Skip to content
Pierre Colart
fr

Pierre Colart

Senior AI/ML Engineer / Solution

Senior AI & Solution Engineer with 9+ years of experience designing secure systems and driving AI strategy. I lead POCs through to production and deploy responsible AI in regulated environments (SOC 2, GDPR), turning complex technical concepts into clear business value for non-technical stakeholders.

Experience

Passbolt

Status
present

Senior AI/ML Engineer / Solution

Period : 2022 — presentDuration : 4 yrs

Open-source password management solution used by governments and large organizations

  • Spearheaded the company’s AI strategy, from sales through to support — not engineering alone.
  • Trained twenty engineers in agentic development.
  • Rebuilt autofill for 500,000 users: authentication-form detection went from 60% to 90%.
  • Engineered the generative-AI data collection engine feeding the autofill and anti-phishing models.
  • Directed open-source AI penetration testing and automated SOC 2 audit campaigns, both built in-house.
  • Started the Windows application and owned its architecture, security model and delivery.
  • Traded off with the design team on what a desktop allows and a browser does not: Windows Hello moves the trust boundary before it becomes an interface opportunity.
  • Architected it in native UWP, then migrated it to Tauri 2: six months, four people.
  • Developed secure browser extensions with advanced cryptography (Node.js, React component library).
  • Managed the mobile team — five people — then the product team on the encryption product.
  • TypeScript
  • Node.js
  • React
  • Rust
  • Tauri
  • Generative AI
  • Developer tooling
  • Open source
  • JavaScript
  • Application security
  • Penetration testing
  • Cryptography
  • SOC 2
  • Anti-phishing
  • Browser extensions
  • PostgreSQL
  • Kotlin

Switch Case

Status
present

AI / ML Engineer

Period : Aug 2020 — presentDuration : 6 yrs 2 mos

Generative-AI products, automated security and large-scale RAG

  • Product AI: designed and industrialised a generative-AI data collection engine used to train and deploy autofill and anti-phishing models built from scratch.
  • Argus: autonomous LLMs crawl the web for sensitive pages, authentication and payment forms, driven by a browser extension exposed over MCP.
  • Kept labelling deterministic by design: the model applies written rules and explains what it could not classify. It does not decide.
  • Turned that dataset into a model that recognises a sensitive zone, a password field or an authentication form: it feeds autofill and warns before credentials reach a malicious site.
  • Rebuilt Passbolt’s autofill on it: in-page detection of authentication forms went from 60% to 90%, for 500,000 users.
  • Sirius, same architecture: phishing-site capture, ML and LLM categorisation, image inference, fraudulent site and email detection.
  • Started both from a personal roadmap and kept ownership of them: Passbolt runs Argus and Sirius as an external tool, and uses their data twice over, to train its models and to decide which autofill features come next.
  • Split the runtime on load rather than preference: AdonisJS where the product lives, Rust for the ingestion pipeline, the virtual machines and inference.
  • AI-driven security: autonomous agents orchestrating security scanners for automated penetration testing, plus automated SOC 2 audit campaigns.
  • RAG solution over millions of rows, for a medication reimbursement platform: a CSV of medications crossed with the written law that governs reimbursement, two sources sharing no structure.
  • Escalation to a human expert by design: on critical medications, the expert answers, not the model.
  • Proved the concept on N8N / Supabase, then rewrote it on Mastra, Rust back end and React front end.
  • Gated every release behind a parallel test pipeline checking answers against defined rules.
  • Made re-indexing unattended: dropping a new CSV or a legal text in the admin interface re-runs the embedding pipeline into the vector stores on its own.
  • Author of the AI and machine learning R&D articles published on the blog.
  • Python
  • Rust
  • Go
  • Mistral AI
  • Open-source LLMs
  • Autonomous agents
  • Agent orchestration
  • MCP
  • Mastra
  • Embeddings
  • Vector databases
  • TensorFlow
  • PyTorch
  • Supabase
  • Penetration testing
  • Application security
  • SOC 2
  • RAG
  • React
  • Next.js
  • Anti-phishing
  • Browser extensions
  • PostgreSQL

