AVAILABLE FOR ENGAGEMENTS — Red team · Penetration testing · Application security · Security advisory FOUNDER-LED — Every engagement scoped and delivered personally, end to end EVIDENCE-LED — Every finding backed by a working proof-of-concept AVAILABLE FOR ENGAGEMENTS — Red team · Penetration testing · Application security · Security advisory FOUNDER-LED — Every engagement scoped and delivered personally, end to end EVIDENCE-LED — Every finding backed by a working proof-of-concept

Founder-led offensive security · Nairobi & remote

Attacker mindset. Defender mission.

Focus areas:

I'm Martin Mwathi, founder of Orvantis Security. Think like the attacker. Strike at machine speed. Prove it by hand. Frontier AI and purpose-built agents hunt your defenses like a real adversary — finding the foothold, chaining weaknesses, and pushing toward your crown jewels. Then a human takes the trigger: I run the attack to the end, prove the breach, and strip the noise down to what truly puts you at risk. Machine speed to find it. Human proof it's real. I break in on your terms — before someone does on theirs.

LIVE scan latency 10.4ms · packets 1,247 · target locked
0%
Findings backed by a proof-of-concept
0%
Reliance on automated scanners
0h
Response on critical issues
0:1
Direct, founder-led delivery

Services

How I can help

Every engagement is scoped, controlled and fully documented — but never softened. I test the way a motivated attacker would, then provide a clear path back to a stronger position.

⬡

01 / RED TEAM

Red Team Engagements

Objective-based adversary simulation against your real environment — people, process and technology together. It answers one question: what would a determined attacker actually achieve against your organisation?

◈

02 / PENTEST

Penetration Testing

Scoped, hands-on testing of web apps, mobile apps, APIs and infrastructure. Manual work — not scanner output — with a working proof-of-concept behind every finding I report.

⬟

03 / APP SECURITY

Application Security

Deep review of the applications your business actually runs on — authentication, business logic and access control, the areas automated scanners consistently miss. Findings prioritised by real business impact, not a CVSS score alone.

◉

04 / ADVISORY

Security Advisory

An attacker's eye built into how you design, ship and review systems. Threat modeling and architecture review grounded in offensive experience — not a compliance checklist.

How an engagement runs

The offensive lifecycle

I follow the same structured attack process a serious adversary uses — run with precision, written down at every step.

01

Recon & OSINT

Surface mapping, subdomain enumeration, passive OSINT — a full picture before touching a system.

02

Threat Modeling

Attack-path analysis and entry-vector prioritisation grounded in real adversary behaviour.

03

Initial Access

First foothold through the weakest viable vector — application, credential, or human.

04

Lateral Movement

Privilege escalation and pivoting — from foothold to objective, the way an attacker would.

05

Objective

Simulated impact — data access, system compromise, or the agreed goal — with proof.

06

Report & Retest

Full attack-path write-up, PoCs, and support through remediation until the finding is closed.

What a finding looks like

Evidence only. No filler.

Every finding I deliver comes with a working proof-of-concept — not a theoretical risk, a demonstrated one. Sample below is redacted from a client engagement.

orvantis — engagement-report.txt (redacted sample)
FINDING Unauthenticated IDOR — Patient Record Exposure
SEVERITY Critical (CVSS 9.1)
ASSET api.[redacted].internal/v2/patients/{id}

DESCRIPTION
The patient record endpoint performs no ownership check on the authenticated
user. Incrementing the integer {id} parameter exposes full records belonging
to other patients including name, DOB, diagnosis codes, and prescriptions.

REPRODUCTION
GET /v2/patients/10042 HTTP/1.1
Authorization: Bearer <token-for-patient-10001>

→ HTTP/1.1 200 OK — returns patient 10042's full record

IMPACT Full PHI exposure for all registered patients. No rate limiting.
FIX Enforce a server-side ownership check against the authenticated user's ID.
STATUS Closed — fix shipped by client, verified on retest

How I work

A direct, founder-led engagement

Orvantis is deliberately a focused, founder-led practice. The person who scopes your engagement is the same person who delivers it, writes it up, and stays available for questions throughout.

Founder-led

Delivered personally, start to finish

The person who scopes the work delivers it

Evidence-led

If it can't be demonstrated, it isn't reported

Every finding carries a working proof-of-concept

Committed to closure

Retesting is included as standard

Findings close only when the risk is resolved

Tools & techniques

The same tooling serious adversaries rely on

RECONNAISSANCE

Shodan Amass theHarvester Subfinder Recon-ng Maltego

EXPLOITATION

Burp Suite Pro Metasploit SQLMap ffuf Nuclei Custom exploits

POST-EXPLOITATION

BloodHound Sliver Mimikatz Rubeus CrackMapExec Impacket

Sectors

Sectors I work across

🏦

Financial Services

Banking, insurance, and payment systems — high-value targets that deserve attacker-level scrutiny.

🏥

Healthcare & MedTech

EMR systems, patient portals, connected devices — where a security failure has a human cost.

🏛️

Government & Public Sector

National systems and citizen data that cannot afford a breach — or a cover-up.

⚡

Critical Infrastructure

Energy, utilities, and industrial control systems where availability is non-negotiable.

💻

Technology & SaaS

Platforms where one vulnerability becomes a risk for every single customer you have.

₿

FinTech & Crypto

Digital assets and trading platforms — where an API flaw or logic bug costs real money, fast.

Why Orvantis

Why teams work with Orvantis

01 / DEPTH

Offensive-first thinking

I come from hands-on offensive work and red teaming, not compliance audits. Every engagement is led by the same attacker mindset — measured, careful, and grounded in proof over speculation.

02 / EVIDENCE

Zero findings without a PoC

If I report it, I can show it. Every finding comes with a working proof-of-concept, exact reproduction steps, and a real business-impact read — not a theoretical CVSS number.

03 / COMMITMENT

Engaged until it's fixed

I don't simply file a report and move on. I stay through remediation — retesting fixes, answering questions, and closing findings only when the risk is genuinely resolved.

Process

From first message to closed findings

01

Scoping call

20 minutes. We look at the specific system — enough to spot the real risk, scope the work, and quote it accurately. No obligation.

02

The engagement

Structured testing against the agreed scope — documented at every step, safe, with nothing touched beyond what we agreed.

03

Report & retest

Plain-language report. Every finding has severity, a PoC, and a fix. Retest is included once you ship the patches.

See what an attacker would find first

I'll take a short, no-obligation look at your system — enough to show you where the real risk actually sits.

Start a conversation View services