVUM keeps conversational AI simple: press the button, ask a question, and hear the answer. Built around an ESP32-S3 and a minimal handheld interface, it avoids unnecessary menus and controls so the device is easy to understand from the first use.

PRESS TO ASK // DIRECT ANSWER // MINIMAL INTERFACE

ESP32-S3 · HANDHELD · CONVERSATIONAL AI
SYSTEMS LABORATORYONGOING
04 // INFRASTRUCTURE

The homelab is where the theory gets tested. Its seven network segments can communicate only when a service actually requires it. OPNsense manages routing and policy across Kali Linux, Ubuntu Server CLI, Windows 11, Windows Server, Tails, IoT devices, phones, and other peripherals. An ESP32-S3 provides the access point, while Cloudflare Tunnel carries public services without directly exposing the origin.

SEVEN SEGMENTS // POLICY-BASED ACCESS // PRIVATE ORIGIN

OPNsense · LINUX · WINDOWS · ESP32-S3

OPERATOR RECORD

IDENTITYPUBLIC
Adrian Hernandez
Adrian is a cybersecurity student who wants to know why something works, how it works, and—when it breaks—how to fix it.

His work and studies cross network infrastructure, systems administration, embedded security, encryption, and human-centered technical tools. What interests him most is how separate layers, keys, and recovery pieces fit together to protect information and make recovery possible. More layers are not automatically better; they matter only when each one is understood and used correctly.

He holds an associate degree in Technical Support and a bachelor’s degree in Network Systems Administration, and is currently pursuing a master’s degree in Cybersecurity and Information Assurance.
PUBLIC KEYPGP
PGP KEY // NOT YET PUBLISHED
A public key for verifying identity and sending encrypted messages will be published after the key, backup, and revocation certificate are created securely. The private key will never be part of this website.
KEY GENERATION PENDING
03 // RESTRICTED SYSTEM

PRIVATE COMMAND NODE

The operational dashboard is separate from the public edge. It is protected by its own access policy. There is no internal network addressing or topology exposed here.

ENTER COMMAND NODE