Aller au contenu principal
Smidjan
Technical evidence, not promises

Projects & achievements

What I build, I document and secure. Some projects are public on GitHub, others stay private: every status is stated honestly, nothing dressed up.

Flagship project

ClawkWerk — CyFun / NIS2 audit tool

A self-assessment tool I am building to help SMEs prepare for the CyFun framework, the Belgian foundation of NIS2 compliance.

Open source · written in Go

Context

Walloon SMEs now need to position themselves against NIS2. The CyFun framework (CyberFundamentals, Centre for Cybersecurity Belgium) offers a clear framework, but adopting it takes time and a method. That is what this tool prepares: a structured diagnostic, ahead of any official certification process.

Method and guarantees

  • Aligned with the CyFun framework
  • Read-only: the tool never modifies the audited systems
  • Explicit audit scope, defined before each session
  • Credentials are never stored
  • Tamper-proof audit log of every action
  • Every proposed remediation is validated by a human
  • No data is retained after the audit

Result

A clear report, leading to prioritised remediation, then to a progressive hardening of the system.

Important: this tool is an assisted self-assessment and preparation, not an official certification. CyFun certification is issued exclusively by BELAC-accredited bodies.

Proprietary tool, developed solo. Internal architecture and code are not public: technical details on request.

Other projects

What is already built

An open-source library, this site, and application security exercises: the rest of the evidence, public or not.

ClawkWerk

PublicGo

CyFun (CCB) / NIS2 audit tool written in Go: read-only, agentless, built for Belgian SMEs. A structured compliance diagnostic, with no intrusive install.

GoCyFun / NIS2CLIRead-only
View the repo

FormCraft

PublicC#

Open-source C#/Blazor library to build type-safe, dynamic forms with an elegant fluent API.

C#Blazor.NET
View the repo

This site (Smidjan)

Private codeNext.js

This portfolio itself: Next.js 16, React 19, TypeScript, next-intl (FR/NL/EN), with particular attention paid to security (CSP, rate limiting, hardened headers).

Next.jsReactTypeScriptnext-intl

Application security (exercises)

Private codeJava

Hands-on practice with Java/Spring Security and the OWASP Top 10: concrete learning of secure coding.

JavaSpring SecurityOWASP Top 10

I regularly publish and expand my projects.

Follow progress on GitHub

A question about one of these projects?

I answer with the same transparency as on this page: what's done, what's in progress, what stays private.

Fast responseFull transparencyBased in Wallonia