Selected work

Real engagements. Real findings. Things we actually shipped.

A sample of the work — a hackathon-winning AI product built solo, a client security assessment that caught a live data exposure and saw it through to a verified fix, a hardware product built end to end, and the infrastructure behind this very site.

Hackathon — 1st place

Suvidha AI Virtual Hackathon 2026

Built solo, submitted, and judged against 300+ other entries.

Suvidha AI Virtual Hackathon 2026 — 1st place

Class of One — an AI Socratic computer science teacher for schools with no CS program

Built for students who have no CS program at school and no one to ask when they're stuck. Rather than handing out answers, Class of One teaches the way a real teacher would — asking questions, building intuition, and adapting to whatever device the student actually has, from a phone to a shared family computer.

The app covers computer science across nine different areas of the field — programming, cybersecurity, networking, AI, quantum computing, and more — not just coding syntax, with memory across sessions, voice interaction, interactive diagrams, and a learning roadmap so a student always knows what's next. No install, no account, and no admin rights required, so it runs on whatever a student can actually get to — a phone, a library computer, a locked-down school Chromebook.

Google Gemini (3.6-flash) runs the Socratic teaching engine; Pyodide runs real Python in the browser so students can execute code with nothing installed. Every lesson is original — no scraped content or third-party datasets.

Built solo, end to end — product concept, UI/UX, and a full working app backed by a live AI model — and shipped in time for submission and judging.

1stplace, out of 300+ participants
9areas of computer science covered, not just syntax
Soloconcept, UI/UX, and full build, end to end
AI / LLM product Socratic pedagogy voice interaction in-browser Python
Client work

Security assessment — B2B SaaS platform

Details below are described generally to protect client confidentiality — no company names, identifiers, or exposed data are disclosed. Findings and remediation were handled under a signed engagement with defined scope and a disclosure clause.

Application security assessment

Caught a live, unauthenticated exposure of customer data — and drove it to a verified fix

Assessed a multi-tenant SaaS platform across its public marketing site and its authenticated application — the kind of manual, hands-on testing that holds up even when the target's own edge actively blocks automated scanners. Confirmed, read-only, that one database collection was readable by anyone on the internet with no login: customer identities, relationships, and — at the time — some commercial detail that shouldn't have been public.

Reported within the engagement's 24-hour critical-disclosure window. The client remediated; an independent re-test caught a second, narrower issue the first fix didn't cover — exposed authentication material in the same database. Reported again, remediated again, re-tested and closed. The client came out of it with a hardening roadmap and their own automated daily check watching for the same defect going forward.

Delivered as a full written report: findings, defensive posture, test coverage against the OWASP categories, and a hardening roadmap with exact prompts the client could hand to their own AI assistant to implement each fix.

1 Highseverity finding, confirmed & remediated
20+checks across recon, access control, client-side, and config
2 roundsof re-testing before close — the second catch mattered
manual testing access control disclosure & remediation written reporting
Product build

Silicon Spyder — secure event Wi-Fi, with built-in threat detection

A hardware product designed and built solo, from the networking and cloud backend to the two live dashboards on top of it.

Hardware + full-stack build

Secure event Wi-Fi — that also watches its own airspace for attacks

Temporary events run temporary Wi-Fi that nobody's watching. Silicon Spyder is a Raspberry Pi appliance that routes a cellular connection out to a Wi-Fi 6 access point, serving secure internet to 25–50 people at an event — that's the actual product vendors and attendees connect to. A second, dedicated radio runs a detection engine in parallel, untouched by the hotspot's own traffic: channel-hopping across the full spectrum for rogue access points, evil-twin clones, deauthentication floods, karma attacks, beacon spam, and open networks, with on-device LCD alerts, local logging, and a systemd boot service so it comes up on its own.

The cloud side is built the way client work gets built: Supabase (Postgres) behind row-level security, with security-definer functions that validate device credentials before any read or write — nothing talks to a table directly. Two live dashboards sit on top of it, polling every few seconds: a technician view with a real-time threat feed and severity-coded alerts, and a plain-language "you're protected" screen for vendors, no jargon.

The enclosure is a parametric, 3D-printable design (OpenSCAD) built to one hard constraint — non- metal only, since metal blocks Wi-Fi — with its own vented cooling chamber and internal cable routing. Priced to undercut commercial event-Wi-Fi rental while covering hardware and data costs, aimed at event-Wi-Fi rental companies and direct event organizers.

25–50people served secure Wi-Fi per event, the actual product
6attack types detected in parallel, on a dedicated radio
RLS +security-definer functions gate every read/write
Python Raspberry Pi 802.11 / RF Supabase / Postgres + RLS OpenSCAD
Product build

Draft_Tested — a free fantasy football draft room

Shared publicly on Reddit — commissioners called out that it solves the exact pain points that make draft night painful, especially forcing every participant to create an account just to pick.

Web app

Run a full fantasy draft in the browser — no sign-up, no paywall

A complete draft-night tool: snake or linear draft order, a pick clock, CPU-controlled teams so a draft never stalls waiting on a slow pick, and a draft assistant to help on the clock. Pulls real NFL player data live from Sleeper's API, imports an existing Yahoo league with tap-to-copy picks, and exports results to CSV or a printable sheet at the end.

Built and shipped solo. The commissioner problems it's actually solving — a stalled room, an account wall for every participant, a tedious hand-copy into Yahoo or ESPN afterward — are the same ones that make draft night painful in the first place.

Freeno sign-up, no paywall, no account required
Livereal NFL player data pulled from a live API
JavaScript live API data CSV export
This site

Vibe_Tested — the site you're reading this on

Built as its own case study: a small business site hardened the same way client work gets hardened.

Full-stack build + hardening

Designed, built, and hardened end to end

Full SEO and social infrastructure (Open Graph, structured data, sitemap), a site-wide security header policy including a scoped Content-Security-Policy, a rate-limited and input-bounded backend API, and a client-signing flow for service agreements that requires a parent or guardian co-signature before work begins — because the person running this business is a minor, and the paperwork should reflect that honestly.

FullOG / Twitter / structured-data coverage
HardenedCSP, HSTS, and a rate-limited API
Built-inparent/guardian co-signature on every agreement

Case studies on this page are shared with client confidentiality in mind — company names, data, and identifying detail are withheld or generalized throughout.

Coursework

Certificates

Cisco Networking Academy.

Networking Basics Introduction to Cybersecurity

Want the same treatment for your app?

Free consultation, plain-English findings, and a re-test after you fix — same process as above.

Request a free consultation →