← home

available for selected work / 2026

Have something worth
breaking carefully?

Security reviews, website hardening, security tooling, and technical automation for small projects, independent developers, and small businesses.

01 / services

Focused technical work, with the boundaries visible.

The useful engagement is the one that solves a defined problem—not the one with the longest list of deliverables.

  1. 01

    Website security review

    Review an explicitly authorized website for common web-security weaknesses, exposed attack surface, authentication and session problems, configuration issues, and information leakage.

  2. 02

    Security hardening

    Help remediate agreed findings and improve practical controls around authentication, input handling, secrets, access, and deployment—then verify the relevant changes.

  3. 03

    Security tooling / automation

    Build focused Python utilities, integrations, data-processing systems, reporting workflows, or other small tools around a real security or research task.

  4. 04

    AI + security engineering

    Build or integrate AI-assisted security workflows where the model adds a useful signal and its limits can stay visible. Normal code where normal code works better.

02 / who this is for

Small enough to stay close to the work.

This is primarily for people who need a practical improvement without turning it into a massive consulting engagement.

03 / process

A short path from question to evidence.

The exact work changes. The need for scope, authorization, useful output, and a clear handoff does not.

  1. 01

    Scope

    Understand the system, objective, authorization, and boundaries.

  2. 02

    Review / build

    Perform the agreed technical work inside that scope.

  3. 03

    Fix / deliver

    Provide findings, implementation, or remediation for the engagement.

  4. 04

    Verify / report

    Verify relevant changes and leave behind clear documentation.

04 / proof of work

The evidence is in the systems and their rough edges.

Not a technology inventory. These projects show how Fahis approaches engineering, security assumptions, evaluation, and documentation.

01 / application security

Coffre

A password-manager experiment spanning browser-side encryption, authentication and OTP flows, sessions, replay protection, controlled team access, and deployment.

Demonstrates: security-focused application engineering and practical trust-boundary design.

↗
02 / AI security

Neuris / v0id

An experimental malicious-input classifier whose weak classes, evaluation limits, and false-confidence risks remain visible.

Demonstrates: machine-learning experimentation without treating a model as a security guarantee.

↗
03 / research tooling

Ayano

A Python CLI that gathers CVE details, affected-product context, public proof-of-concept searches, and research references.

Demonstrates: traceable security-research automation with source and inference kept separate.

↗
04 / field notes

Dispatches

Development notes that document why a system exists, what it trusts, and what changed while building it.

Demonstrates: technical reasoning made inspectable instead of hidden behind a polished result.

↗

05 / engagement boundaries

Permission first. Evidence throughout.

Active security testing only happens with explicit authorization and an agreed scope. Findings should be supported by evidence, handled responsibly, and limited to the engagement.

No website can honestly be guaranteed “100% secure.” The useful promise is narrower: define what is being reviewed or built, communicate what was found, and be clear about what remains outside scope.

Evidence > dramatic terminal screenshots.

06 / start here

Have a project?

Let’s figure out what actually needs doing.

Discuss a project

Send the system or project, the problem you see, useful links, and what a good outcome would look like. That is enough to start.