Kevin Granger

Cybersecurity Policy Manager
Founder of The TCG Forge

My day job is cybersecurity policy work supporting a federal SOC. On my own time, I built The TCG Forge, a live application for trading-card sellers.

I own the architecture, development process, release decisions, and shape of the product, while using AI to write and revise the application code. I also run it in production and handle customer support.

The TCG Forge

I built The TCG Forge for trading-card sellers managing inventory, listings, orders, and shipping. It's a live SaaS application with paying customers, and I'm the solo founder responsible for its development and operation.

The work covers the whole application: deciding what to build, designing the architecture, directing AI implementation, reviewing changes, releasing them, and supporting the people using it. The Seller OS uses React, with Node.js and SQLite behind it.

As of August 30, 2026, the platform had 113 registered users and 61 paid accounts, including lifetime accounts from the founders program.

Visit thetcgforge.com

The TCG Forge Research view showing a set search and navigation for inventory, integrations, orders, and seller tools.
The research screen, from the product's help guides. Sellers can look up sets and card pricing from the same application they use for inventory and orders.

What sellers can do with it

Someone preparing a listing needs different tools from someone packing an order. The application covers both, along with the stock and pricing information they need in between.

Inventory tools include a stock ledger, locations, sealed products, and read-only share links. Orders have their own hub, with manual entry, supported imports, and channel pulls. The shipping side includes a postage wallet, rate quotes, labels, and downloadable pick and pack lists.

I also built the account and support pieces: Google sign-in, plan access, Stripe and PayPal payment paths, picture-first help, and in-app feedback.

Orders and shipping

Sellers move orders through open, ready, and shipped states. They can buy postage, print labels, and download the documents they need for picking and packing. The Orders hub is available to signed-in users without a paid plan.

Imports and pulls vary by channel. Carrier coverage varies too, and public tracking still has edge cases under maintenance.

Inventory and marketplaces

The Pro inventory workflow includes an import preview before changes are applied. Sellers can organize stock and use native ManaPool and eBay connections for supported order and quantity operations.

Imports and quantity updates have partial paths. The account needs the right plan, connection, and supported operation. I don't claim universal two-way sync or protection against every oversell.

Listings and research

The converter prepares channel-specific files for Whatnot, TikTok Shop, Drip, and TCGplayer workflows. Sellers upload those files themselves. That's separate from the native marketplace connections.

The Forge TCG Index supplies catalog and pricing data. Other seller tools include Profit Finder, TCGplayer Price Updater, custom export templates, and Whatnot Wheel Maker. Price Updater is file-based, not a continuous API repricer.

Product scope and usage figures

The August 30, 2026 snapshot contained 75 order records and 69 shipment records. Both include operator activity, and shipment records include mixed states rather than only completed shipments. Converter history recorded 258,901 cards processed cumulatively, not unique cards.

The 61 paid accounts include lifetime access and aren't a monthly subscriber count. Features depend on the plan and enabled capabilities. Watchlists and alerts have operational limits; Selling Stats and Field Notes are partial surfaces. Shopify isn't customer-live, and multi-seat staff administration isn't part of the current product.

Ready-to-print orders with label, envelope, and pick-list actions. Buyer, order, and tracking details are redacted.
Fulfillment controls in the Orders hub. The source screenshot has buyer, order, and tracking information redacted.

How I work with AI

I use AI to write and revise the code. I still own the process, architecture, release decisions, and shape of the product. I decide what needs to change, define the requirements and scope, and review the result before it goes into production.

I've built a development workflow around that division of responsibility. Agents receive bounded tasks, with tests and review requirements appropriate to the change. I retain merge and deployment authority. Some work follows the automated review pipeline; other changes take a documented manual review path.

A pack-list change is one example.

An order's pack list showed the right card name but the wrong identity fields when the order line wasn't linked to inventory. I wrote the acceptance criteria and directed the implementation to reuse the existing catalog lookup. An AI agent made the scoped change.

I ran one unit test file, reviewed the work, and checked a downloaded pack list after the production update. The unit test file passed. A tier-8 diagnostic failed in that environment, with no passing rerun or separate QA and policy pass recorded for this change.

The four-page case study goes through that release and two production incidents: a deployment with missing startup dependencies, and a database-file problem that left backups looking healthy while the application wrote elsewhere. It covers the recovery work and the checks I added afterward.

Read: How I use AI to build The TCG Forge (PDF, four pages)

Development workflow figures

As of the August 2026 review, I've recorded 909 live SDK runs, excluding dry runs. That's a portfolio-wide workflow count, not a release count. The codebase includes 409 automated test files and 25+ named policies.

The 8-tier deploy diagnostic suite covers several parts of the application. The default post-deploy subset checks health, entitlements, and production smoke. These figures describe the system; they aren't measurements of time saved or proof that every release passed every stage.

My cybersecurity work

Cybersecurity Policy Manager

LOGC2 · Defense Logistics Agency SOC support

I write, review, and standardize the procedures analysts and leadership use in a federal SOC. My work has contributed to 100+ adopted TTPs and helped reduce analyst onboarding from about two months to four weeks.

I also created a DLA-wide safe-AI training document. Much of this work is explaining operational requirements clearly enough that the people affected can put them into practice.

Cyber Enterprise Engineer

Harver

I led a year-long security-platform implementation, from vendor evaluation through production deployment. The work included SIEM, SOAR, vulnerability management, and security scanning.

I evaluated 20+ vendors and owned a $99.5K Rapid7 and MDR program, working through requirements, demonstrations, recommendations, and implementation coordination.

Security+ and CySA+ are active through July 2029. My federal work and The TCG Forge are separate; no government work products are shared here.

I'm looking for my next role.

I'm interested in solutions engineering, AI implementation, and cybersecurity work where I can help take a problem from requirements through implementation. I'm based in Ohio and open to remote work or relocation.

If that fits something you're hiring for, I'd like to hear about it.

kevin.granger@kevingranger.com

LinkedIn · GitHub