| hcrypt | Zero-dependency authenticated-encryption CLI & library — cascade/fortress AEAD (AES-256-GCM + ChaCha20-Poly1305), scrypt/Argon2id, keyfile 2FA, streaming file & directory encryption | Node.js |
| secret-scan | Zero-dependency CLI that scans code for leaked secrets (API keys, tokens, private keys, committed .env) — colorful terminal UI, pre-commit hook & remote GitHub-repo scanning | Node.js |
| envault | Zero-dependency encrypted .env vault — AES-256-GCM secrets at rest, injected into your app's environment at runtime, with plaintext never touching disk |
Node.js |
| totp | Zero-dependency CLI authenticator — RFC 6238 TOTP / RFC 4226 HOTP generation & constant-time verification, otpauth:// URIs |
Node.js |
| jwt-cli | Zero-dependency CLI to decode, inspect & verify JWTs — human-readable claims and security-focused HMAC verification that never trusts the token's own alg |
Node.js |
| tls-inspect | Zero-dependency CLI that inspects a host's TLS certificate & connection — expiry, chain, SANs, weak-protocol flags | Node.js |
| bcbp | Zero-dependency CLI that decodes airline boarding-pass barcodes (IATA BCBP) — passenger, PNR, route, flight, seat | Node.js |
| ohlcv-doctor | Zero-dependency CLI that health-checks OHLCV market-data for the bugs that ruin a backtest — gaps, duplicates, look-ahead, OHLC sanity | Node.js |
| Neko HQ | Terminal TUI that watches Claude Code sessions in a live pixel-art panel — one file, one command | Python |
| TraderWolfs | Indicator parameter sweeps & strategy-selection experiments | Jupyter |
| QuantDesk | Multi-strategy paper-trading platform — rule engine, event-driven backtest, risk dashboard, RBAC + audit log | FastAPI · Next.js |
| Troya Suite | IATA-based PSS electronic ticketing platform (event-sourced) | Kotlin · React |
| NewCrem | Multilingual (TR/EN/AR) CRM & ERP — pipeline, HR, inventory, invoicing, 2FA | Laravel · React |
| Akıcı | English-learning game with an FSRS spaced-repetition engine (local-first PWA) | Next.js · TS |
Linked projects are open source · the rest are private / under NDA.


