Skip to content
View arvid-berndtsson's full-sized avatar
😎
I force push to prod on fridays
😎
I force push to prod on fridays

Organizations

@merely-emissions @LimeTip

Block or report arvid-berndtsson

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
arvid-berndtsson/README.md

Hi, I'm Arvid 👋

I lead information security at Vertiseit and build security tools at LimeTip. My work includes governance, security investigations, and helping developers build safer software. I like digging into how systems work and writing tools I can use myself.

Website · Writing · Projects · LinkedIn

🔍 A quick intro

  • 🔐 Head of Information Security at Vertiseit, working on ISO 27001, SOC 2, TISAX readiness, and AI governance.
  • 🍋‍🟩 Founder of LimeTip. Currently building Tapid, an experimental JavaScript and TypeScript package manager written in Rust.
  • 📍 Based in Malmö, Sweden.

🔒 What I'm working on

  • Automating compliance tasks, reviewing vendor risks, and working on incident response.
  • Helping teams adopt secure development practices and understand the reasons behind them.
  • Working on package verification, script sandboxing, and release integrity in Tapid.
  • Building tools for Microsoft 365, Entra ID, and Azure administration.
  • Writing offensive security tools and experimenting with AI agents and MCP.

🏗 Selected projects

  • 📦 Tapid · Experimental JS/TS package manager with verified package storage and explicit script permissions. Website.
  • 🦀 redstr · String obfuscation and transformation for pentesting and testing security controls.
  • 🧼 typesecure · Classify sensitive data and enforce redaction policies before it reaches logs or telemetry.
  • 💤 lazyms · Terminal UI for querying Azure resources and managing Microsoft 365 security policies. Still in alpha.
  • 📋 compliance-simplified · Guides and quizzes for implementing ISO 27001 and SOC 2 controls. Website.
More projects and experiments
  • ♟️ Chess-MCP · Chess engine and game server for AI integrations through MCP.
  • 🔤 is-char · Tiny, dependency-free utility for checking a single JavaScript UTF-16 code unit.
  • 🧱 redstr-server · HTTP API for redstr transformations.
  • 🌐 domain-availability-checker · Cloudflare Worker for domain availability checks through RDAP.
  • 🤖 robots-txt-analyzer · Inspect robots.txt rules and potential security exposures.
  • 🧥 klumo · Experimental JS/TS runtime with LLM translation and self-healing.
  • 💻 terminal-portfolio · A portfolio website that looks like a terminal.

🛠 Tech I work with

Rust TypeScript Python Go PowerShell C#

Azure & Microsoft 365 · Cloudflare · Docker · GitHub Actions · React · .NET · MCP

→ More about my work and technical background

A few things about me
  • Started programming at 8.
  • I miss AppleScript and wish it had more use cases.
  • Sound modification through scripts is something I still can't grasp.

Pinned Loading

  1. robots-txt-analyzer robots-txt-analyzer Public

    Modern robots.txt analyzer with instant analysis, security recommendations, and export capabilities. Built with Qwik and deployed on Cloudflare Pages.

    TypeScript 3

  2. redstr redstr Public

    Red team string obfuscation and transformation for offensive security, WAF bypass, XSS, SQL injection, phishing, and evasion testing

    Rust 6

  3. domain-availability-checker domain-availability-checker Public

    A simple Cloudflare Worker that checks the availability of a list of domains, using Google RDAP.

    TypeScript 2

  4. Chess-MCP Chess-MCP Public

    Chess engine and game server for AI integrations through the Model Context Protocol.

    TypeScript 1

  5. compliance-simplified compliance-simplified Public

    Guides and quizzes for implementing ISO 27001 and SOC 2 controls.

    TypeScript 2

  6. typesecure typesecure Public

    Data classification, redaction, and runtime policies for handling secrets and personal data in TypeScript.

    TypeScript 1