Ömer CoskunIT Services
Ömer Coskun

Ömer Coskun

Software developer and IT consultant, Eitorf, Germany

Taking on new projects

AI that knows your company.And who may see what.

I build assistants and knowledge search on your documents, with sources cited and permissions checked, running in your cloud or your data centre. From the first inquiry to the handover, you talk to the person who builds it.

  • About eleven years of software development
  • German, Turkish, English
  • Eitorf near Bonn, on site and remote

Fig. 1 · Three rules from AKAC, verbatim

Permission-aware RAG and GraphRAG:agents only work with knowledgethe user and the agent are bothallowed to see.

Checked before anything is searched: both the person and the agent need the right.

Protection of derived knowledge:summaries, memories and otheragent outputs stay protectedaccording to the sources theycame from.

A summary is as confidential as its sources.

Multi-agent and delegationcontrol:controlled handover betweenagents, tools and recipients.

Passed on only under control: between agents, too, it matters who may see what.

Decided outside the model, and every decision lands in a verifiable audit chain. Reference gateway with 359 passing tests on PostgreSQL and pgvector.github.com/oemer-coskun/AKAC

Evidence

  • Standard draft

    Author of AKAC, a draft industry standard for what AI agents may know, derive, store and pass on.

    AKAC on GitHub
  • Open source

    cite-or-decline backs every answer with file, page and line, or declines when the sources hold nothing.

    cite-or-decline on GitHub
  • Open source

    green-but-blind finds tests that pass without checking anything, and control characters that break code invisibly.

    green-but-blind on GitHub

Few subjects. Each one done properly.

Four focus areas, each with a project you can check it against.

Knowledge search and assistants

Assistants on your documents that back every answer with its source and decline when the sources hold nothing. Where a decision has consequences, a person approves it.

Backed by: cite-or-decline

Access control

An assistant must never show more than the person asking may see. Roles, attributes and tenants are checked by a fixed rule before any document is searched, not by the language model.

Backed by: AKAC

Runs in your environment

The system runs where your data lives: in your own cloud tenant, your data centre or on your own hardware. With controlled rollouts, health checks and measured latency, cost and quality.

Backed by: Enterprise runtime

Integration with your systems

Backends, interfaces and integrations with existing systems such as ERP and inventory management, with clear contracts between systems, tests and idempotent flows.

Backed by: B2B commerce

What I do not take on: marketing chatbots, image generators and strategy slides that never get built.

What I have built. And how it runs today.

Dated, with role and status. Industry instead of client name, figures only where they can be checked.

  1. since 09/2026AuthorAKAC: Agent Knowledge Access ControlA draft industry standard for what AI agents in a company may know, derive, store and pass on.More on this project
    Starting point
    Classic access control decides who may open a document. It does not decide what an agent may do with what it has read, or who may see what it produces from it: summaries, memories, handovers to other agents.
    Built
    Role and attribute based permissions on company knowledge, enforced by a fixed decision function outside the model. Permission-aware search with a pre-filter and a re-check of every candidate; derived summaries and agent memory inherit the classification of their sources and never become a source of authority themselves. With a per-tenant audit chain carrying verifiable Merkle proofs (RFC 9162), bounded delegation, DPoP and an AuthZEN-compatible interface.
    Status today
    Specification 0.4-draft, first published in September 2026, with four security classes from internal assistants to critical infrastructure. A TypeScript reference gateway with 359 passing tests on PostgreSQL 17 and pgvector with row-level security and OPA, and a conformance suite without cross-tenant leaks. The overview is public; customers and partners receive the specification, implementation and evidence on request.
    Stack
    TypeScript · PostgreSQL · pgvector · OPA · AuthZEN · DPoP · Docker · Helm

