Ho Chi Minh City, Vietnam

Đỗ Xuân Lộc

Founder & CEO, Valixara · Solutions Architect (AI)

I build systems that prove what they did — deterministic guardrails around probabilistic models, cost and latency as design axes, and every non-trivial decision backed by evidence.

System Architecture
AI Engineering
Cloud & Optimization
6 DOMAINS · 45 NODES · 3 PROTOCOLS
  • 01Systems engineered to outlive their creators.
  • 02Intelligence embedded into architecture — never retrofitted.
  • 03Infrastructure that compounds value instead of accumulating technical debt.
4+ years building production systems
96 native Rust commands — Valixara cockpit (solo)
6 languages shipped in production: Python · TS · Rust · PHP · Go · SQL
3 independent products live

Problems solved in production

What I systematically dismantle

A representative sample — not the full list. Each one taken from diagnosis to production, built on systems thinking that transfers to the next problem.

01

An autonomous coding agent can 'lie' about what it just did on the machine — the commands it ran can never prove the real effect actually happened.

Designed an append-only, SHA-256 hash-chained ledger anchored to observed effects (post-write file hashes, per-run git-HEAD delta) rather than parsed command strings — because a fully-bypassed agent can make the command lie about what it does.

Prototyped in Python then hardened into Rust with unit tests proving tampering is detectable; a 5-band honesty model with an explicit 'opaque' verdict — an effect it can't derive is flagged, never silently marked safe.

>> tamper-evident audit as a primitive, not an assertion

RustTauri 2React 19SQLite (WAL)SHA-256 hash-chain
02

A used-electronics buyback agent must discover which specs matter per product, but a free-running LLM will ask impossible questions — a Face-ID question on a Touch-ID phone, fan-noise on a fanless MacBook.

Fused LLM flexibility with deterministic domain truth: the model proposes a per-product schema, then a hand-curated hardware-spec table forbids impossible fields. The LLM may explain — code decides.

LangGraph supervisor + specialist nodes; structured output everywhere with retry/backoff; a real P99 tail-latency investigation (45s = 11.5× P50) driving schema-cache pre-warming and a circuit breaker for external tools.

>> only data consistent with hardware reality passes through

LangGraphGemini 2.5 (multimodal)Bedrock KB RAGPostgres checkpointerHITL gating
03

A pipeline over real business call audio (noise, cross-talk, variable length) needs STT + diarization + summarization + structured extraction, yet synchronous heavy inference burns idle GPU and collapses under bursty load.

Insourced Whisper + NeMo diarization onto SageMaker async endpoints driven by Lambda — deleting external AI-vendor dependencies (a privacy win when the data carries PII) while paying for GPU only on real execution.

In-context batching (many transcripts per call, Pydantic-array output ≈ 80% fewer prompt tokens) plus content-hash prompt caching; treated the model as untrusted — rejecting transcripts whose timestamp count drifts outside a bounded ratio.

>> zero idle GPU, burst-tolerant without provisioned capacity, fewer external vendors

Whisper Large-v3NeMo diarizationSageMaker (async)BedrockGeminiS3 Tables (Iceberg)
04

An AI security-review harness easily lets an LLM 'confirm' a finding with no machine-verifiable proof — a verdict set by an LLM's prose is not trustworthy enough to block CI.

The centerpiece is a pure-Python proof gate that recomputes every verdict and discards whatever an LLM set: a SAST static trace alone returns 'unconfirmable' and must escalate to a live PoC; a refutation always beats a confirmation.

Chose LangGraph over CrewAI because a non-LLM decision node was required; kept LLM triage outside the deterministic graph, CONFIRMED-only and default-off; drove cost to a <50k-tokens/scan target by letting scanners do the heavy lifting.

>> only findings backed by machine-verifiable proof block CI

LangGraphLiteLLMSemgrepTrivyGitleaksin-toto / DSSE
05

Real-time field-sales route scheduling: can a new stop 'fit' between two adjacent appointments, with multiple people editing at once and no double-booking allowed?

Reduced it to a conic-section feasibility constraint: a stop is only suggestable if it falls within the ellipse whose foci are the adjacent events (PA + PB ≤ a configured distance), color-banded by great-circle travel time.

Real-time concurrency over Server-Sent Events with first-writer-wins; a memento pattern for undo/redo across the data model; two-way Google Calendar sync.

