Hieu Luong
Contact

Hanoi · In cybersecurity since 2012

Hieu Luong

AI governance, Multi-Cloud, blockchain and security architecture

I help organizations design resilient multi-cloud infrastructure, run AI within Vietnam's Law on Artificial Intelligence, safeguard personal data under Decree 13, and keep business records tamper-evident on blockchain. Founder of HimiTek.

  • 14 years in cybersecurity
  • 50+ enterprise clients advised
  • 12 cloud, AI and data certifications

Six interlocking rings, one cohesive trust system

From cloud architecture to autonomous AI agents and immutable data ledgers. Choose a ring to explore each discipline.

What I take on

Each engagement starts from a concrete system you already run or plan to launch.

AI governance

AI compliance under Law 134/2025/QH15

I inventory the AI systems you run, classify each against Decree 142/2026/ND-CP and the high-risk list in Decision 33/2026/QD-TTg, then close gaps with controls mapped to NIST AI RMF and ISO/IEC 42001.

  • AI system inventory
  • Risk classification memo with legal basis
  • Gap analysis and remediation plan
  • Notification dossier for the national AI portal

Transition deadlines: 1 Mar 2027 for most sectors, 1 Sep 2027 for health, education and finance.

Classify a system now

AI engineering

Enterprise LLM gateways & Agentic systems

Centralized LLM gateway architecture (OpenClaw), intelligent cost routing, security guardrails preventing data exfiltration, internal enterprise RAG, and automated business workflows via Multi-Agent Swarms with Human Gates.

  • Secure LiteLLM & Ollama proxy gateway
  • Enterprise RAG with role-based access
  • Multi-agent workflows with human-in-the-loop
  • Token spend analytics and cost routing

Multi-Cloud architecture

Multi-Cloud resilience & FinOps

Comprehensive architectural advisory across AWS, Azure and Google Cloud (Triple Crown certified). High-availability distributed infrastructure, disaster recovery strategies, production Kubernetes (EKS/AKS/GKE), and FinOps cost governance.

  • Multi-Cloud architecture blueprints
  • Hardened Kubernetes infrastructure
  • High Availability & Disaster Recovery plans
  • FinOps cloud cost reduction roadmap

Data & Privacy

Decree 13 compliance & Data architecture

Data Protection Impact Assessments (DPIA) under Decree 13/2023/ND-CP and Personal Data Protection laws, data flow mapping, field-level encryption for sensitive PII, and audit-ready enterprise data lakehouse architectures.

  • DPIA compliance assessment dossiers
  • Personal data inventory and flow mapping
  • End-to-end field-level data encryption
  • Compliant data warehouse architecture

Cybersecurity

Security architecture & Technical due diligence

Architecture reviews for cloud, IDC and hybrid infrastructure, security and compliance audits against ISO 27001 and NIST CSF, and technical due diligence before large infrastructure investments.

  • Infrastructure and application security audits
  • ISO 27001 & NIST CSF compliance matrix
  • Threat modeling and gap analysis
  • Technical due diligence for investments

Blockchain & Traceability

Enterprise BaaS & Digital Product Passports

Blockchain-as-a-Service design on Hyperledger Besu, smart contract security review, and traceability solutions anchoring EPCIS 2.0 events on-chain with IPFS storage, ready for EUDR, CBAM, and Digital Product Passports.

  • Multi-tenant private Hyperledger Besu network
  • Smart contract security auditing
  • EPCIS 2.0 supply chain traceability
  • Encrypted decentralized storage on IPFS

Where does your AI system sit?

Vietnam sets three risk levels in law and names its high-risk systems in an official list. The EU AI Act classifies by intended use. Pick a use case to see both side by side.

Choose a use case

Vietnam

Medium risk

Users could mistake it for a person. Self-classify, notify through the national AI portal, and tell users they are talking to AI.

Law 134/2025/QH15 Art. 9–11; Decree 142/2026/ND-CP Art. 9

EU AI Act

Transparency obligations

Not high-risk. Users must be told they are interacting with AI.

AI Act Art. 50(1), applies from 2 Aug 2026

Dashed markers on the stack: a level that applies only under the condition described.

