Ideas,
shipped.

Project development, from first sketch to production, by Nicolas Montani.

Products and clients I've built for

  • thenotification.app
  • SwissDiscover
  • DVM Carrelage
  • Floyd Mail
  • OFF-SCREEN
  • Gartus Technologies
  • Elias D
  • GFMG
  • University of St.Gallen

04 · Hardware prototyping

From breadboard to working device.

Before a connected product gets a budget, someone has to prove it can work. I build fast, honest prototypes on ESP32, Arduino and Pi Pico: sensors, cameras, actuators and the small interfaces that control them.

R&D prototype

Standalone camera node

An ESP32-CAM that runs its own Wi-Fi access point, streams live MJPEG to any browser, records to SD card in hourly segments and lets you download clips. No cloud, no router.

ESP32-CAM · SD_MMC · HTTP

R&D prototype

Home environment monitor

Temperature, humidity and soil moisture on a live OLED, with sensor calibration on the device and clear error states when a read fails.

ESP32 · DHT11 · I²C OLED

R&D prototype

Smart desk companion

A Pomodoro device that pauses when you walk away (ultrasonic presence), reacts to a shake and pulls live JSON over HTTPS. About 2,700 lines of modular C++.

ESP32 · HC-SR04 · ArduinoJson

R&D prototype

Wearable watch face

ESP-IDF firmware for a round AMOLED ESP32-S3: LVGL interface, step and tilt detection from the IMU, battery monitoring and an on-device “Hi ESP” wake word.

ESP32-S3 · FreeRTOS · LVGL

R&D prototype

Remote control & vision

A servo driven from a browser, and an Arduino shield with a Dockerised Flask/WebSocket dashboard that runs YOLOv4-tiny object detection on a camera feed.

ESP32 · Flask · OpenCV

Toolbox

ESP32 / S3 / CAMArduinoRP2040LoRaWANChirpStackESP-IDFFreeRTOSPlatformIOC / C++LVGLWi-Fi AP & STAWebSocketsDocker

05 · Cybersecurity

See your system the way an attacker does.

I combine hands-on offensive testing with research on AI-driven deception. My bachelor thesis at the University of St.Gallen built a honeypot that invents a believable website on the fly, one probed path at a time.

Bachelor thesis · HSG · 2025

AI-Agent Honeypot

A decoy website that writes itself while the attacker is still looking.

Classic honeypots are easy to spot: static pages, canned errors, nothing behind the login. Here a Claude agent, locked inside a firewall-isolated container, writes one realistic file per new path into that visitor's own folder. It reuses the existing CSS and JS so the fake site stays coherent. Every request is logged to PostgreSQL and shown on a live dashboard.

FastAPIClaude Agent SDKPostgreSQLNext.jsDocker
Read the full case study →

ATTACKER

GET /admin/.env

FASTAPI :8000

parse path · check cache

POSTGRESQL

every request + response

CACHE HIT

return session file instantly

CACHE MISS → AGENT

Claude Code · firewall-isolated · writes ONE file

PER-SESSION FILE TREE

generated/
└─ <session>/
   ├─ style.css   ├─ login.php
   ├─ script.js   └─ admin/.env  ← new
Architecture v3.1 · simplified from the thesis

Benchmark vs. Galah (open-source LLM honeypot)

This honeypot Galah

Functional responses · scanner crawl

81
50

Functional responses · 55 OWASP attacks

27
16

Avg. response size · crawl

14.2 KB
0.5 KB

Avg. response size · OWASP attacks

8.2 KB
1 KB

The trade-offs, stated honestly: cached pages return instantly, but a brand-new complex page took 60 to 170 seconds to generate. Galah handled injection and SSRF probes better. All tests ran in a local lab, so no real-world attack data is claimed.

01

Deception & honeypots

Decoy services that catch intruders early and record what they try, from lightweight traps to AI-generated decoy sites.

02

Web application testing

Authorised tests of web apps and APIs along the OWASP Top 10, with clear, prioritised findings.

03

Secure-by-design delivery

Isolation, least privilege, containerised deployment and logging, planned into the project from day one.

04

Threat insight

Structured request logging, session analysis and dashboards that show which endpoints get probed and how.

05

Team awareness

Practical sessions that show what real attacks look like, with live demos from a controlled lab.

06 · Process

Small steps, no surprises.

The same rhythm took DVM Carrelage from paper to an iPad app and The Notification App from an idea to the App Store.

  1. 01

    Discover

    We map the workflow, the users and the constraints, often on site. Out comes a written scope and a clear first milestone.

    1–2 weeks

  2. 02

    Prototype

    A clickable mock-up or a working hardware build, validated with real users before the expensive work starts.

    1–3 weeks

  3. 03

    Build

    Iterative delivery in short cycles with a live preview, so you're never surprised by what shows up.

    weeks–months

  4. 04

    Ship

    App Store, production hosting, documentation and a go-live guide your team can actually follow.

    launch

  5. 05

    Operate

    Monitoring, security updates and the next iteration, once real usage tells us what matters.

    ongoing

07 · Contact

Have an idea? Let's ship it.

Tell me what you're building, or what's still on paper. I usually reply within a day, in English, French or German.