Privileged access architecture
Design control-system patterns for servers, databases, and operational networks with minimal exposure and clear revocation paths.
Loophole, LLC
We help teams design, operate, and support secure access paths for infrastructure where accountability, visibility, and control matter.
The Name
A medieval loophole was a vertical slit in a defensive wall. From outside it looked like a thin opening, but inside it widened so defenders could operate with protection. Loophole carries that same idea into access engineering: expose only what is needed, keep operators effective, and reduce unnecessary exposure.
What We Do
Design control-system patterns for servers, databases, and operational networks with minimal exposure and clear revocation paths.
Build practical SAST, SCA, vulnerability management, and secure release workflows that engineers can actually sustain.
Investigate prompt manipulation, runtime context failures, and trust-boundary risks in modern LLM systems.
Experience
20+ years across application security, architecture, secure SDLC, vulnerability management, and regulated enterprise environments.
Hands-on work aligning systems with PCI DSS, HITRUST, NIST, and audit-driven security controls.
Creator of Bastillion, a web-based SSH access and key-management platform for centralized infrastructure administration.
CISSP-certified security practitioner with deep Java, cloud, Linux, IAM, and DevSecOps implementation experience.
Research
Secure Shell
A 2017 whitepaper proposing a centralized proxy for SSH administration — authentication, session review, and revocation layered onto protected infrastructure access. It's the model Bastillion was later built to implement.
Read the whitepaperAI Runtime Alignment
Public RACI research explores how reframing, social pressure, and recursive self-analysis can destabilize model behavior even when the underlying fact pattern is unchanged.
Supported Project
Loophole supports work around Bastillion, a source-available web-based SSH console used to help centralize shell access, manage credentials, and improve visibility into administrative sessions.
Every session is recorded automatically and can be replayed line by line — who ran what, on which host, and when. It's the privileged-access audit trail that PCI DSS, HIPAA, SOC 2, and NIST 800-53 all expect somewhere in scope, built in without a commercial PAM product.
The public project remains available and supported on GitHub.
Try It Yourself
Grab the latest release from GitHub — a single self-contained file, no build tooling or dependencies to wrangle.
Java 21 is the only prerequisite. One command starts an embedded server with HTTPS already configured out of the box.
Open the console in your browser and sign in with the default account. Free and unlicensed for up to 5 registered systems.
java -jar bastillion-<version>.jar
# open https://localhost:8443
# default login: admin / changeme
Product
AuxControl is a social music experiment for the aux cord: guests join a session, search for and queue tracks, vote together, and the top-voted track plays next.
Jukebox mode works without an account using song search and previews, while Spotify and Apple Music modes let a host connect their own service for full-track playback.
Visit AuxControlContact
For deployment, support, and security architecture conversations, contact Loophole through your established business channel or email the company inbox.
loophole.company