Founder-led offensive security · Nairobi & remote
I'm Martin Mwathi, founder of Orvantis Security. Think like the attacker. Strike at machine speed. Prove it by hand. Frontier AI and purpose-built agents hunt your defenses like a real adversary — finding the foothold, chaining weaknesses, and pushing toward your crown jewels. Then a human takes the trigger: I run the attack to the end, prove the breach, and strip the noise down to what truly puts you at risk. Machine speed to find it. Human proof it's real. I break in on your terms — before someone does on theirs.
Services
Every engagement is scoped, controlled and fully documented — but never softened. I test the way a motivated attacker would, then provide a clear path back to a stronger position.
01 / RED TEAM
Objective-based adversary simulation against your real environment — people, process and technology together. It answers one question: what would a determined attacker actually achieve against your organisation?
02 / PENTEST
Scoped, hands-on testing of web apps, mobile apps, APIs and infrastructure. Manual work — not scanner output — with a working proof-of-concept behind every finding I report.
03 / APP SECURITY
Deep review of the applications your business actually runs on — authentication, business logic and access control, the areas automated scanners consistently miss. Findings prioritised by real business impact, not a CVSS score alone.
04 / ADVISORY
An attacker's eye built into how you design, ship and review systems. Threat modeling and architecture review grounded in offensive experience — not a compliance checklist.
How an engagement runs
I follow the same structured attack process a serious adversary uses — run with precision, written down at every step.
01
Surface mapping, subdomain enumeration, passive OSINT — a full picture before touching a system.
02
Attack-path analysis and entry-vector prioritisation grounded in real adversary behaviour.
03
First foothold through the weakest viable vector — application, credential, or human.
04
Privilege escalation and pivoting — from foothold to objective, the way an attacker would.
05
Simulated impact — data access, system compromise, or the agreed goal — with proof.
06
Full attack-path write-up, PoCs, and support through remediation until the finding is closed.
What a finding looks like
Every finding I deliver comes with a working proof-of-concept — not a theoretical risk, a demonstrated one. Sample below is redacted from a client engagement.
How I work
Orvantis is deliberately a focused, founder-led practice. The person who scopes your engagement is the same person who delivers it, writes it up, and stays available for questions throughout.
Delivered personally, start to finish
If it can't be demonstrated, it isn't reported
Retesting is included as standard
Tools & techniques
RECONNAISSANCE
EXPLOITATION
POST-EXPLOITATION
Sectors
Banking, insurance, and payment systems — high-value targets that deserve attacker-level scrutiny.
EMR systems, patient portals, connected devices — where a security failure has a human cost.
National systems and citizen data that cannot afford a breach — or a cover-up.
Energy, utilities, and industrial control systems where availability is non-negotiable.
Platforms where one vulnerability becomes a risk for every single customer you have.
Digital assets and trading platforms — where an API flaw or logic bug costs real money, fast.
Why Orvantis
01 / DEPTH
I come from hands-on offensive work and red teaming, not compliance audits. Every engagement is led by the same attacker mindset — measured, careful, and grounded in proof over speculation.
02 / EVIDENCE
If I report it, I can show it. Every finding comes with a working proof-of-concept, exact reproduction steps, and a real business-impact read — not a theoretical CVSS number.
03 / COMMITMENT
I don't simply file a report and move on. I stay through remediation — retesting fixes, answering questions, and closing findings only when the risk is genuinely resolved.
Process
20 minutes. We look at the specific system — enough to spot the real risk, scope the work, and quote it accurately. No obligation.
Structured testing against the agreed scope — documented at every step, safe, with nothing touched beyond what we agreed.
Plain-language report. Every finding has severity, a PoC, and a fix. Retest is included once you ship the patches.
I'll take a short, no-obligation look at your system — enough to show you where the real risk actually sits.