    AKAC on GitHub

  2. since 03/2026Co-founder and AI engineer, SiegFlow AISIP: an agentic enterprise platformA modular platform for autonomous B2B processes, set up without programming, with agents that act only within what they are allowed to do.More on this project
    Built
    Agents, permission-aware knowledge search, routing across several language models, persistent company knowledge and role-based access for staff. Every step follows the chain state, action, authority, execution, feedback: with agent identity, scopes, budgets, human approval, tenant isolation and an audit trail. Authorisation happens outside the language model, through fixed execution gates that fail closed. A REST and event architecture on FastAPI with versioned interface contracts, webhooks, idempotency and safe retries; working, episodic and long-term memory stay separate from the authority layer.
    Status today
    In development at SiegFlow AI, which I co-founded in March 2026 and where I am responsible for product, system and platform architecture.
    Stack
    Python · FastAPI · TypeScript · PostgreSQL · LangGraph · Docker · Kubernetes · Helm · SysML v2
  3. 05/2024 to 03/2026FreelanceEnterprise runtime for language modelsDistributed language model and agent workloads in the cloud and on Kubernetes, with model serving and observability.More on this project
    Built
    Workloads on AWS Bedrock, Azure, Docker, Kubernetes and Helm, with routing across several models, load balancing, autoscaling, health checks and controlled rollouts. GPU and memory isolation with NVIDIA MIG designed and validated, model serving with Triton. Observability for latency, throughput, GPU load, errors, cost per run and quality; with deployment verification, resource control and feedback from operations.
    Status today
    Completed in March 2026.
    Stack
    AWS Bedrock · Azure · Kubernetes · Helm · Docker · NVIDIA MIG · Triton · Langfuse · MLflow · OpenTelemetry
  4. 07/2023 to 05/2024Freelance, food wholesaleB2B commerce for a food wholesalerHeadless commerce with company and budget logic, real-time stock and a connection to the inventory system.More on this project
    Built
    A headless B2B commerce platform with dynamic product data, company and budget logic, real-time stock status and a connection to ERP and inventory management. REST interfaces, custom endpoints and webhooks for ordering, allocation and synchronisation; clear boundaries between systems, error handling and idempotent integrations.
    Status today
    Completed in May 2024.
    Stack
    Medusa · Node.js · TypeScript · PostgreSQL · REST · Webhooks
  5. 2026Open source, MIT licencecite-or-decline and green-but-blindA knowledge search that shows its sources or declines, and scanners for tests that are green and still check nothing.More on this project
    Starting point
    Knowledge search always answers, even when its sources hold nothing. And a test suite can be entirely green while single tests check nothing at all.
    Built
    cite-or-decline stores every passage with file, page and line range and backs every answer with them; a passage without provenance is never stored, and where the corpus holds no answer, the system declines. green-but-blind consists of four scanners; one breaks the code on purpose and checks that the responsible test goes red.
    Status today
    Both public and checkable. cite-or-decline runs without an API key, with 193 passing tests and 36 guards that are each removed on purpose to show that their test goes red.
    Stack
    Python · FastAPI · PostgreSQL · pgvector · static analysis · mutation testing

    cite-or-declinegreen-but-blind

  6. ResearchResearch and architecture projectLOGOS-1: memory, knowledge and evaluationWorking memory, episodic memory and long-term knowledge for AI systems, studied reproducibly.More on this project
    Built
    A research and evaluation infrastructure on provenance, retrieval and protected authority boundaries: with preregistered hypotheses, mutation testing, counterexample and repair cycles, measurable non-functional requirements and threat modelling at the boundaries between data, model and tools.
    Status today
    More than 4,000 automated tests, over 20 documented experiments and over 30 invariants.

Rules belong in front of the model. Not inside it.

You can ask a language model not to mention confidential content. You cannot rely on it.

So in my systems a fixed, verifiable rule decides which document a request can reach at all. When in doubt, it refuses. I have written the approach up as a draft standard: AKAC.

AKACIn depth: why permissions belong in front of the model

Fig. 2 · The path of a request, schematic

Diagram: a request from sales passes the identity check to a fixed rule. The rule allows searching price lists, product sheets and quotes, and blocks contracts, HR files, salaries and board documents. The answer names its source.

Example: a request from sales reaches 3 of 7 sources. The other 4 are never searched, not merely hidden.

Systems that maintain themselves. Nothing goes live without you.

