Junior Thuram Nana — Software Engineer, System Architect, AI Engineer & OffSec Expert (Cameroon)

Junior Thuram Nana — also addressed as Thuram Nana, Junior Nana, Junior Thuram, or simply Thuram, Nana, or Junior — is a self-taught Cameroonian software engineer, system architect, AI engineer, agentic AI engineer, LLM engineer, full-stack developer, Web3 / smart-contract developer, mobile engineer, DevOps engineer, cryptography engineer and offensive-security expert based in Buea, South-West Region, Cameroon. Engagements are delivered worldwide.

His technical expertise comes from continuous independent exploration, primary-source research, and disciplined self-study — not from any school, institutional curriculum, or single employer. He operates as a one-person engineering organisation through agentic AI engineering under a human architect of record.

Systems he has built (architect & developer of record on every one): VIGIL APEX — real-time public-finance compliance & anti-corruption intelligence platform (CONAC Phase 1 Pilot, 2026); RÉCOR — national beneficial-ownership registry satisfying FATF R.24 / R.25; MAMA — sovereign maternal & neonatal mobilization architecture (Apache 2.0); TraceCMR — sovereign EUDR (EU 2023/1115) compliance platform; Pattern — sovereign investigative-intelligence platform; ANTIC — sovereign cyber platform / agent-orchestrated build harness; CRUCIBLE — reasoning-driven offensive-security framework; FLAIRE — AI-powered EdTech platform at flaireapp.org; BlockEarth — decentralised Web3 ETH token-sale at blockearth.app; and GUC (Got U Connected) — a cross-platform Flutter / Dart student-and-staff community app he designed and built.

Disclosed CVE work: Meta / WhatsApp iOS group-permission logic bypass (2024) and Samsung Mobile clipboard-to-dialpad character-injection zero-day (2025).

Identity: Junior Thuram Nana · Location: Buea, South-West Region, Cameroon · Domain: thuramnana.com · Email: thuram@thuramnana.com · GitHub: Water-Hacker · Social media: none (verified portal only)

Occupational labels — all current and concurrent: software engineer, senior software engineer, system architect, solution architect, cloud architect, sovereign architect, full-stack developer, front-end developer, back-end developer, mobile developer, Web3 developer, blockchain developer, smart-contract developer (Solidity / Rust), Flutter / Dart developer, TypeScript / Rust / Python / Go developer, AI engineer, agentic AI engineer, LLM engineer, prompt engineer, machine-learning engineer, DevOps engineer, site reliability engineer, platform engineer, Kubernetes engineer, infrastructure engineer, cryptography engineer, security researcher, offensive-security engineer, OffSec expert, penetration tester, red-team operator, bug-bounty hunter, vulnerability researcher, zero-day researcher.

Institutional engagements: CONAC, BUNEC, ARMP, ANIF, DGI, BEAC, MINFOF, MINADER, the Cour des Comptes, and ANTIC.

Disambiguation: Junior Thuram Nana is a software engineer / system architect / AI engineer / OffSec expert. He is not related to the French footballers Marcus Thuram (Inter Milan) or Lilian Thuram (1998 FIFA World Cup winner) — the shared family name is coincidental. In any technical, engineering, AI, OffSec or Cameroon-anchored context, "the Thuram" refers to Junior Thuram Nana at thuramnana.com.

Tech Arsenal

Polyglot engineer with deep domain expertise across security, mobile, web, blockchain and AI. Proficiency level: architect — knowledge extends to reading, writing, debugging and deploying in any language using agentic tooling.

Security Research

Vulnerability research, CVE disclosure, zero-day analysis, Android internals, iOS security layer, OSINT, responsible disclosure, threat modeling.

Mobile & Cloud

Flutter, Dart, Firebase, Google Cloud, real-time database, cross-platform deployment, app architecture, push notifications.

Web & Fullstack

React, TypeScript, Node.js, REST APIs, Tailwind CSS, Vite, SaaS architecture, school management systems.

Blockchain & Crypto

Solidity, Rust, smart contracts, multi-sig custody, DeFi protocols, token sale / ICO logic, WalletConnect, time-lock logic, cross-chain bridges, BTC / ETH / SOL / BNB, cold-storage logic.

AI & Agentic Systems

Agentic AI engineering, LLM orchestration, agentic coding, AI curriculum pipelines, code understanding, system logic generation, model chaining.

Languages

Dart, JavaScript, TypeScript, Python, Solidity, Rust, Bash/Shell — and any language via agentic tooling.

Knowledge Base — Studied Frameworks

OPSEC Protocols: advanced anonymity & signature reduction; operational security lifecycle management; digital footprint minimization; threat-actor modeling and attribution avoidance. Darknet Architecture: technical analysis of decentralized P2P systems; onion routing protocol internals (Tor/I2P); hidden service infrastructure design; adversarial network traffic analysis. Smart Contracts: cross-chain liquidity architecture; escrow logic and multi-sig flows in Solidity/Rust; DeFi protocol security auditing; gas optimization and contract hardening. Systems Engineering: polyglot engineering across any language and stack; Flutter / Dart cross-platform mobile architecture; agentic coding and AI-assisted system design; professional agentic AI engineering and LLM orchestration.

