Nazline Mwita - Cybersecurity & Assurance Lead
CO-FOUNDER & LEAD

Nazline Mwita

Co-Founder & Cybersecurity Assurance Lead
Co-founding partner alongside Harry Ndeke · Building secure AI-powered websites, automations & resilient workflows.
Nairobi / Thika, Kenya
CompTIA Security+ B.S. Computer Science Responsible Disclosure
Assurance Console (Interactive v2.0)

Nazline Mwita: Security Assurance & Advisory Console

Working Positioning: "We help growing organisations build secure AI-powered websites, automations and digital workflows, then document, test and hand them over responsibly."

Type help to inspect services, entry offer, audit methodology, or verified credentials.

client@assurance:~$

PRACTITIONER OVERVIEW Assurance Leadership & Operating Model

Practitioner
Nazline Mwita
Consulting Role
Co-Founder & Cybersecurity Assurance Lead
Core Clearance
CompTIA Security+ Certified · B.S. Computer Science
Operating Rule
Clarity before branding · Proof before promotion

I lead the cybersecurity and technical assurance practice at our emerging consulting firm. Working alongside Harry Ndeke, I ensure that as organisations adopt AI assistants, automated integrations, and modern web architectures, they do so with rigorous security boundaries.

"Many providers build websites, automate workflows, or conduct security reviews in isolation. We treat security, automation, and maintainability as one continuous system: map → secure → build → test → document → hand over."

Rather than relying on generic scanner output or fear-based sales tactics, my work is grounded in verifiable evidence, authorized scopes, and clear remediation pathways that non-technical decision-makers can trust.

Core Assurance Domains

🛡️

Authorised Security Audits

Scoped web application, API, and cloud configuration assessments conducted under written rules of engagement.

Automation & Data-Flow Hygiene

Reviewing webhook endpoints, credential storage, and least-privilege tool execution for n8n and autonomous agents.

🔍

Evidence-Led Threat Analysis

Human-verified vulnerability triage and realistic severity rankings that separate real exploit paths from vanity alerts.

📋

Governance & Responsible Handover

Clear remediation roadmaps, Kenyan Data Protection Act compliance, and comprehensive operational documentation.

CONSULTING PRACTICE Services & The Entry Offer

We serve SMEs, startups, and established teams that need to replace manual bottlenecks with reliable digital workflows without exposing customer data, API keys, or operational stability.

RECOMMENDED FIRST ENGAGEMENT

Secure Digital Workflow Assessment

Fixed Scope · 2 to 3 Weeks Delivery

A fixed-scope discovery engagement that maps one critical workflow, public web surface, or internal API; identifies security and operational vulnerabilities; ranks high-ROI automation opportunities; and delivers an actionable 30/60/90-day remediation and implementation roadmap.

Current-State Architecture Map End-to-end trace of your data flows, external integrations, and sensitive data touchpoints.
Authorised Security Observations Human-verified risk findings on configurations, permissions, and exposed surfaces within agreed scope.
Automation & AI Feasibility Matrix Prioritised evaluation of automation opportunities ranked by business value, operational risk, and implementation effort.
Actionable Remediation & Build Roadmap Concrete 30/60/90-day plan with clear stop-points, owner assignments, and safe implementation paths.
Request Scoping Call Zero obligation to proceed with follow-on builds. Clear decisions before code.

The Firm's Four Service Pillars

01

Secure AI-Powered Websites

Modern business and service websites built for speed, conversion, and durability. Includes guided search assistants, lead capture integrations, and technical SEO/AEO foundations.

Led by Harry · Audited by Nazline
02

AI & Workflow Automation

Robust n8n workflow architecture, multi-step integrations, and RAG knowledge systems that eliminate manual data re-entry while maintaining strict operational audit trails.

Led by Harry · Audited by Nazline
03

Authorised Security Services

Scoped website, web application, and API assessments with formal rules of engagement. Practical remediation reports that explain risks in plain business language.

