Activity
Mon
Wed
Fri
Sun
Sep
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
What is this?
Less
More

Memberships

Clief Notes

44.5k members • Free

89 contributions to Clief Notes
I built a workspace that answers security questionnaires
I built another workspace, this one answers security questionnaires. It takes the questionnaire a company sends, SIG, CAIQ v4, Google VSAQ, or an Excel file, and turns it into a question list. Every answer cites a source in the approved content, and what it can't cover gets flagged. I review the gaps myself before anything goes out, and the checks that run are plain deterministic scripts. I ran the whole thing end to end against a practice questionnaire, 30 real questions, with a real company trust page as the content. I have not run it for a real company yet. The company facts are still not set and the content folder has nothing in it. Right now I do not have a way of getting it in front of others to use, so I don't know if there is value in it. I was just looking into whether this is a good topic. Has anyone here had to answer one of these for a company? Do you think there is value in it? How do you answer them now?
0 likes • 47m
@Andre Cordero the verified or flagged part is where I ended up too. Mine answers security questionnaires, every answer has to cite a source that is in my approved content, and what it can't cover gets flagged for me to review before anything goes out. The check that the source is a real file is a plain script, no model in it. The side-by-side for the reviewer is the piece I don't have. When a citation gets flagged, do you fix it in the article, or does the reviewer handle it some other way?
0 likes • 42m
@Binit Nath it's for the business I work for. I mentioned it in case others need something similar.
How Are You Structuring Client Onboarding & Delivery Behind the Scenes?
For those of you already working with AI/automation clients, what does your behind-the-scenes client onboarding and delivery system look like? I understand the discovery side. What I'm trying to build is a clean operational framework for what happens once a client starts moving forward. Specifically, I'm curious how you handle things like: • Client folder/workspace structure • Discovery notes → scope → build handoff • Credentials and access • Client-provided assets/information • Project status and task tracking • Testing and client approvals • Documentation of automations/agents/workflows • Launch/go-live checklist • Training and handoff • Ongoing support/maintenance If you have a standard folder structure, checklist, SOP, or client lifecycle that you actually use, I'd love to see how you've organized it. I'm less interested in the sales process and more interested in the operational infrastructure that keeps a client engagement organized from discovery through handoff.
1 like • 2d
@André Ramirez this is the question I've been working through too, so I'll answer from what I actually do. The whole thing lives in a repo now. If the data can be pulled straight from the repo, someone can set up on their own. When a page has no api or mcp server to pull from, I use a browser extension that feeds the llm what it needs from the page. The keys stay hidden, they never go out with the repo. When someone runs setup in the workspace, the workspace knows the extension has to be there, walks them through it, and checks the access is set up right before anything runs. Everyone's workspace sends its output to the same repo, so a few people can work the same build, each from their own workspace. And if that's more than someone wants to take on, Jake just put out Alpha. What does your handoff look like today, and where does it break first?
I'm wrapping my trust and LLC workspace in a web application
I've been heads down on trust structures and LLCs the past few weeks. The kind where a living trust owns the LLC, with you as the trustee and the manager, so the business carries as little liability exposure as possible. The workspace ends with a filing-ready packet of legal and tax documents, and step-by-step instructions for every step that happens outside the workspace. Now I'm wrapping it in a web application so other people can use it without going through what I went through. I've also been heads down on a hidden job search workspace. I researched how the different applicant tracking systems actually work. A bunch of them expose public job feeds, Greenhouse, Lever, Ashby, SmartRecruiters, Workable, Recruitee, and the workspace pulls those directly. Everything else gets found with dorks. It vets each posting for scams and ghost jobs, and fills the applications in my real browser for me to review before anything submits. So far it's seen 411 postings, and 314 of them dropped before applying. 73 applications have gone out. I know @Bilal S shared his Seeker the other day. To me, this helps reduce the stress of the job hunt. Has anyone here set up a trust to own their LLC? How did you structure it, and who walked you through it? Anyone else here searching past the job boards? I'd love to hear what's working, the rough parts especially.
1 like • 2d
