Command Center
Sales-execution CRM for real-estate teams. Live and in daily use at a Dubai brokerage.
I'm Mohammed Jawed — senior DevSecOps & platform engineering leader with 18+ years in IT, including 12+ inside the UN system at the IAEA. At Mannat AI Labs I build open-source AI-security and platform tools that hold up under scrutiny.
The lab
Each product begins with a real problem in someone's life or work — self-hosted, explainable, with human oversight at the core. All run on the lab's own hardened production platform.
Sales-execution CRM for real-estate teams. Live and in daily use at a Dubai brokerage.
Multi-tenant publishing platform — every organization runs its own publication, with editorial workflow built in.
Multi-agent LLM validation framework with human-governed memory consolidation. Sole-authored Zenodo preprint, 2026.
Open-source AI red teaming — an autonomous operator attacks your AI system, adapts, and returns a reproducible security score.
Threat categorization from malware C2 communication. Peer-reviewed at ICISSP 2024, Rome — Best Position Paper Candidate.
Self-hosted GST billing for Indian SMBs — MIT licensed, Docker-ready, light enough to run on a Raspberry Pi.
Self-hosted email & notification delivery API — queue-backed, multi-tenant, an open-source alternative to SendGrid.
WireGuard-segmented multi-VPS, Gravitee API management, OpenBao secrets, ModSecurity WAF, and full Prometheus–Grafana–Loki observability.
Operating principles
Make software delivery from developer hands into production reliable, predictable, visible, secure, and largely automated — with well-understood, quantifiable risk.
Measure everything. Improve every aspect of the development ecosystem — especially time to detect, time to respond, and feedback delay. Automate repeatable steps.
Set standards for transparency and predictability. Communicate clearly. State intentions publicly — and be held to them.
Agility. Speed up the transition of ideas from the whiteboard, to the keyboard, to the live site, to the users.
Experience
International Atomic Energy Agency (IAEA)
Mannat AI Labs
CLSA · Saxo Bank · Hewlett-Packard · Aditi Technologies
Core competencies
The Agent Org
Mannat AI Labs ships like a full delivery organisation — because it runs one. Every role below is an AI agent: defined in code, scoped to its own tools, and held to hard gates. Review roles are read-only by design — they can block a release, but can never touch source.
Mohammed Jawed
Human · Founder
Delivery Lead & GTM Lead — runs the ceremony, enforces the gates, signs every release
// built on Claude Code subagents — each role is a version-controlled definition with its own model, tool scope, and mandate. One person, org-level throughput.
Research & writing
A paper without an artifact is a promise, not a contribution — every publication here ships with runnable code or a live system.
Zenodo preprint, June 2026 · Sole author · CC-BY-4.0
ICISSP 2024, Rome · Best Position Paper Candidate · with C3i Hub, IIT Kanpur
Master's thesis, Technische Universität Wien · Grade: Excellent
About the founder
18+ years in IT, including 12+ inside the UN Common System at the International Atomic Energy Agency in Vienna — leading DevSecOps and security operations for an organization that cannot afford to break. Recognised for building capabilities, not just operating tools: two custom in-house IAEA platforms, the organisation's DevOps culture and Continuous Improvement framework, and the IAEA Merit Award (2023).
Two cybersecurity-focused Master's degrees, both Pass with Distinction — TU Wien and IIT Kanpur. Published researcher: ICISSP 2024 (Best Position Paper Candidate) and a sole-authored Zenodo preprint on multi-agent LLM scoring (2026). Before Vienna: release engineering in global finance at CLSA and Saxo Bank.
Mannat AI Labs is my independent research lab. The name means sacred wish in Hindi and Urdu, and the lab takes it seriously: each product begins with a real problem in someone's life or work — open source first, self-hosted, with explainability and human oversight at the core.
Working together
Adversarial testing of LLM applications and agentic systems — prompt injection, data leakage, tool abuse — with a reproducible security score and a go/no-go verdict before you ship. The practice behind KavachRT.
Let's discussFrom near-zero to 100+ secure deployments a day: CI/CD with security scanning built in, Kubernetes and container hardening, secrets management, and full-stack observability — the playbook proven over 12 years in one of the world's most careful organisations.
Let's discussFractional or interim security engineering leadership: AI governance and human-oversight design, ISMS and Three Lines of Defence, engineering standards, and coaching teams to own security rather than outsource it.
Let's discussContact
Open to senior DevSecOps and AI-security roles, consulting engagements, and research collaboration — based in Vienna, working globally.