Led by Nazline
04

Secure Automation Reviews

Data-flow, webhook, and permission reviews for automated systems. Setting tool-execution boundaries, credential hygiene, and human approval checkpoints for AI agents.

Led by Nazline

ETHICAL STANDARDS Responsible Security Boundary & Charter

Cybersecurity capability is valuable only when governed by discipline and ethics. We hold ourselves to clear, published boundaries:

STANDARD PROTOCOL

Permission Before Testing

Active security testing is conducted strictly under written client authorization that defines exact targets, methodology, testing windows, and emergency stop conditions.

STRICTLY PROHIBITED

No Unsolicited Scans

We do not perform unsolicited active scanning against arbitrary websites, nor do we use automated scanner dumps to manufacture panic or pressure prospective clients.

STANDARD PROTOCOL

Human Evidence Verification

Every finding reported to a client is manually reproduced and evaluated for actual business impact. We measure trust and clarity rather than inflated vanity metrics.

STANDARD PROTOCOL

Data Minimization & Privacy

We never extract, download, or retain client data to "prove" impact. All assessment evidence is handled with least privilege and securely deleted per our retention policy.

VERIFIED PROOF Technical Proof & Active Deliveries

Research & Implementation Final Year Cybersecurity Project

AI Integrated Smart Packet Analyzer

A high-performance Machine Learning Network Intrusion Detection System (NIDS) designed to analyze network flows in real time, distinguish malicious traffic from normal operations, categorize threats, and provide explainable attribution behind every prediction.

  • Evaluated on 82,332 held-out UNSW-NB15 benchmark network flows
  • Binary attack detection and multi-class threat classification with XGBoost
  • Real-time packet inspection via NFStream and Scapy with explainable prediction scoring
  • SOC-style triage dashboard with exportable incident logs and PDF/CSV compliance reports
PythonXGBoostStreamlitNFStreamScapyThreat Intelligence
View Research & Code on GitHub
Active Client Delivery Commercial Delivery Record

Munar: Website Audit, Optimization & Deployment Handover

Collaborative delivery project with Harry Ndeke for Munar (munar-ke.vercel.app). Managed the security baseline, content structure, UX clarity, accessibility, technical SEO foundations, and production deployment on Vercel.

  • Established baseline audit across performance, mobile responsiveness, and headers
  • Enforced security boundary: scoped reviews without intrusive unauthorized scanning
  • Implemented structured data, canonical URLs, and clean analytics without tracking leaks
  • Delivered client access, documentation, and maintainable handover record
Client DiscoverySecurity BaselineTechnical SEOUX / Mobile AuditingVercel
View Munar Deployment

ACCREDITATION Credentials & Continuous Learning

Jul 2023 to Sep 2026

Zetech University

B.S. in Computer Science

Rigorous focus on computer systems, algorithm design, software engineering architectures, database security, and networking protocols.

Mar 2023 to Present

GOMYCODE

Diploma in Cybersecurity

Applied laboratory coursework in network defense, authorized penetration testing methodologies, vulnerability assessments, incident triage, and cryptography.

Validated Industry Credentials

CompTIA Security+ Certified

Global Benchmark for Cyber Defense, Threat Assessment, Identity Governance, and Cryptographic Implementation.

Founding Cross-Training Rhythm

Nazline Mwita and Harry Ndeke · Bi-weekly technical exchange
ACTIVE CURRICULUM
Nazline Teaches:
  • Threat modeling & security baselines
  • Web and API vulnerability assessment
  • Authorised testing methodology & scoping
  • Evidence, severity rankings & remediation
  • Data privacy & incident response fundamentals
Harry Teaches:
  • APIs, webhooks & data-flow architecture
  • n8n workflow design & error handling
  • AI agents, tools & RAG systems
  • AI-powered website systems & AEO
  • Observability & client handovers

ENGAGEMENT INTAKE Scoped Consultation & Assessment Intake

Interested in our Secure Digital Workflow Assessment, an authorized web/API review, or secure automation design? Submit your project context below. All inquiries are held in strict confidence.