Fusion Technology Strategies builds practical, evidence-first tools for incident response, AI security, Windows administration, cloud resilience, accessibility, and federal cloud operations.
The projects below are designed for operators who need to understand what a tool will do, test it safely, and retain useful evidence afterward. Each repository documents its guardrails, permissions, limitations, and validation approach.
| Project | What it helps you do | Best first step |
|---|---|---|
| M365 Incident Response Console | Investigate and contain Microsoft 365 incidents with guarded live actions and tamper-evident evidence | Run the offline self-test, then use a disposable lab tenant |
| Bedrock Guardrail Firewall | Inspect AI traffic for PII, prompt injection, unsafe content, and grounding problems | Run the local deterministic demo before enabling optional cloud integrations |
| Windows Admin Toolkit | Operate twenty guarded local and remote Windows administration workflows | Download the latest signed release and verify it before execution |
- WCAG 2.2 Site & PDF Scanner: audit websites and PDFs, exercise axe-core in a real browser, and produce evidence-first remediation reports.
- AWS Chaos Engineering Framework: orchestrate bounded AWS FIS experiments with GovCloud-aware safeguards, rollback, and audit evidence.
- AWS GovHawk Efficiency Analyzer: surface potential waste, security blind spots, and operational risk across AWS GovCloud services.
- Ultra-Fast Proxy Fetcher & Tester: turn volatile public proxy feeds into a bounded, security-hardened network-diagnostics report.
- IDS Rule Converter: convert and validate Snort and Suricata rules while preserving unsupported or ambiguous semantics for operator review.
- Safe before clever: potentially disruptive actions are gated, scoped, and documented.
- Evidence over adjectives: projects include deterministic tests, sample outputs, and explicit limitations.
- Auditable dependencies: automated updates are reviewed, workflows use immutable action references, and protected branches require validation.
- Operator ownership: local and offline modes are available where the problem permits them; telemetry is not added to security or administration tools merely to count users.
- Portable by design: the primary runtime remains straightforward to inspect and move, even when optional package and integration layers are available.
The security scanner operations record documents portfolio schedules, ownership, exceptions, evidence retention, and the verification process.
Questions, reproducible bug reports, and implementation feedback are welcome in the relevant project. Please use each repository's SECURITY.md instructions for vulnerabilities instead of opening a public issue.
For consulting and mission support, visit https://www.fusiontsi.com or email jeff@fusiontsi.com.

