Software engineer in Nairobi. I build performant, secure web applications end to end, and I go deep on the parts most people skip: security posture, edge cases, correctness.
Founder of Nyxora Labs, a software engineering studio doing client work and building products. I run the studio mostly solo, which means I own everything from architecture to deployment.
Language and framework agnostic in practice, though I reach for TypeScript, Node.js, and PostgreSQL by default. Strong interest in application and infrastructure security.
Most of my recent work lives in private repos, so here is what to look at:
Nyxora Sentinel is a passive web security posture scanner. Point it at a domain and it audits security headers, cookies, TLS and certificates, and DNS/email records, then grades the result against a versioned rubric. It runs on serverless with a defence-in-depth SSRF guard: per-hop redirect validation and IP pinning to close DNS-rebinding and TOCTOU vectors. It scores A+ on its own scan. That link is the live demo, not a repo.
Lab Notes (nyxoralabs.com/notes): short, principle-led writeups in the studio's voice. The quick version of what I learned building Sentinel.
Security writeups: the same class of bugs as my Lab Notes, but as code teardowns. Vulnerable path and fix side by side, built to walk through. Public and readable, even though Sentinel's source is not.
- Studio: nyxoralabs.com
- Co-organiser, Claude Community Kenya (CCK)
TypeScript · Vue · Nuxt · Node.js · Nitro · PostgreSQL · Python · Vercel · AWS · Cloudflare

