Business development / service architecture / AI systems

From messy problems
to working systems.

I’m Janko Štrkalj. I turn ambiguous, high-stakes problems into systems people can actually act on: across AI, risk, security, and enterprise workflows.

janko / current_focus.yaml
# working at the seam between
problem: "too much signal, not enough decision"
current_builds: [Riskform, GRC Assistant, Evidence Manager]
domains: [AI, risk, security, GRC]
method: frame → model → build → test
bias: explainable systems over black boxes
status: shipping
How I work

I like the part before the obvious solution exists.

The useful work is usually not adding another dashboard. It is finding the decision hiding underneath the workflow, making the logic explicit, and designing a system that survives contact with reality.

01 / FRAME

Find the actual decision.

Separate symptoms from constraints. Map stakeholders, incentives, evidence, uncertainty, and where human judgment still matters.

02 / MODEL

Make the logic inspectable.

Turn tacit reasoning into policies, states, workflows, thresholds, and escalation paths that can be challenged and improved.

03 / SHIP

Build the smallest credible system.

Prototype the interface and operating model together. Test whether the decision gets faster, clearer, and easier to defend.

Current builds
Riskform / Risk Reduction Platform

Stop prioritizing vulnerabilities. Prioritize the work.

Riskform turns fragmented vulnerability and threat intelligence into explainable remediation campaigns: ordered by the risk they can remove and the effort required to remove it.

public data first policy as code explainable decisions campaigns, not CVEs
PRIVATE BUILD / NOT PUBLIC YET
INPUT NVD · CVSS · EPSS · KEV · threat intel signals
↓
POLICY taxonomy · scoring · grouping · planning explain
↓
OUTPUT remediation campaigns now / next / later
GRC Assistant / Private Build

Put AI inside the workflow, not on top of it.

GRC Assistant explores how cybersecurity maturity, assessments, controls, evidence, risk, and audit readiness can operate as one connected system, with humans retaining decision authority.

human in the loop structured evidence compliance as code AI-native workflows
PRIVATE BUILD / NOT PUBLIC YET
MODEL Maturity → Assessment → Controls structure
↓
EVIDENCE documents · validation · linked risks context
↓
DECISION risk · mitigation · audit readiness human-led
Evidence Manager / Private Build

Turn scattered files into connected, searchable context.

Evidence Manager is a private, AI-assisted workspace for organizing files, notes, references, and saved material into logical objects that can be searched, connected, and revisited by meaning instead of folder location.

local-first semantic search AI-assisted linking personal knowledge
PRIVATE BUILD / NOT PUBLIC YET
INPUT files · notes · links · screenshots · references collect
↓
AI LAYER extract · relate · cluster · describe connect
↓
OBJECT searchable evidence with context retrieve
A recurring theme

AI is most useful when it becomes infrastructure for judgment, not decoration around a workflow.

Across Riskform, GRC Assistant, and Evidence Manager, the interesting question is not “where do we put the chatbot?” It is how to structure evidence, context, dependencies, and human checkpoints so better decisions happen inside the workflow.

The common principle is simple: keep evidence attached to context, make relationships explicit, and reduce a large information space into something people can actually navigate and act on.

Proof of work

Less personal brand. More working surface.

What I’m building, how I think, and where to reach me.

Open loop

Working on a decision-heavy system?

Security, GRC, AI-assisted operations, enterprise workflows: if the problem is messy, cross-functional, and hard to make operational, that is usually the interesting part.