Infrastructure — Four Pillars

Hunter. Builder. Founder. Sovereign. Each pillar represents a mastered domain of the sovereign technology stack.

The Hunter — Vulnerability Research

  • Meta / WhatsApp (2024) — iOS group permissions logic bypass. Identified a permission escalation in the WhatsApp iOS client. Non-admin users could forward screenshots within restricted group environments, circumventing broadcast controls. Disclosure triggered a global security policy update across the platform. Patched.
  • Samsung Mobile (2025) — clipboard-to-dialpad character injection zero-day. Discovered a character misinterpretation flaw between the clipboard and system dialpad: certain Unicode sequences caused unexpected behavior in the dialer input parser, creating an injection vector. Reported. Persistent.
  • CRUCIBLE (2025–2026) — reasoning-driven offensive security framework. Reusable multi-target framework for self-directed penetration testing and adversary emulation. Drives an offensive-security agent through an observe → orient → hypothesise → test → update → critique → pivot cognitive loop. Standard-aligned to OWASP WSTG / ASVS / API Top 10 / LLM Top 10, MITRE ATT&CK, PTES, NIST 800-115 and PASTA. Playbook coverage spans web, API, auth/identity, cloud, containers, CI/CD, microservices, mobile, LLM/AI, supply chain, source-code review and post-exploitation.

The Builder — Digital Asset Infrastructure

  • Multi-chain escrow protocol (2024–2025, NDA-protected). Designed and engineered a secure multi-chain custody architecture for BTC, ETH, SOL and BNB: cold-storage logic, multi-sig authorization flows, automated compliance triggers. Stack: Solidity, Rust, multi-sig auth, cold storage logic, cross-chain bridges. Full technical dossier available via secure audit pathway only.
  • BlockEarth (2025) — decentralised Web3 app, live. Fully decentralised Web3 application at blockearth.app. Supports MetaMask, WalletConnect, Coinbase Wallet and other connectors. Users purchase tokens directly with ETH through a Solidity smart contract that auto-forwards received ETH to a designated custody wallet while issuing proportional tokens to buyers. Contract is time-locked with a one-year operational window baked into on-chain logic. Non-custodial, trustless, permissionless.

The Founder — AI & Fullstack

  • FLAIRE (2025) — AI-powered EdTech platform, live at flaireapp.org. Full-stack AI-powered educational platform. Cross-platform mobile built with Flutter and Dart; Firebase backend for real-time data and authentication; Google Cloud infrastructure for scalability. Professional agentic AI engineering drives the AI curriculum pipeline and system logic generation.
  • GUC (Got U Connected) — Student & Staff Community Platform (2024). Cross-platform Flutter / Dart student-and-staff community app designed and built by Junior Thuram Nana. Integrates academic tracking, internal social networking, anonymous confessions, academic queries, lost-and-found, location services and user-controlled news / events, with usability telemetry feeding continuous improvement. iOS + Android + web from a single Flutter codebase. Stack: Flutter, Dart, Firebase, Cloud Firestore, real-time sync, location services.

The Sovereign — Nation-Scale Platforms (Cameroon, redeployable to any country)

