
Ömer Coskun
Software developer and IT consultant, Eitorf, Germany
Taking on new projects
AI that knows your company.And who may see what.
I build assistants and knowledge search on your documents, with sources cited and permissions checked, running in your cloud or your data centre. From the first inquiry to the handover, you talk to the person who builds it.
- About eleven years of software development
- German, Turkish, English
- Eitorf near Bonn, on site and remote
Fig. 1 · Three rules from AKAC, verbatim
Checked before anything is searched: both the person and the agent need the right.
A summary is as confidential as its sources.
Passed on only under control: between agents, too, it matters who may see what.
Evidence
- Standard draft
Author of AKAC, a draft industry standard for what AI agents may know, derive, store and pass on.
AKAC on GitHub - Open source
cite-or-decline backs every answer with file, page and line, or declines when the sources hold nothing.
cite-or-decline on GitHub - Open source
green-but-blind finds tests that pass without checking anything, and control characters that break code invisibly.
green-but-blind on GitHub
Few subjects. Each one done properly.
Four focus areas, each with a project you can check it against.
Knowledge search and assistants
Assistants on your documents that back every answer with its source and decline when the sources hold nothing. Where a decision has consequences, a person approves it.
Backed by: cite-or-decline
Access control
An assistant must never show more than the person asking may see. Roles, attributes and tenants are checked by a fixed rule before any document is searched, not by the language model.
Backed by: AKAC
Runs in your environment
The system runs where your data lives: in your own cloud tenant, your data centre or on your own hardware. With controlled rollouts, health checks and measured latency, cost and quality.
Backed by: Enterprise runtime
Integration with your systems
Backends, interfaces and integrations with existing systems such as ERP and inventory management, with clear contracts between systems, tests and idempotent flows.
Backed by: B2B commerce
What I do not take on: marketing chatbots, image generators and strategy slides that never get built.
What I have built. And how it runs today.
Dated, with role and status. Industry instead of client name, figures only where they can be checked.
since 09/2026AuthorAKAC: Agent Knowledge Access ControlA draft industry standard for what AI agents in a company may know, derive, store and pass on.More on this project
- Starting point
- Classic access control decides who may open a document. It does not decide what an agent may do with what it has read, or who may see what it produces from it: summaries, memories, handovers to other agents.
- Built
- Role and attribute based permissions on company knowledge, enforced by a fixed decision function outside the model. Permission-aware search with a pre-filter and a re-check of every candidate; derived summaries and agent memory inherit the classification of their sources and never become a source of authority themselves. With a per-tenant audit chain carrying verifiable Merkle proofs (RFC 9162), bounded delegation, DPoP and an AuthZEN-compatible interface.
- Status today
- Specification 0.4-draft, first published in September 2026, with four security classes from internal assistants to critical infrastructure. A TypeScript reference gateway with 359 passing tests on PostgreSQL 17 and pgvector with row-level security and OPA, and a conformance suite without cross-tenant leaks. The overview is public; customers and partners receive the specification, implementation and evidence on request.
- Stack
- TypeScript · PostgreSQL · pgvector · OPA · AuthZEN · DPoP · Docker · Helm
since 03/2026Co-founder and AI engineer, SiegFlow AISIP: an agentic enterprise platformA modular platform for autonomous B2B processes, set up without programming, with agents that act only within what they are allowed to do.More on this project
- Built
- Agents, permission-aware knowledge search, routing across several language models, persistent company knowledge and role-based access for staff. Every step follows the chain state, action, authority, execution, feedback: with agent identity, scopes, budgets, human approval, tenant isolation and an audit trail. Authorisation happens outside the language model, through fixed execution gates that fail closed. A REST and event architecture on FastAPI with versioned interface contracts, webhooks, idempotency and safe retries; working, episodic and long-term memory stay separate from the authority layer.
- Status today
- In development at SiegFlow AI, which I co-founded in March 2026 and where I am responsible for product, system and platform architecture.
- Stack
- Python · FastAPI · TypeScript · PostgreSQL · LangGraph · Docker · Kubernetes · Helm · SysML v2
05/2024 to 03/2026FreelanceEnterprise runtime for language modelsDistributed language model and agent workloads in the cloud and on Kubernetes, with model serving and observability.More on this project
- Built
- Workloads on AWS Bedrock, Azure, Docker, Kubernetes and Helm, with routing across several models, load balancing, autoscaling, health checks and controlled rollouts. GPU and memory isolation with NVIDIA MIG designed and validated, model serving with Triton. Observability for latency, throughput, GPU load, errors, cost per run and quality; with deployment verification, resource control and feedback from operations.
- Status today
- Completed in March 2026.
- Stack
- AWS Bedrock · Azure · Kubernetes · Helm · Docker · NVIDIA MIG · Triton · Langfuse · MLflow · OpenTelemetry
07/2023 to 05/2024Freelance, food wholesaleB2B commerce for a food wholesalerHeadless commerce with company and budget logic, real-time stock and a connection to the inventory system.More on this project
- Built
- A headless B2B commerce platform with dynamic product data, company and budget logic, real-time stock status and a connection to ERP and inventory management. REST interfaces, custom endpoints and webhooks for ordering, allocation and synchronisation; clear boundaries between systems, error handling and idempotent integrations.
- Status today
- Completed in May 2024.
- Stack
- Medusa · Node.js · TypeScript · PostgreSQL · REST · Webhooks
2026Open source, MIT licencecite-or-decline and green-but-blindA knowledge search that shows its sources or declines, and scanners for tests that are green and still check nothing.More on this project
- Starting point
- Knowledge search always answers, even when its sources hold nothing. And a test suite can be entirely green while single tests check nothing at all.
