TULON
A secure data access platform for machine learning researchers
Context
The product handled sensitive hospital and research data; I co-founded it and owned design and engineering.
Problem
When researchers work with sensitive data, there was no systematic way to govern who could reach what.
How I solved it
- An early-stage startup would normally start simple, but the first deployments were already lined up with major hospitals, so the system had to hold from day one
- Shaped a domain-driven architecture and moved the platform to microservices accordingly
- Built the back office web service for data access governance
- Built server features: request and approval workflow, policy management, audit logging
- Built the isolated research environment for AI training data — automated VM provisioning and teardown, environment image templates, network isolation and firewall policy
- Built data egress control — blocked exfiltration paths, a review flow for releasing results, session activity logging and monitoring
- Integrated hospital SSO and managed VM resource quotas
Result
- Secured Samsung Medical Center as the first committed deployment
- Ran adoption discussions across all four major hospital groups in Korea
Impact
Adoption talks landed in healthcare, the domain with the strictest constraints.