Platform architecture and web engineering for enterprise B2B SaaS. Boston, Massachusetts. Founder of Kinetic Gain LLC, where I build governance tooling for the answer-engine and agent era.
Miz Causevic (Mirza Causevic). Background across IBM, CyberArk, Alteryx, Digital.ai and Gryphon.ai, in platform engineering, identity and privileged access, and analytics workflow.
Open to Director of Web Engineering, Principal Platform Engineering, and VP Platform Architecture roles. East Coast US, remote friendly. LinkedIn · kineticgain.com
| If you are | Go to |
|---|---|
A developer who found mcp-kinetic-gain |
MCP server below. Install is one line |
| Evaluating the governance specs | suite.kineticgain.com |
| A recruiter or hiring manager | Background and the role note above |
| Doing security or vendor diligence | kineticgain.com/trust/ |
| Looking for the full estate | portfolio.kineticgain.com |
One MCP server exposing every Kinetic Gain Protocol Suite spec as a callable tool, over stdio. v0.9.1, 75 tools, 12 specs, 172 tests passing, AGPL-3.0.
npx -y mcp-kinetic-gain validate <files...>Claude Desktop, one entry:
{
"mcpServers": {
"kinetic-gain": {
"command": "npx",
"args": ["-y", "mcp-kinetic-gain"]
}
}
}Three tools that show the shape of it:
aup_check_compliancejoins a Classroom AI AUP and a Student AI Disclosure into one allow or deny call.decision_card_validateenforces the full AI Procurement Decision Card conditional ruleset.defensetech_vault_resolve_3axisresolves a CUI tier, export-control status and foreign-person restriction tuple to the most restrictive policy that satisfies all three.
Published on npm and the MCP Registry, both at 0.9.1. Also listed on Glama, PulseMCP, metatext and mcpmarket.
The specs are v0.1 drafts. Nothing here has been certified or attested by a third party, and I do not claim otherwise. Where you see regulatory names such as FERPA, HIPAA, DFARS or NYC Local Law 144, they mark which obligation a field is modelled against. They are not a compliance claim about your use of it.
Vertical reference implementations ship with synthetic fixtures only. No PHI, no student records, no real claimant data. Tools report conformance against a JSON Schema, which is a structural check, not a legal opinion.
Every repo carries its own SECURITY.md. That is where the scoped, checkable version of any claim lives.
17 named platforms · 107 live properties · 17 open specs · 17 verticals
| Named platform | Repos |
|---|---|
| Kinetic Gain Protocol Suite | 12 |
| Kinetic Gain Implementation Stack | 27 |
| AEO Reference Stack | 13 |
| Agent Operations Suite | 23 |
| Platform Reliability Stack | 17 |
| Decision Intelligence | 11 |
| AI Procurement Pulse | 5 |
| HealthTech / Clinical Stack | 18 |
| Growth & Consent Operations | 20 |
| MCP Servers | 38 |
| Landing Sites | 12 |
| Frontend Showcase | 28 |
| Identity & Access Governance | 34 |
| Cloud Cost & Resource Governance | 27 |
| Data Lineage & Privacy Operations | 20 |
| AI Safety & Adversarial Testing | 13 |
| Developer Experience & Platform Engineering | 3 |
Counts are platform cluster sizes; a repo may belong to several platforms, so they sum to 321 membership-slots.
Those figures regenerate from kinetic-gain-canonical.json every six hours. They are cluster sizes,
not a repo total, because one repo can belong to several platforms. The raw public-repo count is
deliberately not a headline here: it drifts, and a wrong number costs more than a missing one.
Claims on this page are meant to be checkable in about a minute.
- The server works.
npx -y mcp-kinetic-gain validate <file>against any Suite document. - The tests pass.
git clone,npm ci,npm test. 172 passing at v0.9.1. - The specs are real. Each is a public repo with a JSON Schema and test vectors.
- The disclosures are live. Any Kinetic Gain domain serves its own
/.well-known/documents. - The numbers reconcile. The estate block above is generated, not typed.
Dependabot on 410 repos · CodeQL on 98 · OpenSSF Scorecard on 52 (strict subset of CodeQL) · SHA-pinned actions across 558 uses: lines (measured 2026-06-04).
Platform engineering, identity and privileged access, and analytics workflow, across IBM, CyberArk, Alteryx, Digital.ai and Gryphon.ai. That history is why the Kinetic Gain work sits where it does: governance, evidence and trust boundaries rather than features.
Two of the surfaces exist because I lived the problem. cert.kineticgain.com and jml.kineticgain.com are the CyberArk certification-review and the joiner-mover-leaver lines from that history turned into working software.
Polyglot by choice, and the language is picked for the problem rather than for the list. Rust for hot paths and cryptographic primitives, Python for the audit-stream services, TypeScript for the operator surfaces, Go and Elixir where the concurrency model earns it.
Concrete, live, and checkable. Not a portfolio of screenshots.
| Surface | What it is |
|---|---|
| suite.kineticgain.com | The Protocol Suite front door. Twelve specs, the full spec table, the two-front-doors model |
| cert.kineticgain.com | CyberArk access-certification review turned into working software |
| jml.kineticgain.com | Joiner-mover-leaver identity lifecycle, from the CyberArk years |
| pulse.kineticgain.com | Weekly self-scored procurement telemetry, signed receipts published at /.well-known/ |
| bench.kineticgain.com | A 30-attack prompt-injection corpus that back-references the refusal taxonomies it tests |
The languages are ranked by how many repositories actually lead with them across the estate, not by preference. The tooling is what genuinely ships and deploys the work.
Languages
Frontend
Backend and data
Cloud, infra and CI/CD
AI and protocol
Open to Director of Web Engineering, Principal Platform Engineering, and VP Platform Architecture roles at enterprise B2B SaaS companies. East Coast US time zone. Remote friendly.