ColartBe

Freelance — Project delivery

Period : 2017 — 2025Duration : 8 yrs

End-to-end delivery for European institutions, startups and SMEs

  • Eight years of engagements taken from scoping through to production, with full ownership: architecture, development, deployment and handover to the client’s team.
  • Two main areas: AI applied to sensitive data for European institutions, and connected systems for consumer products.
  • Sole technical counterpart for non-technical business teams, from the first scoping workshop through to acceptance testing.
  • Java
  • Rust
  • React
  • React Native
  • NestJS
  • TensorFlow
  • Mistral AI
  • IoT
  • PostgreSQL

Miind

Solution Architect

Period : 2022 — 2022Duration : 1 yr

National customs delivery system

  • Traced parcel origin and routing for Belgian customs, under a new European regulation.
  • Architected the real-time layer on Kafka, sized for the volume of small parcels shipped from China.
  • Defended the application and cloud architecture to the government’s own architects, then built the back end.
  • Java team lead for a team of 8 developers split between Belgium and India.
  • Java
  • Spring
  • Kafka
  • Angular
  • Cloud
  • PostgreSQL

Solution Architect

Period : 2020 — 2022Duration : 2 yrs

Open-banking infrastructure for financial institutions

  • Architect responsible for the online payment systems now used by every Belgian, Luxembourg, French and Dutch bank, part of the German ones, with PayPal among the clients.
  • Sized them to absorb a full day of payments, without choosing which ones matter.
  • Built the financial API marketplace: aggregators reuse one bank’s API instead of integrating each bank separately.
  • Built the single entry point normalising bank systems that shared no common access, under the PSD2 obligation to open their APIs.
  • Ran it on AWS, continuous integration and delivery included.
  • Developed Anti-Money Laundering (AML) models.
  • Defined integration and security standards in collaboration with client institutions.
  • Supervised five developers directly, reporting to the CTO, on critical banking systems.
  • Java
  • Spring Boot
  • Vue.js
  • Strapi
  • AWS
  • CI/CD
  • API design
  • Payments
  • PSD2
  • AML
  • PostgreSQL

Positive Thinking Company

Full-stack Engineer

Period : 2018 — 2020Duration : 2 yrs

Investment fund calculation and ingestion systems

  • Architected the fund calculation engine under the MiFID II real-time reporting obligation, at fund / sub-fund / share class granularity.
  • Produced the regulatory deliverables EPT (European PRIIPs Template) and PRIIPs KID.
  • Built the daily deposit chain European financial institutions file through: ingestion, verification and calculation, from its start.
  • Built a configurable ingestion engine absorbing hundreds of non-standard deposit formats, with no per-client connector.
  • Ran the ingestion chain on Kafka, .NET and Java stacks side by side on the same flow.
  • Served a large share of the major Luxembourg banks, on the Kneip engagement.
  • Technical lead for an internal team of 10 Java/JavaScript developers, running technical interviews and training.
  • Java
  • .NET
  • Kafka
  • Angular
  • Vue.js
  • MiFID II
  • GraphQL
  • PostgreSQL

Projects5

European Commission — Sovereign RAG agentfeatured

Secure local deployment of a large-scale RAG system over sensitive documents

Designed and deployed a large-scale RAG agent built on open-source models (Mistral AI) and vector databases.

No outbound calls: all processing stays on-premise, embeddings included, on infrastructure the client administers itself. GDPR compliance is structural, not declarative.

The difficulty is shape, not volume: millions of medication rows in CSV on one side, a written rules document on the other, to be crossed before a reimbursement can be decided.

Escalation to a human expert on the cases the model cannot settle. Every release first goes through a parallel test pipeline checking answers against defined rules.

  • Mistral AI
  • Rust
  • Mastra
  • Embeddings
  • Vector databases
  • RAG
  • On-premise

European Commission — Sovereign video conferencingfeatured

Self-hosted real-time platform, up to 300 participants

Architected a self-hosted video conferencing platform for entrance exams and remote teaching: no data leaves the Commission’s infrastructure, up to 300 participants per call.

Designed the whole system, server architecture plan included. Real-time messaging on RabbitMQ, event-driven, with a browser client served from the Commission’s own page.