- Built
- cite-or-decline stores every passage with file, page and line range and backs every answer with them; a passage without provenance is never stored, and where the corpus holds no answer, the system declines. green-but-blind consists of four scanners; one breaks the code on purpose and checks that the responsible test goes red.
- Status today
- Both public and checkable. cite-or-decline runs without an API key, with 193 passing tests and 36 guards that are each removed on purpose to show that their test goes red.
- Stack
- Python · FastAPI · PostgreSQL · pgvector · static analysis · mutation testing
ResearchResearch and architecture projectLOGOS-1: memory, knowledge and evaluationWorking memory, episodic memory and long-term knowledge for AI systems, studied reproducibly.More on this project
- Built
- A research and evaluation infrastructure on provenance, retrieval and protected authority boundaries: with preregistered hypotheses, mutation testing, counterexample and repair cycles, measurable non-functional requirements and threat modelling at the boundaries between data, model and tools.
- Status today
- More than 4,000 automated tests, over 20 documented experiments and over 30 invariants.
Rules belong in front of the model. Not inside it.
You can ask a language model not to mention confidential content. You cannot rely on it.
So in my systems a fixed, verifiable rule decides which document a request can reach at all. When in doubt, it refuses. I have written the approach up as a draft standard: AKAC.
Fig. 2 · The path of a request, schematic
Diagram: a request from sales passes the identity check to a fixed rule. The rule allows searching price lists, product sheets and quotes, and blocks contracts, HR files, salaries and board documents. The answer names its source.
Systems that maintain themselves. Nothing goes live without you.
I build systems so that they improve themselves, correct their own faults and are updated once a security flaw becomes known. None of it goes live without your approval.
Fig. 3 · A folded structure, held by one clamp


Measure
Health checks, telemetry and evaluation show at all times whether the system does what it should: latency, cost, errors and the quality of its answers.
Correct
When a measure drifts or a scan reports a security finding, a controlled correction starts. It passes tests and security gates; if anything fails, the system returns to its last good state.
Stay current
Dependencies and containers are checked continuously, with a software bill of materials (SBOM), container and secret scanning. Security updates are prepared and tested automatically.
Approve
Every change waits for your approval with traceable evidence: what changes, which checks passed, and how it is rolled back.
Prepared automatically, approved by you.
Permissions first. Then the code.
Every phase ends with something you hold in your hands.
| Phase | Duration | What you have afterwards |
|---|---|---|
| First call | 30 minutes | An honest view of whether and how it can be done. |
| Permissions and data | a few days | A written permission concept and a recommendation for the architecture. |
| Build | a few weeks | A running system, with the code in your repository. |
| Operation | ongoing | Monitoring, updates and security fixes, every change approved by you. |
| Handover | as needed | Documentation, access, an introduction. You should not need me afterwards. |
In the customer portal you see, for every working day, what I worked on.Go to the customer portal
One person to talk to. From design to operation.
I am Ömer Coskun, a freelance software developer and IT consultant based in Eitorf, North Rhine-Westphalia, Germany. I have worked on software for about eleven years, and for about four of them my focus has been AI platforms for companies: permission-aware knowledge search, access control outside the model and operation in your own environment.
I cover the whole way: requirements, architecture, build, security and operation. You always talk to me, with no agency in between.
Since March 2026 I am also a co-founder of SiegFlow AI, where I am responsible for the architecture of an agentic enterprise platform.
- Experience
- About eleven years of software development, about four of them focused on AI systems
- Languages
- German and Turkish (native), English (C1)
- Location
- Eitorf, North Rhine-Westphalia, Germany
- Work mode
- On site and remote
- Contract
- Freelance, directly or through an intermediary
- Availability
Taking on new projects
How we start. And how we bill.
Three ways in, depending on where your project stands.
Architecture review
I review your plan or your existing system for permissions, data flows and operation. You receive a written recommendation.
Pilot with a permission concept
One clearly bounded use case on your real data, with a written permission concept, in your environment.
Joining your team
I join your running project and take on a clearly defined part: architecture, build or operation.
Terms
Day rate from €700
We agree the exact rate and the scope in writing beforehand.
- Availability
Start agreed together
- Response
- Reply within one business day
Do you place IT projects?Page for intermediaries
Before we start. Good to know.
Where does our data live?
Where you decide: in your cloud tenant, your data centre or on your own hardware. Which services are connected and where they run, we decide together before any data moves.
Do you work through intermediaries?
Yes, and directly as well. Intermediaries have their own page describing both ways: proposing a single project or becoming a partner.
Which models do you use?
The ones that fit your data, your requirements and your budget: models from your cloud, for example through AWS Bedrock or Azure, as well as self-hosted models. Routing across several models keeps you from being tied to one vendor.
Remote or on site?
Both. I am based in Eitorf, North Rhine-Westphalia, and come to you for workshops, alignment and acceptance; the ongoing work can be done remotely.
Can you join a project that is already running?
Yes. I work my way into existing code, past architecture decisions and your processes, and then take on a clearly defined part.
Who runs the system afterwards?
You, if you wish: you receive the code in your repository, documentation, access and an introduction. I can also keep running it, with monitoring, updates and security fixes that you approve.
What does it cost?
The day rate starts at €700. We agree the exact rate and the scope in writing beforehand.
How soon can you start?
We agree the start together. You will get a reply to an inquiry within one business day.
Your project. Our first conversation.
Briefly describe where you stand. You will get an honest assessment, even if it is that you do not need me.
Eitorf, North Rhine-Westphalia, Germany
- Or write to
- mail@oemer-coskun.de
- Already a customer?
- Go to the customer portal