Focused technical work, with the boundaries visible.
The useful engagement is the one that solves a defined problem—not the one with the longest list of deliverables.
01
Website security review
Review an explicitly authorized website for common web-security weaknesses, exposed attack surface, authentication and session problems, configuration issues, and information leakage.
02
Security hardening
Help remediate agreed findings and improve practical controls around authentication, input handling, secrets, access, and deployment—then verify the relevant changes.
03
Security tooling / automation
Build focused Python utilities, integrations, data-processing systems, reporting workflows, or other small tools around a real security or research task.
04
AI + security engineering
Build or integrate AI-assisted security workflows where the model adds a useful signal and its limits can stay visible. Normal code where normal code works better.
02
02 / who this is for
Small enough to stay close to the work.
This is primarily for people who need a practical improvement without turning it into a massive consulting engagement.
01Small businesses
02Independent developers
03Small web applications
04Early-stage technical projects
03
03 / process
A short path from question to evidence.
The exact work changes. The need for scope, authorization, useful output, and a clear handoff does not.
01
Scope
Understand the system, objective, authorization, and boundaries.
02
Review / build
Perform the agreed technical work inside that scope.
03
Fix / deliver
Provide findings, implementation, or remediation for the engagement.
04
Verify / report
Verify relevant changes and leave behind clear documentation.
04
04 / proof of work
The evidence is in the systems and their rough edges.
Not a technology inventory. These projects show how Fahis approaches engineering, security assumptions, evaluation, and documentation.
01 / application security
Coffre
A password-manager experiment spanning browser-side encryption, authentication and OTP flows, sessions, replay protection, controlled team access, and deployment.
Demonstrates: security-focused application engineering and practical trust-boundary design.
Active security testing only happens with explicit authorization and an agreed scope. Findings should be supported by evidence, handled responsibly, and limited to the engagement.
No website can honestly be guaranteed “100% secure.” The useful promise is narrower: define what is being reviewed or built, communicate what was found, and be clear about what remains outside scope.