|
I build things that are fast, secure, and actually work.
From zero-day research to production-grade apps.
Transparent pricing. Professional delivery. No fluff.
Full vulnerability assessment of your web app, network, or CCTV infrastructure. I find what attackers would find — before they do.
Full-stack web applications built with clean architecture. Django, Node.js, REST APIs, databases — built to scale and secured from day one.
Cross-platform mobile apps for Android and iOS with a single codebase. Beautiful UI, native performance, and baked-in security practices.
Automated bots for Telegram, WhatsApp, Discord, or the web. Scraping, alerting, customer service, or task automation — fully custom.
Purpose-built security tools tailored to your infrastructure. From network scanners to vulnerability assessment utilities — fast, concurrent, and production-ready.
Custom privacy-focused chat and messaging applications with end-to-end encryption. Built with Flutter for Android & iOS — only intended recipients can read messages.
High-performance REST APIs built with Django or Go. Clean architecture, JWT auth, rate limiting, and full documentation — ready to power your web or mobile app.
Polished Flutter apps for everyday use — recipe managers, music players, productivity tools, and more. Clean UI, offline support, and fast performance on all devices.
Get an instant estimate for your project.
Trusted by businesses & individuals across Kenya
High-performance network tool for CCTV device detection, vulnerability scanning, and default credential checking. Built with Go for concurrent scanning across large networks.
Mental health platform with AI-powered chat, mood journaling, community features, and gamification. Django REST API backend + Flutter mobile app + PostgreSQL.
Fast network discovery tool featuring port scanning, service detection, banner grabbing, and report generation in JSON/HTML. Concurrent goroutines for blazing speed.
Suite of Telegram and Discord bots for task automation, web scraping alerts, and AI-powered customer service. Deployed and actively used by real clients.
Static analysis tool for Android APK files. Detects security vulnerabilities, hardcoded secrets, weak cryptography, and validates OWASP Mobile Top 10.
Advanced JavaScript security analysis tool — secret detection, entropy analysis, source maps, GraphQL, WebSockets, tech fingerprinting and HTML reports.
Flutter frontend for the CCTV security scanner. Visualizes scan results, device discovery, and vulnerability reports in a clean mobile interface.
Multi-threaded password cracking tool written in Go with support for multiple hash types, PCAP analysis, and custom transformation rules.
Quick reads. Real insights.
Ports 22, 23, 3389, 5900, and 8080 left exposed to the internet are an open invitation. Each one has a history of mass exploitation. Here is what to do about each one before an attacker finds them first.
Most Flutter developers store API keys in dart files, compile them into the APK, and ship them to the Play Store. Decompiling takes 60 seconds. Use flutter_dotenv, certificate pinning, and server-side validation to stay safe.
Go's goroutines let you scan 10,000 ports concurrently with minimal memory. Compiled to a single binary with no dependencies. Cross-compiles to Linux, Windows, ARM in one command. For security tooling, nothing comes close.
Most WhatsApp bot tutorials get you banned in a week. The Baileys library with proper session management, rate limiting, and human-like delays is the difference between a bot that lasts and one that gets blocked overnight.
I went from writing basic Python scripts to landing real security clients in under 18 months. HTB forced me to think like an attacker, understand real CVEs, and write custom exploits. Here is the exact path I followed.
Most login pages fail on three things: no rate limiting, weak session tokens, and verbose error messages that tell attackers whether the username or password was wrong. Fix these three and you eliminate 80% of brute-force risk overnight.
Before any attack, hackers spend hours in reconnaissance. Public GitHub repos, job postings, LinkedIn tech stacks, and misconfigured DNS records hand them everything they need. A 30-minute OSINT audit on yourself will shock you.
Decompiling Android APKs takes under 60 seconds. In that time, you can extract hardcoded API keys, Firebase credentials, and database URLs left by developers. If your app is on the Play Store, assume it has been checked. Use environment variables and certificate pinning.
Daniel did a full security audit on our web platform and found critical vulnerabilities we had no idea about. The report was detailed, clear, and came with actionable fixes. Highly professional work.
Built us a Telegram bot for order notifications and client follow-ups. It works flawlessly, was delivered on time, and he even trained us on how to use it. Would hire again without hesitation.
Hired Gatiella to build a custom Telegram bot for our logistics business. It handles order updates, client notifications, and daily reports automatically. Saved us hours every week and the code is clean and well documented.
We needed a Flutter app for both Android and iOS on a tight budget. Gatiella delivered a polished, fast app in under three weeks. Firebase integration worked perfectly from day one. Will definitely work together again.
Gatiella ran a full penetration test on our CCTV and network setup. Found three critical misconfigurations we had no idea about. The report was detailed with clear steps to fix each issue. Exactly what a serious security audit should look like.
Tell me what you need. I'll respond within 24 hours.