  • WebRTC
  • Java
  • React
  • RabbitMQ
  • Real-time

personal-cv

2026This site — markdown content, continuous deployment

Bilingual static site generated from markdown files validated by a Zod schema. Every push to main triggers the build and publish. A print stylesheet produces a clean PDF from the same source.

  • Astro
  • React
  • Tailwind
  • GitLab CI

Cinextra — Ticketing and venue automation

Website, cash registry and IoT-driven screening control
  • Ticketing site wired to the till: online booking and on-site purchase draw from the same seat stock.
  • Transactional integrity on a unique resource: two buyers cannot obtain the same numbered seat.
  • Delivered ticket counts to some fifty film suppliers, each in its own format — API or CSV.
  • Automated the venue: screening playback and lighting, through IoT devices and wired systems.
  • Python for automation, Java for the rest — a deliberate call.
  • Screening forecasting model to support programming decisions.
  • Java
  • Spring
  • Angular
  • Python
  • Cloud
  • Concurrency
  • IoT
  • Forecasting
  • MongoDB

Domecho — Smart-home AI platform

Home automation predictions, OCR and visual analysis models
  • Self-hostable alternative to Home Assistant: any platform, any connected device.
  • Real-time learning from usage, crossed with the calendar, to suggest routines — preheating a room on a day off.
  • Self-hosted Llama LLM executing functions, written before function calling existed as an API feature.
  • Voice assistant on Mozilla TTS: speech, reasoning and execution with no third-party dependency.
  • Face recognition on the entrance camera, wired to the alarm: a recognised face carries its own PIN.
  • Platform hosted on Google Cloud.
  • Integration of Zigbee, Z-Wave, Bluetooth, Thread and WiFi devices.
  • TensorFlow models for home automation predictions, alongside OCR and visual analysis.
  • Web application (React, NestJS), mobile app (React Native), Python service for the devices.
  • TensorFlow
  • Llama
  • Mozilla TTS
  • NestJS
  • React
  • React Native
  • Python
  • Google Cloud
  • Zigbee
  • Z-Wave
  • Thread
  • MongoDB

Education

Generative AI for Cybersecurity Specialization

Jul 2026
Institution
LearnQuest

Cyber Security with AI Specialization

2025 — 2026
Institution
Macquarie University

Deep Learning Specialization

2023
Institution
Stanford University

Bachelor of Computer Science

2014 — 2018
Institution
HELMo — Liège, Belgium

Certifications

Certified Kubernetes Administrator (CKA)

Sep 2026
Issuer
The Linux Foundation — Pearson VUE
Credential ID
Credential ID : 5XFRKKD2NBJX

AI Agents for Cybersecurity

Jan 2026
Issuer
Starweaver
Credential ID
Credential ID : A9JTQTYAQUEQ

Google Cybersecurity Professional Certificate

Jan 2024
Issuer
Google
Credential ID
Credential ID : 186ef7aaae358de22c0c3764f03b49d5

TensorFlow Developer Professional Certificate

Jul 2023
Issuer
DeepLearning.AI
Credential ID
Credential ID : DHWZJ5GS8V7S

Skills

Backend
  • TypeScript
  • Java
  • Rust
  • C#
  • Python
  • Go
  • NestJS
  • Spring Boot
Frontend
  • React
  • React Native
  • Angular
  • Vue.js
ML / AI
  • TensorFlow
  • PyTorch
  • RAG systems
  • Autonomous agents
  • MCP
  • Mastra
  • Mistral AI
  • Llama
  • Ollama
  • Vertex AI
Security
  • SOC 2 / GDPR compliance
  • Cryptography
  • Anti-phishing
  • Risk analysis
  • Zero-trust architecture
Regulated domains
  • PSD2
  • MiFID II
  • PRIIPs / EPT
  • AML
  • Customs
Cloud & data
  • Vector databases
  • PostgreSQL
  • Kubernetes
  • Observability
  • Performance engineering
  • Kafka
  • RabbitMQ
  • AWS
  • Azure
  • Google Cloud
  • Docker
  • CI/CD
Languages
  • French — native
  • English — fluent (C1)
  • Dutch — basic
fr
⌘KOpen