Ibrahim Waziri Jr’s new company is built around a problem he has worked on for years: turning dense regulatory text into something software can act on. His earlier projects show where the idea came from.
This summer, Ibrahim Waziri Jr left Google Cloud to found Bitsfront, a company he describes as building AI-native threat intelligence and cyber governance infrastructure. His LinkedIn profile says it is aimed at regulated industries in growth markets. In his Georgia Southern alumni profile, published in early August, he already lists himself as its founder and chief executive.
Public details on Bitsfront are limited at the time of writing. The company’s own materials and Waziri’s profiles describe its direction, but independent coverage of its products, customers and funding is not yet available. His LinkedIn profile names Mariojose Palma, a former Microsoft colleague, as co-founder and chief technology officer.
The premise is easier to judge against his record. Bitsfront’s stated territory, governance and threat intelligence for regulated sectors follows a line of projects that began at Microsoft and matured in a Washington think tank.
A Pentagon approval, written in OSCAL
The earliest of these is the eMASS approval announced in June 2021. As Waziri described it, the Defence Department approved Microsoft’s access to its authorization system after Azure’s security plans were translated into a machine-readable format using NIST’s OSCAL standard, with help from the Defence Information Systems Agency and Booz Allen Hamilton. The result was that defence customers could request inherited security controls for Azure directly through eMASS.
“Rules as code”
In July 2025, Waziri wrote an op-ed for CyberScoop arguing that a June 2025 White House executive order signalled a shift toward machine-readable policy. He noted that the order directs the National Institute of Standards and Technology, the Cybersecurity and Infrastructure Security Agency and the Office of Management and Budget to pilot machine-readable federal cyber policy within a year, and that agencies would eventually be able to buy only consumer internet-of-things products whose Cyber Trust Mark could be parsed automatically, from January 2027. Organizations that sell to government, he wrote, would need to show that their controls are enforced through machine-readable rules. He closed with a line that reads as a mission statement: “The future of cyber and AI governance won’t be documented; it will be deployed!”
GovSCH
That project was GovSCH, short for Governance Schema. Waziri built it as a 2025 #ShareTheMicInCyber Fellow at New America, a Washington think tank. He was one of eight fellows in the programme’s third cohort, announced in January 2025. His stated aim was a toolkit to translate regulatory requirements into terms that engineering teams could act on.
The report, published on 28 October 2025, addresses a gap he identifies between existing standards. NIST’s OSCAL describes security controls in machine-readable form, but there is no standard format for authoring the high-level documents that come before controls: executive orders, frameworks and laws. GovSCH is an open-source answer, made up of three schemas written in JSON and YAML. One covers U.S. executive orders, one covers cybersecurity and risk frameworks, and one covers international data protection regulations.
To build it, Waziri reviewed source documents by hand and used the AI models GPT-4.5 and Gemini-Ultra to cross-check the patterns he found. The sample set included three U.S. executive orders (EO 14028, EO 14144 and EO 14306), the NIST and Defence Department risk management frameworks, and the GDPR, Brazil’s LGPD and China’s PIPL. The code is on GitHub under New America’s organization.
The report is candid about its limits. GovSCH is not a compliance tool and offers no legal advice; its design is shaped mainly by U.S. executive orders and NIST frameworks, and testing it in live use or through formal standardization is left to future work. Independent evidence of adoption was not available at the time of writing.
On stage and on air
Waziri has presented the ideas at conferences. On 1 May 2025, he spoke at the RSA Conference in San Francisco on bridging cybersecurity governance and engineering, on behalf of #ShareTheMicInCyber alongside Katelyn Ringrose and Camille Stewart. In August 2025, he appeared on the GRC Engineer podcast, hosted by Ayoub Fandi, to discuss GRC engineering in the public sector; the show notes point to OSCAL, NIST SP 800-53, FedRAMP, the Defence Department’s risk management framework and the Cloud Security Alliance’s controls matrix.
At RSAC 2026 on 24 March, he presented with Abhilasha Bhargav-Spantzel, a Microsoft partner security architect who also holds a Purdue doctorate. Their session dealt with identity verification and AI, including deepfake fraud and algorithmic bias, and offered a governance framework for high-stakes systems. Waziri has said on LinkedIn that attendees voted it a top-rated session. The pair later wrote an RSAC article, “The Death of Human Verification: Why Trust Must Move Beyond Detection,” arguing that identity checks should rest on cryptographic proof rather than on people spotting fakes.
He was also billed as a confirmed speaker, as founder and CEO of Bitsfront, at the 18th ISACA Nigeria Chapters Annual Conference (ANNCON 2026) at the Shehu Musa Yar’Adua Centre in Abuja on 24 to 26 August. The conference theme was “Reimagining Trust in the Age of AI,” and his session was billed as “Tilt the Screen: Transparency, Trust and Innovation in the Age of AI.”
Nigeria
His Nigerian work runs alongside all this. Waziri has written about Nigerian cybersecurity policy since at least 2017, including blog posts arguing for a national cybersecurity agency. He contributed a chapter, “Safeguarding Nigeria’s Digital Development Efforts,” to Remaking Nigeria: Sixty Years, Sixty Voices (2020), edited by Chido Onumah. In 2024, he joined the federal Digital in Health Initiative committee, described in more detail in this series.
Recognition
– Phi Kappa Phi, Georgia Southern University, inducted 2013.
– Daniel and Martina Lewis Graduate Assistantship Award, Purdue University College of Technology, 2015.
– Top 50 Information Security Professional, 2021, named by OnConferences, according to his alumni profile.
– #ShareTheMicInCyber Fellow, New America, 2025 class.
– 40 Under 40, Class of 2026, Georgia Southern University Alumni Association. Honorees are nominated by others and chosen by a selection committee; self-nomination is not permitted.


