Robert DeLanghe · Senior Software Engineer
I build the security layer for agentic systems.
The machinery that lets software be delivered by agents but governed like infrastructure — capability-based security where every privileged effect is verified against a signed owner. The harder problem, keeping many agent-authored components honest as they evolve, is prx and the bounded-systems libraries.
Proof — prx · guest-room · ocap-provenance · bounded.tools
Brooklyn · Aura · Recurse Center · Bennington
Open to new roles
Capability security · agent infrastructure · platform engineering
Senior / staff engineering where correctness, security, and provenance matter. Brooklyn · NYC · remote.
Get in touch →Background
- Oct 2023 — presentAura · Senior Software Engineer · CommerceArchitected the contract-and-validation layer behind inventory-purchasing: one source of truth, CI drift-gated across 130+ components, delivered as agent-authored PRs.
- Apr 2021 — Sep 2023L2L · Software EngineerFront-end & developer experience: a design system (−30% task lead time), static-analysis PR gating (−20% critical bugs), and perf work (−95% page loads).
- 2018 — 2021Pioneer Works · Kaleida Studio · The Prepared · Software Engineer (Contract)Built CRMs, ETL pipelines, and production-automation systems for arts & media orgs — APIs, data, and workflow tooling.
- Fall 2019Recurse Center · ParticipantStudied type theory in Haskell — making invalid states unrepresentable; the foundation for the contract/capability work now.
Education
- 2009 — 2012Bennington CollegeComputational & parametric design — algorithmic design for digital fabrication.
The corpus
Selected work
-
prxpinned
The agent-run work-unit CLI: capability-scoped agents whose every privileged effect is verified against its signed owner, driving a work unit through one signed pipeline to a merged PR.
-
guest-roompinned
Guest-agnostic room+door capability runtime — the core library claude-box is built on.
-
claude-boxpinned
A capability-secured box for agent sessions — its authority is the door references it holds (keeper/scout/concierge/net), parent-agnostic.
-
door-kitpinned
In-box door-client SDK for claude-box's capability doors (keeper/scout/concierge/spawn), over the guest-room protocol
-
dev-contracts-specpinned
Zod schemas and types for dev-contracts
-
bdelanghe-claude-skillspinned
Claude Code skills and plugins for AI-assisted engineering workflows
-
ssh-doctor
A Bash script that diagnoses SSH setup issues and provides streamlined troubleshooting 🩺🔧
-
site
robertdelanghe.dev — software-engineering portfolio (synoptic v2)
-
site
The bounded.tools website — static, built on @bounded-systems/brand
-
gh-project-room
Front Desk projection + sync room for bounded-systems (org project #2)
-
brand
Bounded Systems brand — W3C design tokens, self-hosted fonts, the mark, and ready-to-link CSS.
-
claude-token-tools
Claude Code token-saving toolkit — model-usage auditor + home-manager module