sitkastack

sitkastack is where I build AI systems and write about what makes them hold up: evaluation harnesses, prompt-injection resistance testing, retrieval you can trace, and audit logging.

Regulated environments are where those questions get forced, so that is where the first framework went. The discipline is not limited to them.

vendor-risk-triage is Apache 2.0, 1,377 tests, 100% coverage across twelve packages, mapped to NIST AI RMF, the EU AI Act, OSFI E-23 and SR 11-7. Free, and it stays free.

Not a consultancy. Not taking client work. Speaking, workshops, writing and side projects are open.

Track record

I have automated the regulated back office before.

  • 85% of manual onboarding automated and 61.5% annual sales growth at Refresh Financial, later acquired
  • $500M originated on a lending platform launched in 18 months
  • AML/KYC and POS modernization across 600+ retail locations

Selected work

Regulated-environment delivery.

15+ years shipping systems in fintech, financial services, and regulated industries.

85%
of manual onboarding automated

Fintech · Canada

Refresh Financial: sales and servicing automation

A call-centre-dependent sales and servicing model that couldn't scale. Led the end-to-end automation build: 85% of manual onboarding automated, 61.5% annual sales growth, and the company was later acquired.

$500M+
originated

Financial services · North America

Consumer lending platform launch

A North American financial services group with 600+ retail locations. They needed a new consumer lending product and had no platform to start from. Built the technology and the product line in 18 months, alongside AML/KYC and POS modernization across the network. It still runs the lending business today.

$200M
projected 5-year customer lifetime value

Retail · Canada

MarTech and customer data platform

A top-five Canadian grocer's $16M MarTech program. Built and integrated the customer data platform behind their marketing automation. The roadmap projects 40% higher engagement and 25% better marketing ROI.

Who this is for

sitkastack is built for VPs and Heads of Operations, COOs, and Servicing or Lending Ops leaders at banks, credit unions, insurers, lenders, and fintechs with expensive manual processes and pressure to adopt AI without adding risk.

You hold the budget and feel the pain; your risk or compliance partner is in the room. The work is built so they can sign off on it.

Automation that survives the exam.

Anyone can wire an AI model into a back-office workflow. In a bank, a credit union, or an insurer, the hard part comes later, when OSFI, an examiner, or your internal audit team asks how a specific decision was made and who owned it.

That question has a precise answer here. Every automation I ship carries its evidence with it:

  • An audit log for every automated decision, tied to the model version that made it.
  • A model record: what the model does, its limits, its evals, and when it was last reviewed.
  • A named owner for every class of automated decision, with a documented override path.
  • Controls mapped to OSFI E-23, NIST AI RMF, SOX, and SOC 2 where relevant.

This is the reason the automation is safe, not the product. The product is the manual cost coming out of your operation. The artifacts are why your risk and compliance partners sign off, and why the savings are still there after the exam.

For Canada's federally regulated financial institutions, OSFI E-23 takes effect May 1, 2027. Automation built now is built to that bar by default.

The sitkastack Framework

Proof I build governed AI in the open: sitkastack's vendor-risk-triage framework is shipped at v1.0.5, eight phases complete, open source under Apache 2.0. 1,377 tests at 100% coverage across twelve packages. The full implementation lives on GitHub, with a worked example on /demo.

The open-source framework is a free reference implementation. It is deliberately not a turnkey audit defense.

Eight phases shipped: Discovery & Risk Classification; Data Contracts & Privacy; Architecture & Threat Model; Agent + RAG + Ingestion + Eval; Eval Depth + Retrieval Quality; Operational Hardening; Production Polish; Multi-tenancy + Schema Migration.

Robyn is one of the very few non-engineers I've worked with who can genuinely engage in technical trade-offs while still keeping cross-functional teams aligned and moving forward.
Angela Zenner · Senior Engineering Manager, Wealthsimple. Worked with Robyn at Refresh Financial, where Angela was Director of Technology & Development.
Robyn joined Refresh and built our Enterprise PMO from scratch at a critical time in our growth. She has a rare ability to translate high-level strategy into clear execution plans without slowing down the business, particularly in an environment where we were trying to execute quickly without compromising on quality. I trusted her to manage our most complex initiatives and she delivered every time.
Michael Wendland · Founder/CEO at Refresh Financial
I reported to Robyn at Refresh Financial, first as a Project Manager and later as I transitioned into Product and Marketing roles. Robyn is the rare leader who genuinely cares about her team's long-term career path, not just the project in front of her. She supported my growth and helped me develop the strategic skills I needed to level up within the organization. I'd highly recommend her to any team looking for strong leadership.
Tyler Hinds · Product at KOHO (formerly at Refresh Financial, reported to Robyn)

Tools I built and use

The same patterns I apply to client work.

Internal tool

Executive delivery dashboard

A Python pipeline that ingests Jira, Smartsheet, and timesheet data and uses the Claude API for RAG-based program insights, margin analysis, and forecast views. An internal tool I built and use to replace manual status compilation.

Claude APIPythonJiraSmartsheet
Public demo · GitHub (personal repo)

Fintech service ops triage

AI triage tool for service-operations decisions in regulated environments. Confidence-gated routing, PII redaction, prompt-injection mitigation, and structured audit logging.

Claude APIPythonTool use
View on GitHub
Independent build

Multi-persona AI code review

Claude API pipeline running parallel code review across security, performance, readability, and architectural perspectives before commits land. Pattern testing for earlier risk detection.

Claude APIPrompt engineering
Independent build · In daily use

Daily briefing system

Runs overnight. Surfaces what changed, what's at risk, what needs a decision. Reduces inbox triage and morning context-switching.

n8nClaude API

Writing in public.

Notes from the work. Monthly newsletter on LinkedIn. Long-form on Medium when a piece earns it.

LinkedIn newsletter and posts

A monthly LinkedIn newsletter on what makes an AI system hold up: the control to write, the evidence to keep, and what broke.

MonthlyFollow on LinkedIn

Follow sitkastack on LinkedIn for company updates, new builds, and case studies. linkedin.com/company/sitkastack

Robyn Toor, Founder of sitkastack

Founder

Robyn Toor

15+ years shipping systems in fintech and regulated industries, where the work has to hold up in production, not just demo well. sitkastack brings that standard to small and mid-sized operators. Founded in 2025.

MBAPMPAIGP (in progress)CSMCSPOAWS Cloud Practitioner
Full background at robyntoor.com

Contact.

Questions about the work? Email me at robyn.toor@gmail.com.