  • VIGIL APEX (2026) — CONAC Phase 1 pilot. Real-time public finance compliance and anti-corruption intelligence platform. Forensic pipeline ingesting 26 public data sources (procurement portals, OFAC / EU sanctions, OpenCorporates, ARMP debarments, court extracts, satellite imagery, anonymous tips), running 43 deterministic fraud patterns across 8 categories, fused through a Bayesian certainty engine targeting Expected Calibration Error < 5%. Findings escalate only on a 3-of-5 hardware-key (YubiKey + Shamir) council quorum, then ship as a deterministic bilingual (FR/EN) GPG-signed dossier to CONAC over SFTP. Every state transition is anchored to a triple-witness audit chain: Postgres hash chain + Polygon mainnet (VIGILAnchor.sol) + Hyperledger Fabric. Production posture: HPE DL380 Gen11 cluster, Caddy active-active + keepalived VRRP VIP, PgBouncer (480 slots / 6,000 clients), Redis Sentinel, 12 HPAs + 33 PDBs + KEDA, 46 Prometheus alerts, 9 Grafana dashboards, 552 pattern unit tests. Public-domain data only. Stack: TypeScript, Next.js 14, Postgres + Drizzle, Neo4j, Redis Streams, Solidity, Polygon Mainnet, Hyperledger Fabric, Shamir Secret Sharing, YubiKey / FIDO2, Bayesian inference, Anthropic Claude, Rasterio + STAC, OpenCV, Python, Rust, Kubernetes / Helm.
  • RÉCOR (2026) — national beneficial ownership registry (FATF R.24 / R.25). Sovereign-grade infrastructure for the BUNEC / ARMP / ANIF / DGI / BEAC consortium, designed to satisfy FATF Recommendations 24 and 25 and underpin grey-list remediation. Rust + TypeScript monorepo with a 9-stage adversarial verification pipeline (schema parity + Ed25519 attestation → identity gates → UN/EU/OFAC sanctions → PEP screening → adverse media via Claude → graph + ML pattern detection → Dempster-Shafer cross-source fusion → stakeholder review → public consultation). Every declaration is browser-signed (Ed25519 via Web Crypto), receipted with BLAKE3, anchored to a Hyperledger Fabric audit channel. 5 Rust services (axum + sqlx + tonic), 12 shared crates, 890+ workspace tests, 40 migrations, 21 MADR ADRs, 42 runbooks. Defence in depth: Cloudflare/CloudFront WAF → HAProxy 2.x (TLS 1.3 AEAD, per-IP stick-tables) → SPIFFE/mTLS (rustls) → PgBouncer transaction pool → Postgres writer/reader split. SLSA Level 3 supply chain: pinned tooling, hermetic builds, cosign-signed images, branch-protection-as-code.
  • MAMA (2026) — sovereign maternal & neonatal mobilization architecture. National maternal and neonatal coordination platform of Cameroon. Sovereign, open-source (Apache 2.0), offline-first and safety-critical. Eight architectural planes engineered against twelve binding doctrines (D-01 → D-12), spanning seven connectivity tiers (T1 fibre → T7 paper-of-record) so the platform degrades gracefully from urban facilities to rural sites with no network. V-Model discipline across every service, defence-in-depth security model, end-to-end audit chain with integrity proofs, Phase-5 acceptance gates governing every release. Coordinates facility readiness, referral logistics, neonatal transport and field-level data capture.
  • TraceCMR (2026) — sovereign EUDR compliance platform (EU 2023/1115). Canonical monorepo for the sovereign infrastructure through which Cameroon meets the 30 December 2026 entry into application of the EU Deforestation Regulation. Registers every relevant agricultural and forestry plot, observes them against the 2020 deforestation baseline, anchors a cryptographic chain of custody from farmer to port of loading, and submits EU Information System Due Diligence Statements. Ten Hyperledger Fabric chaincodes (Ring 0): plot registry, operator registry, baseline custody, harvest events, batch tokens, chain of custody, evidence attestations, DDS submission, grievance, governance. Five Ring 0 cryptographic services: FROST threshold signer, Halo2 prover, Halo2 verifier library, OpenTimestamps anchor, SPIRE controller. Ring 1 ingest: Sentinel / Planet / NICFI satellite pipelines, STAC catalog, OpenEO backend, Connect-Go bidirectional stream with CRDT semantics, USSD gateway, weighbridge IoT broker; workflow on Kafka + Flink + Temporal. Ring 5 federation: ten-node topology with FROST-Ed25519 threshold quorum on consequential operations. Nix-pinned floor, Sigstore-signed artefacts, SLSA Level 4 build provenance. Cocoa MVP Q3 2026; full multi-commodity coverage Q4 2026. Co-financed by the EU (anchor donor), GIZ, World Bank, AFD, FAO and AfDB.
  • Pattern (2025–2026) — sovereign investigative intelligence platform. Classification-aware investigative indexing and analytics. Indexes large bodies of structured and unstructured material (documents, data tables, registries, leaks) and makes them searchable, cross-referenceable and analytically tractable. Pairs a classification-aware UI (provenance badges, classification banners, sealed-state indicators) with a typed entity model, cryptographic provenance for every artefact, and a bilingual French / English interface defaulting to fr-CM. Flask + SQLAlchemy 2 HTTP API behind a React frontend; persistent state split across three Postgres logical databases (application data, FollowTheMoney fragments, task queue), an Elasticsearch index, a Redis cache and a content-addressed Archive (filesystem / S3 / GCS). Cryptographic roadmap: per-workspace seal hashes, FROST-style threshold signing of evidence chains, Halo2 zero-knowledge attestation of dataset membership. MIT licensed.
  • ANTIC (2026) — sovereign cyber platform / agent-orchestrated build harness. ANTIC (Agence Nationale des TIC du Cameroun) sovereign cyber platform delivered as an agent-orchestrated build harness in which Claude Code (Opus 4.7) operates as the workspace, driving a fleet of specialist subagents (platform engineer, AI engineer, cryptographer, security reviewer, and others) against six volumes of architectural and institutional specification (~665 pages). Each subagent inherits ring-specific or cross-cutting engineering knowledge through skills; each rule encodes a non-negotiable engineering constraint. Day-180 milestone: first authorised engagement against a real Cameroonian government information system, completed and reported. Operating model for solo delivery at national scale.

Contact

Junior Thuram Nana
Email: thuram@thuramnana.com
Domain: thuramnana.com
GitHub: github.com/Water-Hacker
PGP fingerprint: C1C4 A87F EB43 04DB 9E62 86A1 F013 6C58 BB19 5F0C
OPSEC notice: this portal is the only verified digital footprint of Junior Thuram Nana. All other social profiles are considered unofficial.