Independent engineering lab & technical consultancy

Engineering without
artificial boundaries.

Practical engineering for complex systems - from low-level hardware interfaces and embedded firmware to networking, security architecture, automation, and secure application development. Shipped work you can read the source of.

FirmwareNetworkingSecurityAutomationSystems
v2.8.8 Latest Reaper release
6 Supported router models
78 Documented UI screens
Open Public repositories

01 / Capabilities

Across the stack.
Focused on outcomes.

Disciplines overlap in real systems. A firmware problem becomes a networking problem becomes a security problem. The work follows the problem wherever it leads.

01

Software Engineering

Windows applications, systems programming, privileged services, internal tooling, integrations, and engineering-focused utilities.

C / C++C# / .NETPython
02

Embedded & Firmware

Embedded Linux, router firmware, kernel and driver work, hardware interfaces, platform integration, and low-level debugging.

LinuxBroadcomDrivers
03

Network Engineering

Routing, wireless systems, traffic management and QoS, diagnostics, VPN technologies, DNS, and network segmentation.

RoutingWi-Fi 7VPN
04

Security Engineering

Attack-surface reduction, privilege separation, secure architecture, vulnerability analysis, hardening, and defensive tooling.

HardeningAnalysisArchitecture
05

Automation & QA

Test automation, validation frameworks, CI/CD workflows, audit logging, repeatable environments, and quality systems.

CI/CDTestingTooling
06

Systems Integration

Connecting software, hardware, networks, and operations into systems that are observable, maintainable, and resilient.

IntegrationReliabilityOps

02 / How to work together

Scoped engagements,
not open-ended retainers.

Most work starts as one of the following. Each has a defined scope, a written deliverable, and a clear finish line - so you know what you are buying before it starts.

03 / Selected work

Built to solve
real constraints.

Every project below exists because something needed to work differently. Where the source is public, it is linked - the code is part of the argument.

01 Open source Firmware / Networking ● Shipping

AM-Reaper

A security-hardened, de-clouded, open-source Asuswrt-Merlin firmware fork for six ASUS Wi-Fi 7 BE-series routers. Built around local control, network visibility, reduced attack surface, and keeping hardware acceleration in the data path instead of trading performance for control. Every public build is compiled in a GitHub Actions clean room - no secrets, no control servers, no telemetry.

  • RT-BE86U / BE88U / BE96U / GT-BE98 / GT-BE98 Pro + RT-BE92U (experimental)
  • Warden threat & geo firewall
  • Gatekeeper device approval
  • Object-based native firewall
  • Hardware-accelerated QoS
  • Public clean-room builds & provenance
The AM-Reaper administration dashboard showing system status, security posture and connected clients.
Reaper administration dashboard
02 Product QA / AI governance ● In development

QAAI Engine

A vendor-independent tool that makes QA test-case authoring faster and more accurate without requiring the author to intimately know the application under test. Works against any Jira + XRay deployment, pairing a browser extension with a governed AI proxy so organisations keep control of what leaves their perimeter.

  • Browser extension (Edge + Chrome)
  • Cloudflare Workers governance proxy
  • 14-point sanitizer enforced at each boundary
  • Signed, by-actor audit logging
  • Identity-gated access control
  • Built toward SOC 2 / ISO 27001 alignment
03 Systems R&D Windows / Hardware ● In development

Sensor Broker

A hardened Windows sensor broker that replaces the long-standing driver → daemon → HTTP → plugin chain used for hardware monitoring. Instead of handing clients arbitrary ring-0 access, the broker exposes a named, read-only sensor catalogue over an authenticated named pipe - so consumers never scan, never supply addresses, and never need administrator rights.

  • Named-pipe IPC with DACL enforcement
  • Peer-process identity + Authenticode signer pinning
  • Scoped capability tokens & rate limiting
  • Narrow-IOCTL, HVCI-compatible SMBus driver
  • Intel i801 + AMD FCH support
  • No client-side bus scanning, by design
04 Client delivery Web / Performance ● Delivered

Client Web Delivery

Static-first marketing sites built and deployed for small businesses - including a Florida construction contractor - with an emphasis on speed, crawlability, and long-term maintainability rather than a heavy CMS that rots in eighteen months.

  • Hand-built static delivery
  • Automated image pipelines
  • Recurring Lighthouse audits
  • Hardened headers & caching
  • Crawler- and agent-readable by design
05 Utility Windows / Security ● Internal

Register Broker

A focused Windows utility for controlled registry operations - designed around clear privilege boundaries, predictable behaviour, and auditability rather than convenience.

  • Privilege-separated architecture
  • Minimal, explicit interface
  • Defensive systems programming
Founder & principal engineer

04 / Who you are working with

I build systems
I'd be willing to defend.

I studied programming in college, then served in the military - which is where the habits that define this practice came from: verify before you trust it, follow the procedure, and never push something forward because it is convenient.

Engineering stayed a serious discipline rather than a job title for a long time, which meant the work was always driven by an actual problem rather than a sprint board. Unbounded Engineering is where that becomes a practice: firmware, networks, security, and the unglamorous systems work that holds the rest together.

What you get is a direct line to the person doing the work. No account manager, no handoff to a junior team, no discovery phase that bills for six weeks before anything is built. If something is a bad idea, I will say so before you pay for it.

Based
Florida, USA
Background
Military · Programming · Hardware · Troubleshooting
Practice
Solo, direct engagement
Source
Public where possible

05 / Engineering philosophy

The best solution respects the whole system.

Good engineering is not about applying a favourite technology. It is about understanding constraints, removing accidental complexity, and making choices that hold up under real conditions - including the condition where someone else has to maintain it.

  1. 01

    Understand before abstracting

    Start at the real boundary: hardware, protocol, process, or person.

  2. 02

    Prefer explicit systems

    Clear interfaces, observable behaviour, and failure modes that can be reasoned about.

  3. 03

    Design for the operator

    A system is only successful when people can deploy, diagnose, and maintain it.

  4. 04

    Earn complexity

    Use sophisticated tools when the problem requires them - not as decoration.

  5. 05

    Reduce what you expose

    Narrow interfaces, least privilege, and no capability granted without a reason.

06 / Open engineering

The work should
speak for itself.

Selected tools, experiments, and systems are developed in the open. Source code is both a deliverable and a record of engineering thought - including the parts that were harder than they looked.

Explore on GitHub
activity.log
$ git log --oneline --all fetching public activity… _

Reaper is free. The routers are not.

Every supported model has to be bought, flashed, bricked, and recovered on real hardware. If the firmware saved you time, you can help cover the bench.

Support the project

07 / Contact

Have a difficult engineering problem?

Tell me what you are building, what is not working, and what a practical path forward looks like. I read every message myself and will tell you honestly if it is not a good fit.

contact@unbounded-engineering.com github.com/TheUnboundDeveloper

Unbounded Engineering LLC · Florida, USA

This opens your own email app with the details filled in - nothing is sent from this page, and no third party ever sees it. Prefer to write it yourself? Use the address above.