Jeevan Siddhabhaktula

Jeevan Siddhabhaktula

Risk · Governance · AI

I investigate freight and carrier fraud — missing trailers, phantom carriers, double brokering, insider collusion — across European and North American lanes. The tools below are what that work taught me, rebuilt in the open so anyone can check the reasoning rather than take my word for it.

Risk Manager at Amazon · Hyderabad, India · German A2, working toward B2 · EU work authorisation held, open to relocation across Germany

jeevansiddhabhaktula@gmail.com LinkedIn GitHub

One idea, three instruments why these fit together

Risk work fails in a predictable way: a threat gets named, everyone agrees it is serious, and nothing changes — because nobody wrote down which signals actually distinguish it from an ordinary bad day. So I built the layers in order.

  1. A data model. An open taxonomy of freight fraud patterns, where every indicator is weighted, stage-tagged, and paired with the innocent explanation that mimics it.
  2. An instrument on top of it. An assessment engine that turns what you can actually observe into a ranked, arguable finding — and refuses to call it a probability.
  3. The same discipline elsewhere. A control room that derives which AI regulations a system attracts, and holds the evidence behind every control.

Every tool here is static, dependency-free and run entirely in your browser. Nothing you type is transmitted, logged or stored.

Work live, not screenshots

Freight & carrier fraud

Freight & Carrier Fraud Risk Taxonomy

An open, structured taxonomy of fraud and cargo-loss patterns in European road freight — the reference layer everything else is built on.

The hard part: every pattern carries a false_positives block — the benign cause that produces the same signal, and the check that separates them. That is the part published threat lists leave out, and the part that decides whether an investigator trusts the model.

  • 12 patterns
  • 8 categories
  • 77 indicators
  • 31 documented false positives
  • 137 countermeasures
  • 11 public sources
  • CC BY 4.0

Freight Risk Atlas

An assessment engine over that taxonomy. Scope a movement, record what you can observe, and it tells you which patterns the evidence supports — with the false positives to rule out first and the countermeasures that still apply at that stage.

The hard part: it reports indicator coverage, never a probability of fraud, and it never counts Unknown as Absent — unknowns are reported as weighted evidence gaps with their own completeness score. A tool that quietly treats missing evidence as exculpatory is worse than no tool.

  • 77 indicators scored
  • coverage, not probability
  • 40% of detection weight lands after the loss
  • 86 automated assertions

FOMO — German logistics risk monitor

A standing watch on German and EU supply-chain risk news: cargo theft, phantom carriers, freight fraud, insolvency, regulatory change and disruption, in English and German.

The hard part: keeping it honest and cheap — public news feeds only, classified into risk themes, re-scanned every six hours by a scheduled job, with no scraping of anything that forbids it.

  • EN + DE sources
  • re-scans every 6h
  • zero infrastructure

ONE MORE SHIFT — a farewell arcade game

Flag or clear real fraud-taxonomy signals against a 60-second clock. All 108 cards — 77 real risk indicators, 31 real innocent explanations for them — are pulled straight from the taxonomy above, not invented for the game.

The hard part: pacing a deck that's 71% one card type without long same-answer streaks. The first version spent the scarcer card type on a random 65% roll whenever it wasn't strictly forced — which could burn through that pool early and leave nothing left to break a streak later. Fixed by rationing it: only ever spent when a streak actually needs breaking, never for variety.

  • 108 real cards, 12 patterns
  • seeded, reproducible decks
  • difficulty ramps mid-shift
  • 24 tests
  • works double-clicked from disk

Financial crime intelligence

RISK//RING — Financial Crime Network Intelligence

A trained fraud classifier with honest metrics, SHAP explainability, and graph-based collusion-ring detection — evaluated against known ground truth instead of asserted. Simulates a transaction network with injected rings running real FATF typologies (structuring, layering, round-tripping), because the standard public fraud dataset has no account IDs and can't support any network analysis.

The hard part: the first run scored 100% precision and recall — a sign the simulation was leaking, not a good result. Found the amount-distribution bug behind it, added deliberate false-positive pressure, and shipped the honest number instead: 0.82 precision at 1.0 recall. Community detection on a naive graph recovers rings but pulls in 90%+ unrelated accounts (0.07 precision); a documented resolution sweep gets that to 0.76 precision / 0.77 recall without hiding the trade-off.

  • 20 rings, 3 FATF typologies
  • 0.82 precision · 0.995 PR-AUC
  • SHAP on every flagged case
  • 0.77 recall / 0.76 precision ring recovery
  • 10 tests, zero backend

SHADOW//NETWORK — Persistent Fraud-Investigation Simulation

A synthetic freight-carrier economy that advances one real day at a time, watched by a BYOK AI investigator council. 120 carriers and 24 lanes drift, form collusion rings, and commit incidents drawn from real fraud patterns; an unattended scheduled job ticks the world forward, and a public leaderboard tracks the council's cumulative win rate against fraud it never gets to see labelled.

The hard part: the council reviews a redacted case brief, never the sim's own answer key — ground truth, pattern id and causal trace are stripped before an event ever reaches it, so a win is a real catch, not a lookup. A missing or failing API key degrades safely to a zero-cost rule-based reviewer instead of breaking the run, and the whole day-by-day history recomputes from one seed, so losing the data directory costs nothing but a script run.

