Skip to content
Bartłomiej Czech

Bartłomiej Czech

AI Software Engineer. I build and secure AI systems.

Section I: About

I’m an AI Software Engineer in Poland. I build AI agents and the infrastructure that connects them to real tools and data, mostly in Python and around the Model Context Protocol (MCP).

The question I keep coming back to is how to let an agent act for someone without giving it more than it should have: who it acts as, where it can reach, what it can read, and what it does when its input lies to it.

At ActiveCampaign I own the OAuth that lets ChatGPT, Claude and Cursor connect to our MCP server with a single URL, and I now lead custom MCP connectors, which let customers plug their own MCP servers into our AI agent, including its security design, agreed with our Security team.

I’ve spoken at the GenAI Kraków Meetup (agent development) and the BRAVE AI Community meetup (AI-native SWE workflow), and took part in Bending Spoons First Ascent Poland 2026.

Away from the keyboard, I speak five languages (Polish, English, German, French and Turkish) and train MMA.

Section II: Projects

  1. camel-prompt-injection

    Defends AI agents against prompt injection by design, extending DeepMind’s CaMeL architecture with scope-guarded branching and a static analyser. The base for my Master’s thesis; on AgentDojo it reaches 77.5% task utility with 0% attack success.

    GitHub: camel-prompt-injection

  2. Security Architecture for AI Agent Systems

    My Master’s thesis (MEng Cybersecurity, AGH University of Kraków), defended with honours. It builds a complete evaluation pipeline for secure LLM agents: datasets, metrics, adversarial evaluations and deployment.

    Zenodo: Security Architecture for AI Agent Systems

  3. scopeguard-rag

    Access control for RAG: a benchmark of five strategies for keeping retrieval from leaking documents a user shouldn’t see. It measures answer quality against document leakage for each strategy.

    GitHub: scopeguard-rag

  4. ai-agent-security-thesis

    Prototype code from my thesis. It implements an MCP gateway that puts a policy engine and scoped tokens between agents and their tools.

    GitHub: ai-agent-security-thesis

Section III: Experience

  1. Nov 2025 – Present

    ActiveCampaign · Associate Software Engineer

    Owned and shipped single-URL OAuth 2.1 for the company MCP server, from client registration and account selection to token refresh, revocation and multi-region deployment, so ChatGPT, Claude and Cursor connect with one URL; this laid the groundwork for ActiveCampaign’s ChatGPT app. Built the tools, keyword-based full-text search and evals for the Integrations Recommendations agent. Now leading customer-managed MCP connectors, making calls to customer-supplied servers safe by design, with Product, Security and SRE.

  2. Jul – Sep 2025

    ActiveCampaign · Software Engineering Intern

    Rebuilt a legacy Python service into separate client, API and service layers with input validation and dependency injection, raising test coverage from 32% to 95%. Fixed a long-standing data-integrity issue in a company-wide ARR metric.

  3. Mar – Jul 2025

    Accenture · GenAI Engineering Intern

    Worked on a production RAG system that matches candidates to projects from unstructured CVs, from NLP preprocessing to embedding-based retrieval and evaluation.

  4. Jul – Sep 2024

    Comarch · Software Engineering Intern (RAG)

    Worked on a RAG assistant over internal technical documentation.

Education

  1. 2025 – 2026

    MEng, Cybersecurity · AGH University of Kraków · Defended with honours

  2. 2021 – 2025

    BEng, ICT · AGH University of Kraków

Section IV: Contact

The best way to reach me is email.