It started with a dinner invitation in Dandong.
In 2014, my parents—Kevin and Julia Garratt, Canadians who had lived and worked in China for more than thirty years—were asked to meet someone to discuss a friend's daughter studying abroad in Canada. The conversation never happened. Instead, my father was pulled into one black sedan by plainclothes officers. My mother was forced into another. There were no goodbyes. No warrants read aloud in any meaningful way. Just the sudden, terrifying realization that their ordinary lives had become leverage in a much larger geopolitical game.
They were accused of espionage. My father was later formally charged with stealing state secrets. The charges were absurd. My parents ran a coffee shop popular with Western expats and tourists near the North Korea border while quietly continuing aid and community work they had done for decades. They were not spies. They were pawns—detained as retaliation after Canadian authorities arrested a Chinese national accused of cyber-espionage against American defense contractors.
My mother was eventually released on bail after several months. My father remained in detention for a total of 775 days before finally being deported in September 2016. They documented the full, harrowing experience in their book, Two Tears on the Window. I encourage anyone who wants the complete human story to read it.
I know this chapter of our family history not as distant news, but as something that unfolded while I was already building my own life and career across Vancouver, Beijing, and the broader Asia-Pacific region I had called home for 22 years. As their son, I advocated publicly and privately for their release. I spoke with media. I engaged officials. I watched how opaque systems, selective narratives, and the absence of transparent, verifiable evidence could be weaponized against ordinary people.
That experience never left me. It became part of the lens through which I see power, surveillance, information control, and—most importantly—the critical importance of evidence-grade truth in any high-stakes environment.
The Through-Line to Cybersecurity
Fast-forward to 2024–2025. After founding, scaling, and successfully exiting Spark RE Technologies—a real estate technology platform that grew to serve thousands of professionals and generated millions in revenue—I made a deliberate pivot.
I chose to go deep into security research and AI-powered intelligence systems. Not in spite of what my family went through. Because of it.
The modern attack surface looks nothing like a dinner setup in Dandong, but the underlying dynamics are hauntingly familiar: Adversaries who operate in the shadows. Supply chains and third-party relationships used as vectors of compromise. Sophisticated tradecraft designed to evade detection. The weaponization of information and narrative when hard evidence is inconvenient. Ordinary organizations and individuals left exposed while powerful actors play larger games.
State-sponsored threat actors (and sophisticated criminal groups mimicking them) routinely exploit software supply chains, living-off-the-land techniques, and multi-stage exploit chains that traditional point-in-time scanners completely miss. They map your attack surface better than you do. They generate "evidence" on their own terms when it serves them. I decided to build the opposite.
What is SCAFU, and why was it built?
SCAFU (sca-fu.com) is an AI-native security intelligence platform architected to discover vulnerabilities that conventional tools overlook, trace them through full supply chains, and produce evidence-grade documentation. I built it because high-stakes environments—whether bug bounty programs, legal counsel, or executive decision-making—require findings that hold up under adversarial scrutiny, not just static noise.
How does SCAFU differ from traditional security scanners?
Unlike traditional sequential scanners, SCAFU relies on a privacy-first, context-aware architecture designed for evidence-grade outputs:
- Context-aware, multi-agent orchestration: Instead of running static scans in sequence, SCAFU deploys 16+ specialized intelligent agents that coordinate in real time. Pre-scan reconnaissance identifies your exact tech stack, cloud providers, WAFs, and security controls. Payload generation agents then craft framework-specific attack vectors. Validation agents dramatically reduce false positives while mapping realistic exploit chains—often 3–5 steps deep.
- Supply chain and platform-level visibility: Most scanners stop at your perimeter. SCAFU maps outward—connecting domains to vendors, vendors to affected organizations, and exposures to real business and compliance risk. This is critical in an era where the majority of major breaches originate in the extended supply chain.
- Evidence-grade outputs: Every finding comes with verified exploitation paths, business impact analysis, regulatory mapping, and framework-specific remediation code. These are reports you can hand to legal, leadership, or a bug bounty platform with confidence.
- Privacy-first architecture: Security-critical work happens locally with on-prem or self-hosted models where it matters most. Your sensitive targets and data never leave your control unnecessarily.
Traditional vulnerability scanners were built for a different era. They generate noise. They miss context. They produce findings that fall apart under adversarial scrutiny. In high-stakes environments—especially those touching critical infrastructure, regulated data, or international operations—that is no longer acceptable. SCAFU was built for the world I actually live in.
Why Lived Experience Matters
There is a reason I care so deeply about defensible evidence and supply chain truth. I watched a sophisticated state security apparatus apply classic intelligence tradecraft against my own parents: prolonged, repetitive interrogation designed to induce inconsistency; total environmental control; the slow erosion of agency; and the construction of a narrative that served geopolitical objectives rather than facts.
I also saw what it took to push back: relentless focus on verifiable details, building credible coalitions, understanding the opponent's incentives and playbook, and refusing to let narrative replace evidence. Those same muscles are required in modern cybersecurity.
When I contribute to bug bounty programs or conduct security research, I bring the same standard: findings must be real, reproducible, and documented in a way that cannot be easily dismissed. When I architect systems like SCAFU or explore adjacent platforms (Nuculair for OSINT enrichment, AURA for intelligent outbound workflows), the north star is always the same: reduce asymmetry. Give defenders—especially those without nation-state resources—the tools to see what attackers already see, and to prove it with evidence that stands up.
What is the operating philosophy behind these systems?
My core architectural philosophy is that in a world full of noise, narrative, and asymmetric power, what you can actually prove matters more than what you can claim. Whether I was building real estate technology that actually solved brokers' daily frustrations, advising companies on product and market strategy, or now shipping security intelligence platforms, the principles remain unchanged:
- Solve real problems, not imagined ones.
- Privacy and defense-in-depth are non-negotiable requirements, not features.
- Ship, gather real feedback, iterate rapidly.
- Bridge domains—lessons from one field illuminate problems in another.
The family ordeal reinforced something deeper. It is the operating philosophy behind everything I build.
Closing Reflection
My parents survived 775 days of detention, interrogation, and political theater by holding onto what was true and refusing to surrender their agency or their story. I try to honor that legacy by building systems that make truth easier to surface and harder to obscure—especially when the stakes involve real data, real organizations, and real people.
The threats have evolved from black sedans and interrogation rooms to compromised build pipelines, malicious npm packages, living-off-the-land binaries, and AI-augmented social engineering. The response must evolve too. This is the work I'm here to do.
← Back to Blog