Projects
Emergency and disaster evacuation software for enterprise and public administration clients. Real-time building evacuation management with multi-floor coordination.
Legal AI engine for Italian statutory and case law. Verified citations from primary sources with clickable references to original documents. Zero hallucination by design — reasoning, not generation. Free access, pay-per-use.
AI biomechanical analysis system for racehorses. Custom pose estimation pipeline with MS3 biomechanical correction microservice that transforms noisy cutaneous keypoints into real articular center data. Built from zero budget: custom dataset, 30h Kaggle GPU training, microservices on Hugging Face.
A zero-permission, minimal-surface Site-Specific Browser runtime designed to make client patching obsolete. No binary reverse engineering, no smali hooks, no runtime bytecode injection, and zero reliance on modded GmsCore or Play Services workarounds. No cat-and-mouse game chasing upstream breaking releases every week. All network filtering and ad-blocking are strictly delegated to the local AdGuard stack. Zero declared Android permissions, zero background daemons, no API spoofing, zero telemetry, and zero maintenance overhead. An architectural proof of concept for uncompromised, tamper-free mobile web playback.
SESSION1 — Cyber Security Department
Session1 is the Cyber Security Department of PS 1978 LIMITED. Independent vulnerability research, audit, and coordinated disclosure for software companies and technology organizations. Six published CVE identifiers in the MITRE/NVD database (2026), including the only critical-severity forever-day documented on a standalone consumer mobile application, and Top 100 in the Tencent Security Response Center Hall of Fame — the only independent European researcher in the ranking. Full findings and methodology on the department site.
Vendors receive private notification and a suggested fix prior to any public disclosure. All findings are timestamped via eIDAS-qualified blockchain deposits prior to vendor contact, establishing legally certified discovery priority. Vendors have 7 days from receipt of the security report and suggested remediation to act. No response, no merge, no CVE — immediate full disclosure. Where a vendor has a documented prior history of refusing to merge security fixes submitted by PS 1978 LIMITED, no remediation window is extended regardless of finding severity, vendor size, or jurisdiction.
PGP available on request