Available for software engineering roles - backend systems, production reliability, cloud deployment, and AI-assisted workflows.

From my build archivePrototype

Network Guardian AI

AI-assisted network traffic review prototype using anomaly signals, entropy-style scoring, FastAPI, React, SQLite, and local/hosted AI summaries.

01

Why I started it

Network events can be noisy, difficult to prioritize, and hard to explain quickly without structured signals.

AI summaries are useful only when they stay grounded in observable data and avoid overstating security impact.

02

What took shape

A FastAPI and React prototype for reviewing traffic signals and producing AI-assisted summaries.

A detection direction using anomaly-style scoring, entropy-oriented features, and structured event storage.

A privacy-aware AI path that can use local models such as Ollama, with hosted model fallback where appropriate.

03

Under the hood

FastAPI backend for ingestion and analysis endpoints.

React interface for reviewing network and security signals.

SQLite-backed prototype storage.

Isolation Forest-style anomaly detection direction.

Entropy-style scoring for suspicious or unusual patterns.

Local/hosted AI summary boundary using Ollama and Gemini.

04

Where it stands

Prototype. It should not be described as a production security control or a verified threat-detection system.

05

Repo notes

Primary language: Python

Technologies: Python, FastAPI, React, SQLite, AdGuard, Ollama, Gemini, Isolation Forest, Entropy, TypeScript, JavaScript, HTML, CSS, Docker, NumPy, Pydantic, Pytest, Scikit-learn, Uvicorn, Docker Compose

Topics: Not specified

Last updated: 2026-05-27T04:54:01Z

Stars: 0

Forks: 0

Status: Active

Visual notes

What the build looked like.

Read the longer notes
I have not added screenshots to this entry yet. The original README is still below if you want the less-polished version of the story.

๐Ÿ›ก๏ธ Network Guardian AI

Multi-Tenant Security-as-a-Service Platform


๐Ÿ“– Table of Contents

  1. ๐Ÿ” Overview
  2. ๐Ÿ•น๏ธ Core Features
  3. ๐Ÿ—๏ธ System Architecture
  4. ๐Ÿง  Intelligence Layers
  5. ๐Ÿ‘ฅ Multi-Tenancy
  6. ๐Ÿ’ณ Billing & Subscriptions
  7. ๐Ÿ”‘ Developer API
  8. ๐ŸŽจ UI Components
  9. ๐Ÿš€ Getting Started
  10. ๐Ÿงช Testing

๐Ÿ” Overview

Network Guardian AI is a real-time network security platform with multi-tenant support. It intercepts DNS queries via AdGuard, performs multi-layered behavioral analysis, and provides threat intelligence through a modern dashboard UI.

Security-as-a-Service: Ready for commercial offering with tenant isolation, billing integration, and tier-based access control.


๐Ÿ•น๏ธ Core Features

  • Real-time Threat Detection: Live stream of DNS requests with risk assessments
  • Manual Domain Analysis: On-demand analysis with Gemini AI and ML heuristics
  • 12-Panel Stats Dashboard: Comprehensive metrics overview (Overview, ML, Alerts, Blocklist, Settings)
  • Admin Dashboard: CRM-style tenant management interface
  • Usage Tracking: Per-tenant usage analytics and rate limiting
  • Developer Portal: API key generation and endpoint documentation

๐Ÿ—๏ธ System Architecture

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚                     Docker Compose                          โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”    โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”   โ”‚
โ”‚  โ”‚  Network Guardian   โ”‚    โ”‚    AdGuard Home         โ”‚   โ”‚
โ”‚  โ”‚  (Backend + UI)    โ”‚    โ”‚    (DNS Interceptor)    โ”‚   โ”‚
โ”‚  โ”‚   Port: 8000       โ”‚    โ”‚    Port: 8080, 53       โ”‚   โ”‚
โ”‚  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜    โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜   โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

Components:

  • Frontend: React/TypeScript, served from backend static
  • Backend: Python 3.11 / FastAPI
  • Database: SQLite with multi-tenant support
  • DNS Interceptor: AdGuard Home
  • AI: Google Gemini (with local heuristic fallback)