I build systems so that they improve themselves, correct their own faults and are updated once a security flaw becomes known. None of it goes live without your approval.

Fig. 3 · A folded structure, held by one clamp

  1. Measure

    Health checks, telemetry and evaluation show at all times whether the system does what it should: latency, cost, errors and the quality of its answers.

  2. Correct

    When a measure drifts or a scan reports a security finding, a controlled correction starts. It passes tests and security gates; if anything fails, the system returns to its last good state.

  3. Stay current

    Dependencies and containers are checked continuously, with a software bill of materials (SBOM), container and secret scanning. Security updates are prepared and tested automatically.

  4. Approve

    Every change waits for your approval with traceable evidence: what changes, which checks passed, and how it is rolled back.

Prepared automatically, approved by you.

Permissions first. Then the code.

Every phase ends with something you hold in your hands.

PhaseDurationWhat you have afterwards
First call30 minutesAn honest view of whether and how it can be done.
Permissions and dataa few daysA written permission concept and a recommendation for the architecture.
Builda few weeksA running system, with the code in your repository.
OperationongoingMonitoring, updates and security fixes, every change approved by you.
Handoveras neededDocumentation, access, an introduction. You should not need me afterwards.

In the customer portal you see, for every working day, what I worked on.Go to the customer portal

One person to talk to. From design to operation.

I am Ömer Coskun, a freelance software developer and IT consultant based in Eitorf, North Rhine-Westphalia, Germany. I have worked on software for about eleven years, and for about four of them my focus has been AI platforms for companies: permission-aware knowledge search, access control outside the model and operation in your own environment.

I cover the whole way: requirements, architecture, build, security and operation. You always talk to me, with no agency in between.

Since March 2026 I am also a co-founder of SiegFlow AI, where I am responsible for the architecture of an agentic enterprise platform.

LinkedIn profile

Experience
About eleven years of software development, about four of them focused on AI systems
Languages
German and Turkish (native), English (C1)
Location
Eitorf, North Rhine-Westphalia, Germany
Work mode
On site and remote
Contract
Freelance, directly or through an intermediary
Availability

Taking on new projects

How we start. And how we bill.

Three ways in, depending on where your project stands.

  • Architecture review

    I review your plan or your existing system for permissions, data flows and operation. You receive a written recommendation.

  • Pilot with a permission concept

    One clearly bounded use case on your real data, with a written permission concept, in your environment.

  • Joining your team

    I join your running project and take on a clearly defined part: architecture, build or operation.

Terms

Day rate from €700

We agree the exact rate and the scope in writing beforehand.

Availability

Start agreed together

Response
Reply within one business day

LinkedIn profile

Do you place IT projects?Page for intermediaries

Before we start. Good to know.

Where does our data live?

Where you decide: in your cloud tenant, your data centre or on your own hardware. Which services are connected and where they run, we decide together before any data moves.

Do you work through intermediaries?

Yes, and directly as well. Intermediaries have their own page describing both ways: proposing a single project or becoming a partner.

Which models do you use?

The ones that fit your data, your requirements and your budget: models from your cloud, for example through AWS Bedrock or Azure, as well as self-hosted models. Routing across several models keeps you from being tied to one vendor.

Remote or on site?

Both. I am based in Eitorf, North Rhine-Westphalia, and come to you for workshops, alignment and acceptance; the ongoing work can be done remotely.

Can you join a project that is already running?

Yes. I work my way into existing code, past architecture decisions and your processes, and then take on a clearly defined part.

Who runs the system afterwards?

You, if you wish: you receive the code in your repository, documentation, access and an introduction. I can also keep running it, with monitoring, updates and security fixes that you approve.

What does it cost?

The day rate starts at €700. We agree the exact rate and the scope in writing beforehand.

How soon can you start?

We agree the start together. You will get a reply to an inquiry within one business day.

Your project. Our first conversation.

Briefly describe where you stand. You will get an honest assessment, even if it is that you do not need me.

Request a projectReply within one business day

Eitorf, North Rhine-Westphalia, Germany

Already a customer?
Go to the customer portal