Indicative self-assessment only, not legal advice. Based on Vietnam's Law on AI No. 134/2025/QH15, Decree 142/2026/ND-CP, Decision 33/2026/QD-TTg and the EU AI Act (2024/1689, as amended by 2026/1744), current to 15 Sep 2026. Confirm with counsel.

Discuss this system with me

Career, kept as a ledger

Each block holds one chapter and the SHA-256 hash of the block before it, computed in your browser when the page loads. Alter one block and the link after it breaks.

  1. #02007 – 2012

    Academy of Cryptography Techniques

    B.Sc. in Information Security

    prev
    hash
  2. #12012 – 2015

    DHA

    System and security engineer

    SIEM and EDR monitoring; security policy across enterprise environments.

    prev
    hash
  3. #22014 – 2017

    Nextop Asia (remote, Japan)

    Senior security engineer

    Firewall, IPS/IDS, WAF, DLP, SIEM and vulnerability management; incident investigation.

    prev
    hash
  4. #3Hanoi

    Plantynet

    Senior security engineer

    Secured AWS infrastructure and CI/CD pipelines with Jenkins, Docker, Kubernetes and Ansible.

    prev
    hash
  5. #42019 – 2022

    GTEL Group

    Security solutions consultant and project manager

    Advised 50+ enterprise clients; delivered firewall, IPS/IDS, DDoS mitigation, SIEM, ATP and threat intelligence projects.

    prev
    hash
  6. #52022 – now

    VNPT-IT

    Cybersecurity and infrastructure specialist; blockchain R&D lead

    Security and compliance audits of cloud, IDC and SOC platforms; technical due diligence for infrastructure investments; designed a Blockchain-as-a-Service platform.

    prev
    hash
  7. #62026 – now

    HimiTek

    Founder

    AI compliance consulting under Law 134/2025/QH15 and HimiTrace traceability.

    prev
    hash

Selected work

Drawn as the layers each system is built from. Hover or focus a card to pull the layers apart.

Enterprise platform

Blockchain-as-a-Service platform

Multi-tenant BaaS. Each tenant deploys a private Hyperledger Besu network with a Blockscout explorer, Grafana monitoring and IPFS storage.

  • Besu
  • Docker
  • IPFS
  • React

Interactive demo

HimiTrace batch verification

Supply-chain transparency: EPCIS 2.0 events anchored on Hyperledger Besu, certificates encrypted on IPFS, verified by scanning a QR code.

  • Hyperledger Besu
  • IPFS
  • EPCIS 2.0

Healthcare

Cross-hospital EHR sharing

Electronic health records shared between hospitals through blockchain and an IPFS cluster. Patients control access; records stay encrypted.

  • Java
  • Besu
  • IPFS HA

AI / LLM

OpenClaw LLM gateway

Routing and orchestration across OpenAI, Claude, Gemini and self-hosted Ollama, with an A/B proxy.

  • LiteLLM
  • Ollama
  • Python
Cloud labs and study projects (10)

Certifications and education

Amazon Web Services

  • Solutions Architect – Professional
  • Developer – Associate

Microsoft Azure

  • Solutions Architect Expert
  • Data Scientist Associate
  • AI Engineer Associate
  • Administrator Associate

Google Cloud

  • Professional Cloud Architect
  • Professional Cloud DevOps Engineer

IBM

  • Data Science
  • Data Engineering
  • Data Warehouse Engineer
  • Applied Data Science
  • Academy of Cryptography Techniques B.Sc. Information Security · 2007–2012
  • Le Hong Phong High School, Nam Dinh IT and Mathematics · 2004–2007

Writing

All posts on LinkedIn
Portrait of Hieu Luong

Tell me about your system

A few lines are enough: what the system does, who it affects, and when it has to comply. I reply personally, by email or Zalo.

HimiTrace

Demo data

Besu node connected

Dak Lak durian batch #DK-0932

tx 0x8b32cf43…a982f10b

  1. Harvest and packing

    2026-05-20 07:30

    Dak Lak cooperative · signed 0xHTX…82a9

  2. Quality check

    2026-05-20 14:15

    VietGAP certificate · stored on IPFS Qm…43ab

  3. In transit

    2026-05-21 09:00

    Cold chain · 5 °C