๐Ÿง  Intelligence Layers

LayerMethodPurpose
Layer 1Shannon EntropyDetects random DGA strings locally
Layer 2Isolation Forest (ML)Unsupervised anomaly detection
Layer 3Gemini AISemantic threat analysis
Layer 4Blocklist LookupKnown threat database

๐Ÿ‘ฅ Multi-Tenancy

Tenant Management

  • Complete Isolation: Each tenant has separate data, API keys, and configurations
  • Tenant Middleware: Automatic tenant identification via subdomain, headers, or API key
  • Dashboard Switching: TenantSelector component for quick context switching

Subscription Tiers

TierFeaturesRate Limit
Free100 requests/minBasic ML heuristics
ProUnlimited + Gemini AIFull analysis pipeline
EnterpriseCustom + SLAPriority support

๐Ÿ’ณ Billing & Subscriptions

Stripe Integration

  • Checkout Sessions: One-click subscription upgrade
  • Customer Portal: Self-service billing management
  • Webhook Handling: Automated tier updates on payment events
  • Usage Tracking: Daily and overall stats per tenant

API Endpoints

POST /billing/checkout     - Create Stripe checkout session
POST /billing/portal       - Get customer portal URL
POST /billing/webhook      - Stripe webhook handler
GET  /billing/tiers        - List subscription tiers

๐Ÿ”‘ Developer API

Authentication

  • API Keys: Per-tenant API key generation
  • JWT Support: Token-based authentication
  • Rate Limiting: Tier-based request limits

Endpoints

POST /api/v1/analyze       - Analyze domain
GET  /api/v1/stats         - Get tenant statistics
GET  /api/v1/history       - Get threat history
WS   /ws/public            - Real-time updates

Rate Limits

TierRequests/Minute
Free100
Pro1000
EnterpriseUnlimited

๐ŸŽจ UI Components

Stats Dashboard (12 Panels)

  1. Blocklist KB / Known Threats
  2. Ollama Models / Local AI
  3. Total Decisions / Analyzed Domains
  4. Autonomy Score / Local Analysis Rate
  5. Patterns Learned / ML Model
  6. Active Alerts / Pending
  7. Anomaly Model / Training Status
  8. Sources Active / Blocklist Sources
  9. Vector Embeddings / Threat Storage
  10. Entropy Threshold / Dynamic
  11. Activity Trend Chart
  12. Category Distribution Pie Chart

Pages

  • Dashboard: Main threat monitoring view
  • Admin: Tenant management, CRM interface
  • Usage: Per-tenant usage analytics
  • Pricing: Subscription tier information

๐Ÿš€ Getting Started

1. Environment Setup

cp .env.example .env
# Edit .env with your API keys:
GEMINI_API_KEY=your_key
STRIPE_API_KEY=sk_live_...
STRIPE_WEBHOOK_SECRET=whsec_...

2. Start Services

# Build and start
docker compose up --build -d

# Or just start (if image exists)
docker compose up -d

3. Access

4. Environment Variables

# Core
GEMINI_API_KEY=your_gemini_key
ADGUARD_URL=http://adguard:80
ADGUARD_USER=admin
ADGUARD_PASS=your_password

# Stripe Billing
STRIPE_API_KEY=sk_live_...
STRIPE_WEBHOOK_SECRET=whsec_...
STRIPE_PRO_PRICE_ID=price_...
STRIPE_ENTERPRISE_PRICE_ID=price_...

# Ollama (optional)
OLLAMA_ENABLED=false
OLLAMA_BASE_URL=http://host.docker.internal:11434
OLLAMA_MODEL=nomic-embed-text
OLLAMA_CHAT_MODEL=llama3.2

# Multi-Tenancy
ENVIRONMENT=development  # Set to production for production
API_RATE_LIMIT_PER_TENANT=100
DEFAULT_TENANT_ID=1

