Standalone camera node
An ESP32-CAM that runs its own Wi-Fi access point, streams live MJPEG to any browser, records to SD card in hourly segments and lets you download clips. No cloud, no router.
ESP32-CAM · SD_MMC · HTTP
Project development, from first sketch to production, by Nicolas Montani.
Products and clients I've built for
01 · Services
Most projects stall between the slide deck and the first real user. I sit in that gap: I scope the problem with you, prototype quickly, and ship something people actually use.
02 · Mobile
From a developer tool on the App Store to games, mail and social products: native where it matters, cross-platform where it pays off.
03 · Web
Map-first travel products, operations software for a construction SME and art-directed brand sites. Each one is built around the job it has to do.
04 · Hardware prototyping
Before a connected product gets a budget, someone has to prove it can work. I build fast, honest prototypes on ESP32, Arduino and Pi Pico: sensors, cameras, actuators and the small interfaces that control them.
An ESP32-CAM that runs its own Wi-Fi access point, streams live MJPEG to any browser, records to SD card in hourly segments and lets you download clips. No cloud, no router.
ESP32-CAM · SD_MMC · HTTP
Temperature, humidity and soil moisture on a live OLED, with sensor calibration on the device and clear error states when a read fails.
ESP32 · DHT11 · I²C OLED
A Pomodoro device that pauses when you walk away (ultrasonic presence), reacts to a shake and pulls live JSON over HTTPS. About 2,700 lines of modular C++.
ESP32 · HC-SR04 · ArduinoJson
ESP-IDF firmware for a round AMOLED ESP32-S3: LVGL interface, step and tilt detection from the IMU, battery monitoring and an on-device “Hi ESP” wake word.
ESP32-S3 · FreeRTOS · LVGL
A servo driven from a browser, and an Arduino shield with a Dockerised Flask/WebSocket dashboard that runs YOLOv4-tiny object detection on a camera feed.
ESP32 · Flask · OpenCV
Toolbox
05 · Cybersecurity
I combine hands-on offensive testing with research on AI-driven deception. My bachelor thesis at the University of St.Gallen built a honeypot that invents a believable website on the fly, one probed path at a time.
Bachelor thesis · HSG · 2025
A decoy website that writes itself while the attacker is still looking.
Classic honeypots are easy to spot: static pages, canned errors, nothing behind the login. Here a Claude agent, locked inside a firewall-isolated container, writes one realistic file per new path into that visitor's own folder. It reuses the existing CSS and JS so the fake site stays coherent. Every request is logged to PostgreSQL and shown on a live dashboard.
ATTACKER
GET /admin/.envFASTAPI :8000
parse path · check cachePOSTGRESQL
every request + responseCACHE HIT
return session file instantlyCACHE MISS → AGENT
Claude Code · firewall-isolated · writes ONE filePER-SESSION FILE TREE
generated/ └─ <session>/ ├─ style.css ├─ login.php ├─ script.js └─ admin/.env ← new
Benchmark vs. Galah (open-source LLM honeypot)
Functional responses · scanner crawl
Functional responses · 55 OWASP attacks
Avg. response size · crawl
Avg. response size · OWASP attacks
The trade-offs, stated honestly: cached pages return instantly, but a brand-new complex page took 60 to 170 seconds to generate. Galah handled injection and SSRF probes better. All tests ran in a local lab, so no real-world attack data is claimed.
Decoy services that catch intruders early and record what they try, from lightweight traps to AI-generated decoy sites.
Authorised tests of web apps and APIs along the OWASP Top 10, with clear, prioritised findings.
Isolation, least privilege, containerised deployment and logging, planned into the project from day one.
Structured request logging, session analysis and dashboards that show which endpoints get probed and how.
Practical sessions that show what real attacks look like, with live demos from a controlled lab.
06 · Process
The same rhythm took DVM Carrelage from paper to an iPad app and The Notification App from an idea to the App Store.
We map the workflow, the users and the constraints, often on site. Out comes a written scope and a clear first milestone.
1–2 weeks
A clickable mock-up or a working hardware build, validated with real users before the expensive work starts.
1–3 weeks
Iterative delivery in short cycles with a live preview, so you're never surprised by what shows up.
weeks–months
App Store, production hosting, documentation and a go-live guide your team can actually follow.
launch
Monitoring, security updates and the next iteration, once real usage tells us what matters.
ongoing
07 · Contact
Tell me what you're building, or what's still on paper. I usually reply within a day, in English, French or German.