⬇ Download as Word (.docx)
THERIGHTHEMISPHERE
Software studio — code review, backend security testing & auditing, full-stack development, HTML5 games, game audio.
Portfolio: https://codeberg.org/Caemulus/code-review-portfolio
Live, in production (37 shipped games): https://morrigan-games.pages.dev
HOW WE WORK
TheRightHemisphere is run by Caem, who owns and is accountable for every deliverable. Work is produced with AI specialists under his direction, then passes a machine-enforced, two-auditor / four-pass security review before it ships. The process is AI-assisted, human-directed, and machine-audited — and the final result is his responsibility, not a tool’s.
We say this plainly because it is a strength, not a footnote: our review pipeline is enforced by a gate that refuses to release work without a signed audit artifact covering that exact revision. Most freelance code review is one person and a linter. Ours is a documented process with evidence attached.
CAPABILITIES
- Backend security testing — authentication, sessions, authorization, rate limiting, input handling, secret management, API surface
- Security auditing — code review with file:line evidence, severity rating, and a concrete fix plan; dependency and supply-chain review; leak and exposure analysis
- Production-grade delivery — everything we list is running in production and publicly verifiable, not demonstrated in a sandbox
- Full-stack development — Cloudflare Workers, D1, KV; auth, sessions, leaderboards, payments-adjacent backends
- HTML5 game development — original art direction and procedural music; web, mobile-web, itch.io and portal-ready packaging
- Game audio engineering — adaptive WebAudio synthesis, arrangement, SFX palettes
- Infrastructure & DevOps — hardened Tor/onion deployment, CI-style publishing pipelines, cross-platform build automation
- Multilingual delivery — reports and listings in EN / FR (Québec conventions) / ES / DE
CAEM — Principal
Direction, architecture, final judgment and accountability for every deliverable.
- Owns and signs off all work; accountable for any error or inaccuracy, regardless of tooling
- Sets and enforces the studio’s review standard: two auditors, four passes, no release without a signed audit covering the exact code revision
- Multilingual client delivery (EN / FR / ES / DE)
MUNINN — AI Specialist — Engineering & Security Auditing
Full-stack development, code review, backend security testing, publishing operations.
- Security code review & vulnerability auditing — published portfolio review (1 High: CORS reflect-plus-credentials; 4 Medium; 5 Low), every finding with file:line evidence: https://codeberg.org/Caemulus/code-review-portfolio
- Backend security testing — auth and session handling, authorization gaps, rate limiting, input validation, secret exposure
- Full-stack development in production — arcade account backend (Cloudflare Workers + D1 + KV): authentication, sessions, leaderboards. 16/16 integration tests passing against the live production deployment.
- Production hardening — found and remediated a live exposure in a public repository (reconnaissance data served at a public URL); fixed at the tip, purged from full git history across every branch, verified from a clean clone
- Machine-enforced audit gate — built the gate that refuses to release code without a signed audit artifact covering that exact revision. Nine test cases, all passing.
- HTML5 game development — 37 finished, packaged, live games (verified zips, per-game metadata, itch.io upload-ready)
- Procedural music engines — 50+ deployed game themes via a zero-dependency WebAudio engine
- Infrastructure & DevOps — hardened Tor/onion deployment, CI-style publishing pipelines, cross-platform build automation
LUMEN — AI Specialist — Security Auditing & Backend Testing
Security auditing, backend testing, hardening, financial analysis.
- Security auditing with real findings — audited a live production codebase and found a genuine leak: reconnaissance data (host layout, key paths, local ports) committed to a public repository AND served live at a public URL. Remediated at the tip, purged from full history across all branches, verified from a clean clone. Audit artifact and evidence committed.
- Adversarial review of security tooling — reviewed a release gate and found two real defects, one of which would have blocked every legitimate release permanently. Both fixed, six test cases added, behaviour independently verified.
- Backend security testing — authz/authn gaps, injection, secret handling, endpoint exposure, dependency and supply-chain risk
- Container & infrastructure hardening — image scanning, least privilege, egress control, audit logging
- Professional toolchain — Semgrep, Trivy, Gitleaks, osv-scanner, SBOM pipelines
- Trading / finance / business analysis — quantitative finance and open-source fintech architecture (payment systems, trading toolkits, compliance layers)
IRIS — AI Specialist — Game Design & World-Building
Game systems, narrative, art direction.
- HTML5/JS game development — co-created 37 shipped games (verified zips, upload-ready)
- Game math & systems design — casino-style wheel tuned to a documented, verifiable 96.3% RTP
- World-building & narrative design — authored full world lore with an interconnected cast across the game roster; character canon for the fighting title
- Art direction & art pipelines — full art bible: per-game background/hero/keeper prompts, style guides
KLELIA — AI Specialist — Audio Engineering & Composition
Game audio, arrangement, synthesis.
- Procedural/adaptive game music — 50+ deployed themes, each with a unique root/scale/wave fingerprint across 37 live titles: https://morrigan-games.pages.dev
- WebAudio synthesis engineering — pure-synth audio (zero audio files): excite/drift/pulse adaptive hooks live in the engine
- Sound arrangement — per-game sound palettes with SFX ducking and a shared loudness floor, phone-speaker-verified
- Mixing/mastering — studio methodology with an honest-craft clause (we tell you when a take needs work — that is the service)
- Honest note: record mixing/mastering (vocals/full songs) has no public case study yet — game audio is the published proof.
GIG LISTINGS
Gig 1 — Code Review, Backend Security Testing & Audit
Basic $25 (up to 1k lines, 2 days) · Standard $60 (up to 5k lines + security audit + fix plan, 3 days) · Premium $150 (up to 15k lines, deep audit, 4 days)
Manual line-by-line review plus an automated toolchain (Semgrep / Trivy / Gitleaks / osv-scanner). Backend security testing of auth, sessions, authorization, rate limiting and input handling. Findings delivered with file:line evidence, severity ratings and a concrete fix plan. EN/FR/ES/DE. Sample: https://codeberg.org/Caemulus/code-review-portfolio
Gig 2 — Backend Security Testing & Hardening
Targeted testing of a live or pre-launch backend: authentication and session handling, authorization boundaries, injection and input validation, secret management, endpoint exposure, dependency and supply-chain review. Delivered as a findings report with severity ratings, reproduction notes and remediation guidance — plus a re-test after your fixes.
Gig 3 — HTML5 Game Development (Iris + Muninn + Klelia)
Original games (no clones, no IP exposure) with original art direction, procedural music and documented game math. 37 shipped, live titles as proof. Web and mobile-web, itch.io / portal-ready packaging.
Gig 4 — Game Music & Sound Design (Klelia)
Procedural or composed game themes, adaptive audio systems (WebAudio), full sound arrangement with an SFX palette. Live proof: 50+ themes across 37 titles.
HOW WE DISCLOSE AI
We use AI specialists to produce work, under human direction, with a machine-enforced audit before anything ships. Caem owns and is accountable for every deliverable. If you would prefer work produced without AI, tell us before the order and we will say honestly whether we are the right fit.
STUDIO RULES (our guarantees)
- Honest copy — no fake credentials, no inflated findings
- Client code stays isolated and is never retained after delivery
- Only open-source reviews are ever published as public samples
- Every deliverable is security-checked before handoff