๐Ÿงช Testing

# All tests
PYTHONPATH=. python -m pytest Tests_AI/ -v

# Single test
PYTHONPATH=. python -m pytest Tests_AI/test_heuristics.py -v

# With coverage
PYTHONPATH=. pytest Tests_AI/ -v --cov=backend

# Linting
ruff check backend/ && ruff check backend/ --fix
mypy backend/ --ignore-missing-imports

๐Ÿ“Š Project Structure

network-guardian-ai/
โ”œโ”€โ”€ backend/
โ”‚   โ”œโ”€โ”€ api/              # FastAPI routes
โ”‚   โ”‚   โ”œโ”€โ”€ stats.py      # Statistics endpoints
โ”‚   โ”‚   โ”œโ”€โ”€ chat.py       # Chatbot
โ”‚   โ”‚   โ”œโ”€โ”€ billing.py    # Stripe billing
โ”‚   โ”‚   โ”œโ”€โ”€ tenant_router.py
โ”‚   โ”‚   โ””โ”€โ”€ developer_router.py
โ”‚   โ”œโ”€โ”€ core/
โ”‚   โ”‚   โ”œโ”€โ”€ config.py     # Settings
โ”‚   โ”‚   โ”œโ”€โ”€ tenant_middleware.py
โ”‚   โ”‚   โ””โ”€โ”€ websocket_manager.py
โ”‚   โ”œโ”€โ”€ db/
โ”‚   โ”‚   โ”œโ”€โ”€ models.py     # SQLAlchemy models
โ”‚   โ”‚   โ”œโ”€โ”€ repository.py # Data access
โ”‚   โ”‚   โ””โ”€โ”€ database.py   # DB connection
โ”‚   โ”œโ”€โ”€ logic/
โ”‚   โ”‚   โ”œโ”€โ”€ ml_heuristics.py
โ”‚   โ”‚   โ”œโ”€โ”€ anomaly_engine.py
โ”‚   โ”‚   โ””โ”€โ”€ metadata_classifier.py
โ”‚   โ””โ”€โ”€ services/
โ”‚       โ”œโ”€โ”€ adguard_poller.py
โ”‚       โ”œโ”€โ”€ gemini_service.py
โ”‚       โ””โ”€โ”€ blocklist_loader.py
โ”œโ”€โ”€ frontend/
โ”‚   โ”œโ”€โ”€ components/
โ”‚   โ”‚   โ”œโ”€โ”€ Dashboard.tsx
โ”‚   โ”‚   โ”œโ”€โ”€ StatsPanel.tsx  # 12-panel overview
โ”‚   โ”‚   โ”œโ”€โ”€ AdminDashboard.tsx
โ”‚   โ”‚   โ”œโ”€โ”€ LoginPage.tsx
โ”‚   โ”‚   โ””โ”€โ”€ TenantSelector.tsx
โ”‚   โ”œโ”€โ”€ services/
โ”‚   โ”‚   โ”œโ”€โ”€ tenantService.ts
โ”‚   โ”‚   โ””โ”€โ”€ websocketService.ts
โ”‚   โ””โ”€โ”€ App.tsx
โ”œโ”€โ”€ docker-compose.yml      # Production
โ”œโ”€โ”€ docker-compose.dev.yml  # Development with hot-reload
โ”œโ”€โ”€ Dockerfile              # Multi-stage build
โ””โ”€โ”€ Tests_AI/              # pytest tests

๐Ÿค Built With

  • AI/ML: Google Gemini, Scikit-Learn, Shannon Entropy
  • Backend: Python 3.11, FastAPI, SQLAlchemy
  • Frontend: React 19, TypeScript, Tailwind CSS, Recharts
  • Database: SQLite (development), PostgreSQL-ready
  • Billing: Stripe
  • DNS: AdGuard Home

๐Ÿ“ˆ System Status

  • โœ… Multi-tenant isolation with complete data separation
  • โœ… Stripe billing integration with webhook handling
  • โœ… Developer API with rate limiting
  • โœ… 12-panel stats dashboard
  • โœ… Admin CRM interface
  • โœ… Real-time WebSocket updates
  • โœ… Production Docker deployment

Next conversation

Let's make the next system less fragile.

Open to software engineering roles across full-stack systems, platform and reliability work, workflow automation, and applied AI. I value teams where I can keep learning while contributing to real systems and clear delivery outcomes.

Also open to freelance or contract work across full-stack builds, practical automation, technical SEO, and cloud delivery.