JAKE LAMON

> founder. former SOC 1 / SOC 2 auditor. overlander.

Five years auditing security controls at Grant Thornton and Coalfire. Seven months living out of a Tacoma across the US & Canada. Now in Denver building AuditPilot, Keelix, and a seven-agent automation org that works while I sleep.

CURRENTLY: BUILDING AUDITPILOT · DENVER, CO

2025 — NOW

NOW — FOUNDER ERA

Building AuditPilot — an AI-assisted audit engagement platform for SOC 1 / SOC 2 firms, born from five years of audit pain — alongside Keelix, VoltForge, and a seven-agent automation org that works while I sleep.

PRODUCTS

AUDITPILOT

IN DEV

AI-assisted audit platform for SOC 1 / SOC 2 firms

Multi-tenant SaaS managing the full lifecycle of a compliance engagement — three role-scoped portals, a framework-agnostic control engine spanning five frameworks, cross-framework evidence reuse, and Claude woven through evidence coaching, review, and report drafting. ~970 automated tests. Born from five years of audit pain.

TypeScript · Next.js 16 · Supabase · Claude API · Tailwind v4

KEELIX

IN DEV

Pre-deployment security gate for self-hosted Docker stacks

Probes your host from the outside to learn what is actually reachable from the internet, runs 35 deterministic checks across 9 groups, scores your posture 0–100, and emits audit-ready evidence mapped to SOC 2 and ISO 27001. Deterministic core, optional AI explanations, single static Go binary.

Go · Cobra · Next.js 16 · Supabase · Stripe

VOLTFORGE

IN DEV

Deterministic 12V system designer for overland builds

One intake form returns a complete LiFePO4 electrical design — battery bank, solar, DC-DC, inverter, NEC wire-gauge and fuse schedule. Every number comes from a tested engineering rules engine (269 assertions, property-based tests included); the LLM only writes the plain-English tradeoffs, never the math.

TypeScript · Next.js 16 · Supabase · Zod · fast-check

INFRASTRUCTURE

THE AGENT ORG

LIVE

Seven AI agents on an always-on Mac mini

A self-hosted OpenClaw deployment that runs my life's back office: a daily intelligence digest delivered as email + audio brief, a health coach wired to a decade of Garmin data, market and research scans — 29 cron jobs across seven persona-scoped agents, speaking through MCP servers I built or patched.

7 agents29 cron jobs5 MCP servers1 daily report

OpenClaw · MCP · Telegram · Discord · SQLite · launchd

MISSION CONTROL

INTERNAL

A cockpit for watching and steering the agent fleet

Browser-based control plane that treats OpenClaw's on-disk state as the source of truth and projects it into six operator views — kanban, calendar, intervention queue, activity feed. Writes back through a mutex-serialized, atomic-rename pipeline. 47 tests.

TypeScript · React 19 · Express · SQLite · SSE

OVERLAND MCP

PROTOTYPE

GaiaGPS + TrailsOffroad as AI-callable tools

MCP server exposing two trail services with no public APIs as 19 structured tools — reverse-engineered session auth, a provenance-aware SQLite cache with per-entity TTLs, idempotent writes. An agent plans the route; it lands on my phone in GaiaGPS. 75 tests against real HTTP fixtures.

Python · FastMCP · httpx · SQLite · launchd

SLACK MCP

PROTOTYPE

Slack for AI agents — no bot, no OAuth, no admin approval

Reads your existing Slack Desktop session instead of provisioning credentials — decrypts the session cookie with a Keychain-derived AES key, recovers per-workspace tokens from LevelDB, and exposes seven read-only MCP tools. One ~400-line file, two dependencies.

Python · MCP SDK · cryptography · SQLite

GARMIN-SYNC

LIVE

A decade of my health data, in SQLite I own

Self-hosted Garmin Connect warehouse — sleep stages, HRV, body battery, training load and 24 tables more, synced hourly by launchd with idempotent upserts and an audit log. 2,300+ unattended runs, zero logged errors, ~3,700 days of history, daily markdown recaps.

Python · SQLite · garminconnect · launchd

2024 — 2025

COALFIRE

Consultant · Coalfire

Led SOC 1 and SOC 2 Type I & II examinations for mid-market clients, evaluating control design and operating effectiveness across trust services criteria — security, availability, confidentiality.

Remote

2023 MAR — SEP

THE TRIP

Since college I’d dreamt of taking a gap year and trying van life — and kept putting it off. In March 2023 I stopped putting it off: left my audit job, built out a Go Fast Camper on my 2016 Toyota Tacoma, and spent the next seven months overlanding across the US and Canada — favoring the hard trails and the camps at the end of them.

2019 — 2023

GRANT THORNTON

Risk Advisory Associate → Senior Associate · Grant Thornton LLP

Planned, organized, and executed SOC 1 and SOC 2 security risk assessments to strengthen clients’ IT control environments — business continuity, incident response, security controls.

Denver, CO

2015 — 2019

CU BOULDER

Leeds School of Business

BSBA — dual emphasis in Information Management and Operations Management. Delta Sigma Pi; Alpha Delta Phi founding class.

Boulder, CO