I find the abuse,prove it, and don'tbreak the legitimatecustomers doing it.
legitimateflagged ring
Six years turning messy data into clear, defensible enforcement
decisions — across cloud, fashion, automotive, and energy. Now at
AWS Payments & Fraud Prevention, building
LLM-powered investigation agents, detection systems, and the tooling
they run on. The hard part was never catching abuse. It's catching it
without punishing the people who weren't committing any.
Anyone can catch more abuse. The craft is the cost of catching it.
Move the detection threshold. Catching more abuse is easy — drag it up
and watch recall climb. The hard part is the second bar: every step too
far flags real customers. The job is living in the narrow band where one
is high and the other is near zero.
Hover a node to isolate its component; toggle to strip the legitimate population and leave only the rings. Representative shape — the live graph runs on confidential data.
Edges are hard shared signals weighted by excess-purity-over-base-rate × IDF; brokers are high-betweenness accounts bridging two rings.
Instance families the c-score regex governs6/7 covered
Family A
Family B
Family C
Family D
Family E
Family F
Newer familygap
Every governed family matched the threshold regex — except one newer family, which matched nothing and took the default zero-limit path straight past enforcement.
German-Jordanian, Berlin-based. I build the infrastructure, the
methodology, and the deliverables — and hold all three to a standard
where a caught assumption is the point, not an embarrassment.