skip to content
Mohamed Azahrioui
Mohamed Azahrioui

Mohamed Azahrioui

backend developer, the hague

I build backends and guardrails for AI agents. Now I’m going a layer down: C++ and Linux.

I’m a backend developer in The Hague. I study computer science at Leiden and write production code for real clients at the same time. What I care about is correctness: code that stops when something is wrong instead of guessing, and that keeps a record you can check. The C++ and Linux work is that same question one level down: I’d rather measure what a guarantee costs than assume it’s free.

receiptsthe hague, nl

shipped

fetchgate
v0.2.0 on PyPI · 45 tests, no network, no model · verify
production
CodeHive · Kojac · freelance clients

prototypes · built at hackathons

reachgate
422 tests · OpenVEX / SARIF exports, sha256 manifest · repo
trustgate
runtime authorization on Google Cloud · Vertex / BigQuery · demo
available
summer 2027 internship · penultimate-year, BSc expected 2028

guardrails

Three times now I’ve built roughly the same thing. Each one sits in front of a spot where an AI system would otherwise guess, and puts a fixed rule in charge: the rules decide, the model just explains the decision, and you get output you can check instead of trust. I didn’t plan to specialise in this. It just kept being the problem in front of me.

hackathon prototype · gitlab transcend 2026REACHABLE / UNKNOWN / NOT-AFFECTED

A scanner tells you a vulnerable function exists somewhere in your dependencies. It doesn't tell you whether your own code can ever reach it. Published industry analysis puts roughly four in five 'critical' findings out of reach of the app that ships them, but that's an industry number, not a verdict about your repo. ReachGate walks the code graph to check whether a path actually exists. If it runs out of budget before it can be sure, it returns UNKNOWN rather than marking something safe it never proved. Every result exports as OpenVEX and SARIF with an sha256 manifest, so you can re-check it offline.

two public merge requests in GitLab's own namespace, pipelines and both verdicts visible · open on gitlab

read the case →

open source · published on pypiRETRIEVED / FAILED / UNKNOWN

This is the one I put on PyPI. It sits where an agent fetches a web page and checks whether the page was actually read, or whether the request just came back with a 200. A 200 only means bytes arrived, not that you got the page. If it can't confirm a real read, it stops the agent instead of letting it answer anyway. No model, no API keys. One test in the suite deliberately tries to slip a fake read past it, and fails.

45 tests, no network, no model · verify on pypi

read the case →

hackathon prototype · google cloud rapid agentALLOW / APPROVAL_REQUIRED / BLOCK

Before an agent does something costly, like issuing a refund, TrustGate looks at the data behind the decision: is it fresh, does it still match the contract it was written against, is the source even connected? An agent can be allowed to act and still be acting on bad data. It returns allow, approval-required, or block, with the evidence attached.

recorded walkthrough, Cloud Run with BigQuery evidence checks · watch

read the case →

in production, under nda

Client work I can describe but not link. Same habit, applied where the cost of being wrong is somebody’s money, tax filing or medical record.

in production at a client · source under nda

A crash-safe 'Confirm and send to Exact' flow that books issued material lines from a client's stock and project tool into the Exact / Bouw7 ERP. Idempotent and resumable, so a retry after a partial failure never double-books a line.

in production · source under nda

Safety-critical feature work on a Dutch medical AI scribe that turns a consult recording into a structured clinical note. My work targets the places where a plausible-looking error could pass review unnoticed: medication terms are checked against a validated coding, note fields carry a status and confidence derived from the extracted facts, and values the facts do not support are surfaced for a clinician instead of written as fact.

in production · source under nda

A deterministic checker and override on top of an LLM that auto-corrects Dutch tax documents. It enforces the correct 'sub' notation on EU-directive citations, where the model alone was inconsistent, and surfaces doubtful cases as review cards instead of silently rewriting legal text.

earlier builds and coursework

writing

all posts →

now

I’m looking for a summer 2027 internship, and I take on backend, RAG, and API work in the meantime. On my own time I’m working through C++ and Linux, one small system at a time, because I want to understand what sits under the abstractions I use all day. If you have backend or RAG work, email me and I’ll tell you honestly whether I can help.

certified · HackerRank Software Engineer verify · HackerRank REST API (Intermediate) verify