  • 120 carriers, 24 lanes
  • 12 real fraud patterns, redacted case briefs
  • unattended daily tick, GitHub Actions
  • 80 tests, zero backend

Governance & compliance

AI Risk Control Room

A control room for an AI governance programme: an inventory of AI systems, the obligations each one attracts under the EU AI Act, GDPR, ISO/IEC 42001 and the NIST AI RMF, and the evidence behind every control.

The hard part: applicability is derived from each requirement's own conditions and never stored on a control, so one honest change to a system's purpose re-tiers it everywhere at once. 29 controls answer 70 requirement links; 8 of them satisfy three or more frameworks — evidenced once, reported four times.

  • 4 frameworks
  • 56 cited requirements
  • 29 controls
  • 84 evidence artefacts
  • 70 requirement links

AI Compliance Scanner

A fast self-assessment for a single AI system against three frameworks — the EU AI Act, ISO/IEC 42001 and the NIST AI RMF — each with its own independent score, in under ten minutes.

Not the Control Room, on purpose: the Control Room manages a whole programme's inventory over time; this answers one question quickly — where does this one system stand today? The EU AI Act path is a 4-step wizard whose risk questions each map to a specific article (5, 50, 51–55, Annex III), with a plain-English "explain why" behind every one.

  • 3 frameworks, independent scores
  • 14 risk-qualifier questions
  • NIST GOVERN·MAP·MEASURE·MANAGE
  • one-click HTML report
  • installable PWA, offline

GDPR Compliance Scanner

Screen any data file for personal data before you share, upload or archive it. It reads the file itself, in your browser, and flags which columns look like personal data and which GDPR article each one engages.

Deliberately a screening tool, not a verdict: it answers "what is in here that I should look at?", never "are we compliant?". A header pass and value-pattern detectors rank findings by severity and layer on ENISA severity, NIST impact and DPIA screening — so a human makes the actual call.

  • Excel · CSV · PDF · Word · images (OCR)
  • 9 value-pattern detectors
  • ENISA · NIST · DPIA screening
  • screening, not a verdict
  • installable PWA, offline

reg-search — BM25 Over 56 Cited Requirements

Natural-language search over the same 56 requirements behind the Control Room above, ranked by a BM25 implementation written from scratch — no embeddings, no external model, no API key. Type a plain question and see which article actually matches, and which exact terms earned it that rank.

The hard part: the honest limit of going lexical on purpose. Indexing the article citation itself (“Art. 72”) alongside the requirement text let the number in a query like “72 hours” false-match an unrelated article numbered 72 — found by running real queries against the live index before shipping, not by inspection. Fixed by indexing only title and summary; the citation stays display-only.

  • 56 requirements, 4 frameworks
  • BM25 from scratch, 14 tests
  • zero embeddings, zero API key
  • works double-clicked from disk

Latest regenerated every six hours from real activity

Latest commits

  • fraud-watch Autonomous world tick #16 (day 5)2026-09-26
  • FOMO Automated scan: 2026-09-26 11:09 UTC2026-09-26
  • jeevan-0508.github.io Refresh the activity strip2026-09-26
  • shadow-network Daily tick: day 52026-09-26
  • Jeevan-0508 docs: add HAKAI PROTOCOL card + policy-audit node in governance diagram2026-09-22

Freight risk signals from FOMO

Bot reports open findings across the 9 monitored repos, checked daily

  • No open findings across the 9 monitored repos — all clean.

How I verify this the part I would want to interrogate

  • Tested against the deployed site, not localhost. Every tool is checked by headless assertions run against its public URL, including an independent recomputation of its own arithmetic. A build that only passes on my machine has not been tested.
  • The data validates itself. Each repository ships a schema and a dependency-free validator that runs in CI and refuses a malformed model, so a bad edit fails loudly rather than rendering a plausible wrong answer.
  • No invented numbers. The atlas has no geographic heat map, because credible cargo-crime incident data is paywalled and I will not fabricate hotspots to make a page look better. Where a figure is modelled rather than observed, it says so.
  • Nothing employer-specific. No internal thresholds, no real carriers, no case data. The judgement is transferable; the confidential material stays where it belongs.

Background

Risk Manager at Amazon since 2021, on a central risk team handling carrier fraud investigations across EU and NA lanes — missing trailers, pilferage, identity fraud, double brokering, GPS spoofing and internal collusion — working with business conduct, insurance and worldwide operational security. Lean Six Sigma Black Belt.

Two numbers from that work explain everything on this page. The first is a ~40% reduction in EU and NA audit false positives, achieved by redesigning audit logic and exclusion rules — which is why every pattern in the taxonomy above carries a false_positives block, and why the Atlas refuses to treat missing evidence as exculpatory. The second is >$15M in model-based prevention impact from pattern analysis and control reinforcement, alongside a risk-forecasting engine at roughly 95% accuracy and reporting automation that removed about 90% of the manual effort.

The recurring lesson is the one these tools encode: the expensive failures are almost never a missing signal. They are a signal nobody could separate from noise in time to act.

Certifications — Lean Six Sigma Black Belt · Lean Six Sigma Green Belt · ISO 28000 Supply Chain Security · ISO 9001 Internal Auditor · AWS Certified Solutions Architect · Cybersecurity Foundations, University of London · Power BI / Data Analytics

I also write. A Conversation With Existence is a philosophical memoir, and it is here for the same reason the code is: I would rather be judged on things I actually finished.