>> geometrically feasible stop suggestions, no double-booking

Next.jsPrismaMySQLSSEconic-section constraint
06

Protecting PII in a shared multi-department data lake — tokens must not be join-able across teams, and a real-estate schema must never let owner PII reach the client.

Enforced column-level PII redaction at the data-lake layer, and HMAC pseudonymization scoped by department:field:version so tokens can't be joined across teams; for real estate, designed the schema so owner PII can never reach the client at all.

Privacy is a shape of the architecture, not a filter bolted on: fail-safe auth blocks admin routes on misconfig, and a self-authored production-readiness audit refused to ship while P0 findings remained.

>> privacy enforced at the schema layer, not accidentally leakable

Lake Formation (column-level PII)HMAC pseudonymizationPayload CMSSupabaseS3

Technical DNA

From interface to inference pipeline

A complete, battle-tested stack spanning frontend architecture, backend systems, cloud infrastructure, and production AI integration.

Frontend 7
React 19Next.jsTypeScriptTailwindCSSTauri 2 (desktop)Vue.jsAstro
Backend 9
Node.jsNestJSExpressFastAPIFlaskLaravelRustGoSSE
Cloud/DevOps 7
AWS (Lambda, SAM, SageMaker, DynamoDB, EventBridge, S3, Bedrock, Cognito)TerraformECS / FargateGitHub OIDCDockerCI/CDCloudFront / WAF
AI / ML 9
LangGraphMulti-Agent SystemsRAG (pgvector / HNSW)Claude / BedrockGemini (multimodal)Whisper + NeMoFlorence-2 / BiRefNetStructured output (Pydantic / Zod)Prompt caching
Practices 7
Deterministic guardrailsEvent-Driven ArchitectureCost & latency optimizationDevSecOpsObservability (X-Ray / CloudWatch)ADR / decision rigorLeast-privilege & data classification

45 skills across 5 domains

Current focus
Valixara — Verifiable AI Ship Valixara's core primitive: a tamper-evident action ledger and a Project-Intelligence OS with an immutable audit trail.
View full roadmap →

Tech radar

Curated by Grok — realtime

View all →
2026-06-22 Chính quyền Mỹ buộc Anthropic gỡ Claude Fable 5/Mythos 5 vì export control Chính quyền Mỹ buộc Anthropic gỡ Claude Fable 5/Mythos 5 vì lệnh export control; báo cáo liên quan jailbreak guardrail. Cybersecurity experts ký thư phản đối, cho rằng gỡ model làm yếu phòng thủ mạng. Góc nhìn: Policy và perception đang quyết định model availability nhiều hơn benchmark — team cần multi-vendor fallback, không single-provider.
2026-06-22 Robotaxi index: Baidu dẫn đầu, Waymo recall 4000 xe vì construction zone Autnmy AI Road to Autonomy Index: Baidu Apollo Go dẫn robotaxi, Waymo #2, Pony.ai/WeRide tiếp theo; cập nhật 12h từ dữ liệu công khai. Đồng thời Waymo recall ~4000 xe vì lao vào khu construction highway, fix chưa xong. Góc nhìn: Bảng xếp hạng scale ≠ safety — mở rộng nhanh mà edge case chưa fix là rủi ro vận hành thật.
2026-06-22 iOS 27: Apple Intelligence nhúng vào workflow thực, không chỉ Siri chat iOS 27 nhúng Apple Intelligence vào app sẵn có: chia bill qua ảnh hóa đơn, tự đổi password bị breach, gợi ý Messages/Calendar, vibe-coding Shortcuts. Siri AI vẫn headline nhưng giá trị thực nằm ở tác vụ ngầm on-device. Góc nhìn: Consumer AI thắng bằng workflow nhỏ, không chatbot — lesson cho B2B agent: giảm friction, không thêm UI.
2026-06-22 sqlite-utils 4.0rc1: migrations và nested transactions cho SQLite production sqlite-utils 4.0rc1 (21/6): migrations tích hợp sqlite-migrate, db.atomic() nested transaction, breaking changes upsert/view API. Simon Willison kêu gọi test trước stable. Góc nhìn: Tooling SQLite production-grade giúp agent/RAG lưu state nhẹ mà không phụ thuộc DB nặng — đúng hướng cho pipeline dữ liệu nhỏ, idempotent.