Skip to content
LUIS_VESPA

SECURITY / 02

Security is architecture.

I design trust boundaries and protect application assets — from a PKI-authenticated mTLS channel to a medical device, to certificate-based signatures in a digital identity wallet.

SECURITY / 01

Where I work

Four areas, each solving a different part of the problem.

IDENTITY & AUTHENTICATION

Digidentity · Ypsomed
  • Certificate-based authentication
  • PKI and X.509 certificates
  • Digital signatures with certificates
  • Passwordless login (PLS)
  • Device binding
  • Identity verification and onboarding

NETWORK SECURITY

Ypsomed · Digidentity
  • mTLS with client certificates
  • Certificate pinning
  • Encrypted device-to-device channels
  • Secure API communication

CRYPTOGRAPHY & STORAGE

Digidentity · Ypsomed
  • Android Keystore
  • Key management
  • Signing and encryption
  • Secure secret handling

APPLICATION HARDENING

Digidentity
  • DexGuard obfuscation and hardening
  • R8 / ProGuard shrinking and obfuscation
  • Reverse-engineering resistance
  • Attack-surface reduction

SECURITY / 02

Trust architecture

Each layer of the client protects something different. Select one to see what it is for.

Android client · trust stack

mTLS. Both sides present certificates. The server knows which client is calling, not only that the channel is encrypted.

Request path

  1. ANDROID CLIENT
  2. certificate identityMTLS
  3. API GATEWAY
  4. trust establishedIDENTITY / PKI
  5. BACKEND APIS

Conceptual reference architecture — not a diagram of a specific employer’s system.

SECURITY / 03

Code obfuscation & application hardening

Hardening happens at build time, between the source and the signed release.
  1. Step 01

    Source

    Kotlin code, resources, dependencies

  2. Step 02

    R8

    Shrinking and name obfuscation

  3. Step 03

    DexGuard

    Obfuscation, string protection, hardening

  4. Step 04

    Signing

    Release key, integrity

  5. Step 05

    Release

    Distribution

Obfuscation is not security by itself. It is one layer of defense in depth.

R8 and DexGuard raise the cost of reverse engineering. They do not protect keys that should never have been in the APK, or an API that trusts any client. That is the job of the architecture: keys in the Android Keystore, identity through certificates, mTLS and pinning on the wire.

CONTACT / 08

LET’S BUILD SOMETHING DIFFICULT.

  • › Android platforms.
  • › Secure systems.
  • › Developer tooling.
  • › Agentic engineering.