Code Icon

Hey, I'm Emil

I'm a business-savvy data nerd who spends way too much time in front of a screen. I run a few different companies, invest, advise, and hack. My most notable achievement was founding, scaling, and exiting Debricked, a startup I co-founded in 2018. Following Debricked's 2022 acquisition, we joined Micro Focus. I lead teams developing application security solutions using machine learning, graph algorithms, and static analysis techniques.

I also enjoy writing spaghetti code while drinking wine. 🍷

Current projects

OaizAI that builds AI agents
Valkompass.aiNeo4j + Gemini for Swedish political data
PodidexAI podcast transcript analysis and recommendations

Podcast Appearances

Conference Presentations

Using Graph Database Technology to Resolve Transitive Vulnerabilities at Scale

GOTO Copenhagen 2022

Neo4j applications for complex dependency resolution.

Predicting the rise and fall of Open Source

Foo Café Malmö 2022

Community health metrics and project success prediction. Watch video

Semantic Code Discovery - AI-powered code recommendations

Foo Café Malmö 2022, State of AI series

Introduction to semantic code search capabilities. Watch video

Additional Presentations

Zero to One AI education for managers, company tech-talks, hackathons, and machine learning events.

External Blog Posts

Predicting the rise and fall of an open source project

LinkedIn

Research on why projects become unmaintained. Watch the talk

How Neo4j's Graph database can remediate vulnerabilities

LinkedIn

Demonstrates graph database approaches for dependency vulnerability analysis.

Last Years Open Source - Tomorrow's Vulnerabilities

The Hacker News

Data-driven insights on vulnerability discovery timelines.

Papers

Primary Publications

Automated CPE Labeling of CVE Summaries with Machine Learning

Springer

Addresses vulnerability database labeling using Named Entity Recognition. Achieved F-measure of 0.86 with precision 0.857 and recall 0.865.

Security Issue Classification for Vulnerability Management with Semi-supervised Learning

SCITEPRESS

Uses Hierarchical Attention Networks for automated classification. Achieved F1 score of 71% and identified approximately 191,036 potentially vulnerable issues. Nominated for best paper at conference.

Patents

Method for linking CVE with synthetic CPE
SE2050302A1US12339972B2Debricked AB

Uses NLP to automatically link vulnerability databases (CVE) with platform enumerations (CPE) by extracting information and building synthetic mappings.

Method for finding vulnerabilities in software projects
US12386975B2Debricked AB

Parses dependency files, generates CPE identifiers, and matches against vulnerability databases using confidence scoring to identify relevant security issues.

Method for assessing quality of open source projects
US2023367591A1Debricked AB

Determines quality metrics for open-source projects by extracting features from project data, applying statistical transforms, and weighting relative to similar projects.

Method for identifying vulnerabilities in code
US12265612B2Debricked AB

Automates vulnerability detection using NLP on open-source issue discussions with hierarchical attention networks and virtual adversarial training.

Learning-based identification of vulnerable functions
US2024241963A1Micro Focus LLC

Identifies vulnerable functions in code using call graph analysis and ML models that map CVE data to specific functions.

Software vulnerability remediation
US12314403B2Micro Focus LLC

Maps package dependencies to non-vulnerable versions, ensuring compatibility across interdependent packages while eliminating security risks.

Identification of relevant code blocks via embeddings
US12443396B2Micro Focus LLC

Uses code embeddings and functionality clustering to locate relevant code blocks within software packages based on queries.

Detection of malicious packages using ML
US2024419793A1Micro Focus LLC

Combines malicious code classifiers with community behavior analysis to detect malicious software packages using machine learning.

Automated patch generation for software flaws
US2024385823A1Micro Focus LLC

Uses ML to identify vulnerabilities in databases, locate affected code, and auto-generate patches from version deltas where issues were fixed.

License analysis for AI-generated content
US2025190858A1Micro Focus LLC

Analyzes AI-generated compositions to identify training data sources and automatically assigns appropriate licensing based on source material licenses.

Comprehensive software supply chain analysis
US2024193276A1Micro Focus LLC

Monitors external component updates, analyzes API changes, identifies new vulnerabilities, and generates composite quality scores for developers.

Controlling source code use in AI training
US2025173802A1Micro Focus LLC

Manages licensing for AI models trained on licensed source code, tracking and attributing licenses to AI-generated output code.

Open Source Projects

addcommitpush.io

Next.js • TypeScript

This blog platform itself, built with Next.js 16. Features SSG, MDX content, and audio narration for posts. Open-sourced so you can see how it's built - warts and all.

Debricked CLI

Go • Docker

Command-line interface for open source security scanning and software composition analysis. Delivers vulnerability detection, compliance checking, and health metrics directly to the command prompt. Integrates seamlessly into CI/CD pipelines with multi-platform support.

Valkompass.ai

Next.js • Neo4j • Gemini

Open source platform for exploring Swedish political party positions using AI-powered analysis. Combines knowledge graphs (Neo4j) with Google Gemini to analyze party programs, manifestos, and voting records. Provides transparent, data-driven insights for voters, journalists, and citizens.

I Hate Group Chats

NLP

Early-stage project automating group chat management using NLP. Self-described as "very very early stage".

Research Projects

ARVOS

AI and Risk-based Vulnerability Management for Trustworthy Open Source Adoption

Runtime vulnerability detection using eBPF. Funded by Vinnova. Collaboration: Debricked, Elastisys.

HASMOSS

Health and Security Management in Open Source Software

Swedish industry OSS risk management initiative. Partners: RISE, Debricked, Scania, Addalot.