@Bilal S happy to talk about it. Auto apply is the part I'm most careful with. My workspace fills the applications in a real browser, and nothing submits until I've read it. Would be good to compare notes on the applications at some point.
1 like • 2d
@Bilal S your 6 tiers line up with what I see. The job sites with public feeds get scraped directly, everything else I find with dorks. What did you put at tier 0, and what makes a job site a 5?
Ledger follow-up
Ledger has been live for a few weeks now, and I'm curious how it's actually going for people. If you missed the launch, it's the talent platform Jake built on top of this community, where you list yourself with a profile and companies can find you, and both sides get vetted. I haven't seen anyone talk about what happens after you sign up, so I'm asking directly. Has anyone gotten a first conversation through it? Hired someone? Had a company reach out to them? How long did the vetting take? Jake said in the launch thread that the biggest factor in a hire is past builds, and that the competitions are designed to be projects a company would want to hire someone for. So if anyone who got hired through Ledger has a comp build in their profile, I'd love to hear that story. If you've used it, I'd love to hear how it went. The rough parts especially, it's alpha and they told us to tell them what breaks.
0 likes • 2d
@Jake Van Clief appreciate the straight answer. I'm curious about the few convos that are moving though. What do they look like, and where did they start?
Take 2 - 8 Months of work , thanks to the ICM it's finally done
We had a crappy first impression. Immediately several links were identified as broken in the repo. but they are all fixed and I would like to reintroduce Citadel. If you are into cyber security please take a look at this post quantum crypto implementation. I Don't have the funds for outside audits and validation yet but it feels complete from my standpoint. I would love it if any of you could try and break it. It would mean the world to me. I know that is a big ask so I'm not expecting much. I'm just so excited to have this off my plate. I've been obsessing over it for so long and now I can finally move on to other things. The crazy part is nobody asked me for it. I just heard about it and couldn't stop touching it. Criticism desired, look it over and light me up. really it would have taken me another at months with the ICM. I was doing insane amounts of iterating back and forth with all my Ai. This group brought to a different way of approaching my time with AI and we just started blasting through the work. "The post-quantum mandate. The migration to post-quantum cryptography is no longer optional for a growing set of systems. A future quantum computer would break the RSA and elliptic-curve algorithms that protect most data today, and because an attacker can record encrypted data now and decrypt it later, the risk already applies to anything that must stay secret for years. The United States has set firm timelines in response. National Security Memorandum 10 (2022) and the NSA's Commercial National Security Algorithm Suite 2.0 require National Security Systems and their vendors to move to quantum-resistant algorithms on a staged schedule, with most technology categories reaching exclusive use between 2030 and 2033 and full transition by 2035. The Quantum Computing Cybersecurity Preparedness Act (Public Law 117-260, 2022) and OMB Memorandum M-23-02 place parallel inventory-and-migration obligations on federal civilian agencies. Who it reaches, and the sources. For everyone else the direction is the same, even where it is not yet law: CISA, the NSA, and NIST jointly urge all organizations, and critical infrastructure in particular, to begin migrating now, and NIST's transition guidance (IR 8547) schedules the classical public-key algorithms for deprecation after 2030 and disallowance after 2035. The replacement standards are already published: ML-KEM in FIPS 203, ML-DSA in FIPS 204, and SLH-DSA in FIPS 205, all finalized in August 2024. Together these define what to migrate to and by when: the algorithms in FIPS 203/204/205, the deadlines in CNSA 2.0 and NIST IR 8547, and the mandates in NSM-10, OMB M-23-02, and Public Law 117-260."
Take 2 - 8 Months of work , thanks to the ICM it's finally done
1 like • 3d
@Andre Cordero I took you up on the second look. I went through the README links one at a time, and all of them resolve to files that are actually in the repo now. The dead claim-matrix links I flagged last time are gone. I checked the CI run the validation matrix points to as well, run 31141328479. It's real, it's green, 435 passed / 0 failed / 9 ignored, and the ACVP vectors and the volume tests are on the same run. cargo audit and the docker health check are green on it too. The commit from yesterday that fixed the adaptive threat engine bugs from the Codex review, I read that one as well. It's good work.
0 likes • 2d
@Andre Cordero haha I appreciate that. The all clear covered what I could actually check, the links and the CI run. I'm not a cryptographer, so I could not check the math. One thing I noticed on run 31141328479, it has 9 ignored tests. I did not look into which ones they are.
1-10 of 89
Mike Wiliams
5
206 points to level up
@mike-wiliams-5561
Principal Engineer

Online now
Joined May 4, 2026
Powered by