About

I'm Miha, a software engineer based in Slovenia. I've spent most of the last decade on backend systems and digital identity infrastructure, with a long run of embedded and hardware work alongside it, and now I bring that depth to AI engineering, building reliable, secure LLM systems.

My work runs from multi-tenant APIs to microcontrollers. On the software side: the access-control layer and audit trail of a multi-tenant platform in production, EU digital-identity wallets that passed EBSI Conformance Testing in full, and serverless security infrastructure on AWS. On the hardware side, embedded systems and environmental sensing — a GPS-GSM tracker deployed on around a hundred sea turtles for an EU conservation project, and a network of stations monitoring air and sea quality around a working port. A good share of it ran on blockchain rails, in Rust and Solidity; that's depth I still draw on rather than the headline.

The two sound unrelated, but the discipline is the same. A turtle surfaces for a couple of seconds at a time, so the device has to catch what it can and let the server do the thinking — and then keep doing that, unattended, for months on a sliver of power. A permission check has to hold every single time, because letting the wrong tenant through once is a breach rather than a bug. Both are about staying reliable when there's no second chance. That's the instinct I bring to AI: the interesting problem isn't getting a model to respond, it's making the system around it reliable, and keeping it from getting exploited.

That second half is deliberate. I'm a Certified AI Security Professional (CAISP), trained hands-on to attack and defend LLM systems: direct and indirect prompt injection, insecure tool use, model and supply-chain risks, and the threat modeling to catch them before they ship. These days it isn't theoretical — adversarial testing of LLM systems is part of my current work, and regulation is catching up fast, so findings increasingly have to hold up as evidence rather than just as a bug report. It's the same instinct as the reliability work: assume the thing will be attacked, and build so it holds anyway.

focus
LLM application engineering, with a reliability and security signature
stack
Python, TypeScript, Rust, AWS serverless, CrewAI / LiteLLM, RAG, adversarial testing
background
Backend, cloud, EU digital identity, embedded systems, blockchain (Ethereum, Solana), native iOS
certs
Certified AI Security Professional (CAISP), AWS Certified Cloud Practitioner
elsewhere
GitHub, LinkedIn