52.37°N 4.89°E · Netherlands · CTO / Gysho · Founder / WinkIT

I build AI systems in production, and the governance that keeps them trustworthy.

Thomas Wink. Twenty years turning hard problems into calm, well run systems. I started in web development and Linux operations, moved through security, and now lead engineering as a CTO. Today I ship bespoke enterprise AI and build the guardrails around it.

0+
Years shipping software
0+
AI systems delivered
27001/42001
ISO frameworks audited
Self‑host.
GPU inference, EU data
01

At the helm

Where my time and judgment go right now, and where I think this is all heading.

Right now I am CTO at Gysho, a fractional AI team that builds bespoke enterprise systems. My job is to take a clean sheet idea and turn it into governed, production software quickly, then make sure it stays trustworthy as it grows.

I think the next few years belong to the teams that can build AI fast and prove it is safe at the same time. Speed without governance is a liability. Governance without speed is a museum. The interesting work, and the work I care about, is holding both at once.

  • 01 Composable AI platforms clients own outright
  • 02 Multi agent delivery at senior quality
  • 03 ISO 27001 and 42001 as a default, not a project
  • 04 Keeping sensitive workloads on EU infrastructure
02

What I do

Six things I am trusted to own end to end, from architecture down to the failure modes nobody wants to think about.

A1

AI systems in production

LLM and RAG products that survive contact with real data. Document intelligence, retrieval over vector search, OCR, real time speech agents. The hard part is not the demo, it is the day it goes live.

LLM / RAGVector searchSpeech
A2

AI augmented delivery

A team coding method where AI agents work to contracts in parallel waves, with code review, security review, and testing gates between each wave. Senior judgment sets the design, agents do the typing.

OrchestrationContractsQA gates
A3

Security engineering

Trust boundaries drawn on purpose. Verified RS256 tokens instead of assumed origins, PII redaction before anything reaches a model, and per tenant data isolation threaded end to end as the default, not a bolt on.

AuthN / AuthZPII redactionIsolation
A4

AI governance and compliance

Evidence based audits against ISO 27001 and ISO 42001, with EU AI Act awareness built in. Not a checklist theatre, but risk scored findings backed by runtime proof and a report a board can act on.

ISO 27001ISO 42001EU AI Act
A5

Self hosted AI infrastructure

An OpenAI compatible inference stack running on our own GPUs with cloud fallback, so sensitive workloads never leave our infrastructure. Data sovereignty as an architecture choice, not a marketing line.

InferenceRoutingSovereignty
A6

Production reliability

Retries with backoff, circuit breakers, job queues with heartbeat and stale detection, and long running work that a user can always cancel. The unglamorous engineering that decides whether people trust the thing.

ResilienceQueuesObservability
03

Selected work

A few of the more complex systems I have led. Clients kept general, the engineering described honestly.

Role ▸ Architect & lead European construction
and engineering groups

Requirements intelligence platform

A system that reads large contract and specification documents and scores each requirement against evidence. The complexity lived in the pipeline: OCR and parsing of messy source files, retrieval over a vector store, a multi stage LLM scoring flow, and an adaptive concurrency queue to stay inside provider rate limits. I built a statistical evaluation harness so quality was measured across runs, not guessed at.

Azure OpenAIRAGOCRJob queueMeteor / React
Role ▸ Architect & lead Global negotiation
training firm

Real time AI negotiation trainer

A platform where sales teams rehearse against an AI buyer that talks back. The complexity was the real time loop: speech to text, a reasoning layer grounded in the client's own methodology through retrieval, then text to speech and a speaking avatar, all in the browser and embedded into their CMS through verified tokens. It also scores each session against the methodology, so learners get feedback rather than just a conversation.

Azure SpeechWebRTC / avatarRAGRS256 JWTMeteor / React
Role ▸ CTO, built the system Gysho engineering

Automated our development workflow

I turned delivery itself into a repeatable system. A developer hands a design spec to a multi agent team coding workflow that plans the work, splits it into contracts, builds in parallel waves, and runs code, security, and UX review between each wave. It lets other developers ship whole projects from a spec at senior quality, without me in every loop. This is how a small team delivers like a much larger one.

Multi agent orchestrationDesign to buildContracts & wavesQA gates
Role ▸ CTO, technical owner Gysho composable
AI platform

Composable enterprise AI backend

As CTO, the backend behind a fractional AI team: a modular set of services for authentication, chunking, embeddings, vector storage, and model routing, assembled per client rather than rebuilt each time. Governance and per tenant isolation are designed in from the first sprint, so a proof of concept can grow into production without a security rewrite.

Modular servicesKey VaultSSO / Entra IDGovernance by default
04

How I work

A short version of the principles I keep coming back to, whether I am writing code myself or directing a team of agents.

  1. P1

    Verify against reality

    I trust the running system over the diagram. Before I form a theory I check the actual state: the database, the API response, the file on disk. Silent success gets treated as a failure until it is proven otherwise.

  2. P2

    One coherent fix, not a pile of patches

    When a problem crosses layers I trace it end to end and design a single fix, rather than patching each symptom where it happens to show. Layer by layer patches hide the root cause and quietly seed the next bug.

  3. P3

    Governance from the first sprint

    Security, data isolation, and auditability belong in the design, not in a phase at the end. It is far cheaper to build a system that can be certified than to retrofit one that cannot.

  4. P4

    Right size the effort

    The best engineers know when to stop. I push back on over engineering as hard as on under building. The target is the simplest system that is correct, resilient, and honest about its limits.

  5. P5

    Ship, then show

    People should see working software early and often. Real projects change the moment someone can click on them, so I build in a way that welcomes that instead of resisting it.

05

Perspective

Writing on where enterprise AI is going, from the Gysho business enablement blog.

06

About

The short version of a long path, and the reason a navigation chart runs down this page.

I have been building on the web for more than twenty years. I started as an early web developer and a Linux systems administrator, which is where I learned that the interesting failures live in operations, not in the happy path.

From there I moved through security and into full stack development, and over the last few years into AI engineering and the governance around it. The through line has always been the same: understand the whole system, verify it against reality, and leave it calmer than I found it.

I sail. A navigator reads the instruments, plots a course, and keeps a steady hand when the weather turns. That is more or less how I like to run engineering too, which is why this page is built as a passage rather than a pitch.

07

Plot a course together

Building something ambitious with AI, or want a second set of eyes on the governance around it? Send a note.