Daniel Cortez

DanielCortez

Security engineer across AI security, cloud and software engineering.

Now

Cor4 Digital

Cybersecurity & Digital Solutions Specialist

July 2026 to present

Bolivia

A safety system that watches eight plant cameras and never calls home.

False positives went from 64 to 1. True detections rose from 771 to 828. No new hardware.

Computer-vision safety system

Delivered a production system on 8 plant cameras (26 Python modules, an 11-table SQLite store, 3 n8n workflows), covering frame capture through RF-DETR detection, ByteTrack tracking, zone rules and automated Telegram and PDF reporting.

Private by design

Zero internet egress and no facial recognition: person IDs come from spatiotemporal continuity instead of biometrics. Reverse-engineered a DVR's proprietary DVRIP/Sofia protocol to unblock a client whose unit exposed no RTSP endpoint.

From one site to a product

One-step install via network auto-discovery and offline installers validated across 7 camera source types. Alert delivery raised to 100% under concurrent violations by re-keying deduplication to per-person identity.

Examples of work

Cor4 Digital, company site

Cor4 Digital

Design and front end. App catalogue, consulting, team and contact pages, in English and Spanish, light and dark.

Stack
React 19, TypeScript, Vite, react-router
Security
Hash-based Content Security Policy, HSTS, nosniff, frame and referrer headers; nothing stored until the visitor consents; rate-limited contact form; no third-party trackers.
Open live demo(opens in a new tab)
Cor4 Digital: recording of the home page scrolled top to bottom.

Cor4 Digital, reservation agent

Cor4 Digital AI

Landing page and the owner dashboard the AI agent books against: floor view, calendar, day schedule, undo.

Stack
React 19, TypeScript, Tailwind CSS v4, n8n
Security
Sign-in against an n8n webhook that gives the same answer for an unknown user and a wrong password, request timeouts, and dashboard routes behind a sign-in guard.
Open live demo(opens in a new tab)
Cor4 Digital AI: recording of the home page scrolled top to bottom.

Yorservi S.R.L., oilfield services

Yorservi

Redesign proposal. 17 pages in Spanish and English, pinned hero, horizontal service rail, well-log navigation.

Stack
React 19, Vite, GSAP ScrollTrigger, Lenis
Security
Fully static, prerendered pages with no server-side form: enquiries open in the visitor's own email or WhatsApp, so the site collects no personal data.
Open live demo(opens in a new tab)
Yorservi: recording of the home page scrolled top to bottom.

whitesky.cloud · February 2026 to May 2026

An AI support desk that drafts replies on hardware nobody outside the company can reach.

AI Automation and Cloud Operations Intern, Belgium

AI ticketing
A production n8n workflow connecting Zammad, Rocket.Chat, PostgreSQL and Qdrant: RAG retrieval with Ollama embeddings, on-premise LLM drafting and confidence-score routing. Estimated to cut 40% of manual L1 support work.
Private inference
Deployed Qwen 3 30B on GPUStack on a dedicated GPU VM, air-gapped from the public internet, so customer ticket data never leaves the company network.
Prompt-injection hardening
Strict JSON output schemas and prompt-level rules, verified with adversarial payloads (jailbreaks, instruction overrides, payloads hidden in ticket bodies and image attachments) plus magic-byte validation on attachments. Built a Python test framework for tool abuse, reasoning-chain hijack, confidence manipulation and SQL injection.
Provisioning as code
Python automation against the whitesky.cloud API to create cloudspaces, spin up VMs, add users and manage resources, removing manual console work.
Network isolation
OPNsense first-match LAN ruleset with whitelist-based isolation, and WireGuard with per-user /32 tunnel IPs, so backend services are reachable over VPN only.
Health triage
A second n8n workflow polls the Meneja API every 5 hours, runs each failed healthcheck through an AI agent against a GitLab knowledge base, and posts severity-sorted reports to Rocket.Chat. Kept the Docker fleet (n8n, Ollama, Qdrant, PostgreSQL, pgAdmin) healthy and documented the playbooks.

Freelance security assessments

Two-person engagements, Belgium. Client names and findings stay confidential.

Residential care organisation

Internal network vulnerability assessment

Asset discovery across the internal subnets, authenticated host scanning and manual verification, plus external perimeter and IPv6 checks. Findings scored with CVSS and CWE and delivered as a client report with prioritised remediation.

Independent pharmacy

Workstation assessment and OSINT review

Internal host and service-exposure scan, and an OSINT review of what attackers can learn about the business in public for phishing and fraud. Delivered with plain-language remediation for non-technical staff.

Full-scope penetration test, NDL vulnerability assessment (academic)

5 Critical. 4 High. 4 Medium.

Across VPN, DMZ and internal lab segments. Reached SYSTEM-level access through XML-RPC deserialization RCE, Elasticsearch MVEL script RCE, Pass-the-Hash, SNMPv1 misconfiguration and RDP credential interception.

Lateral movement and subnet pivoting with Metasploit, Impacket and credential harvesting. Delivered an audit report with CVSS scoring, CWE references, topology maps and a remediation roadmap.

  • Academic

    Web security monitoring and honeypot

    Triaged 2,000+ ModSecurity alerts by attack type and tightened WAF rules against the top patterns, cutting mean time to detection about 30%. A Cowrie SSH honeypot wired to Elasticsearch and Kibana captured 500+ brute-force attempts and SQLMap scans.

    Coursework
  • Python CLI

    Advanced Nmap Scanner

    Wraps Nmap with OS fingerprinting, custom NSE scripts, decoy scanning and normalized JSON, XML and grepable output for downstream tooling.

    Source for Advanced Nmap Scanner
  • Python, Flask-SocketIO

    EncryptedChatBackEnd

    Real-time encrypted messaging backend for 100 concurrent users, with AES-256, async I/O and environment-based secret management.

    Source for EncryptedChatBackEnd
  • Python, Flask

    ProductionPetrolForecast

    Exponential, hyperbolic and harmonic decline-curve forecasting behind a Flask interface, with dataset upload and Excel reports.

    Source for ProductionPetrolForecast

Toolkit

Howest University of Applied Sciences
Bachelor of Applied Computer Science, Cybersecurity Professional
Brugge, Belgium

British School Quito
High School Diploma
Quito, Ecuador

English and Spanish, both proficient.

AI and computer vision
RF-DETR, ByteTrack, OpenCV, PyTorch (CPU inference), zone and geofence logic, model benchmarking, GPUStack, Ollama, Qwen 3 30B, RAG, Qdrant, prompt engineering, AI agent security testing
Automation
n8n (production flows, webhooks), REST APIs, Telegram Bot API, SQLite (WAL), PostgreSQL, automated PDF reporting, schema-validated LLM output
Front end
React 19, TypeScript, Vite, Tailwind CSS v4, react-router, GSAP, Lenis, WCAG AA auditing, i18n, light and dark theming
Video and cameras
DVRIP/Sofia, RTSP (Hikvision, Dahua, Reolink, Axis), ONVIF discovery, multi-channel NVR, MJPEG over HTTP, USB capture
Cloud and DevOps
Docker, Linux, VMware, OPNsense, WireGuard, CI/CD, Bash, Infrastructure as Code, IaaS provisioning; AWS at project level
Kubernetes
Talos Linux 3-node cluster, kubectl, NodePort and ClusterIP services, MetalLB, Metrics Server, Horizontal Pod Autoscaling, failure recovery testing
Security
Secure SDLC, threat modelling, firewall design, segmentation, Metasploit, Nmap, Burp Suite, OWASP ZAP, Wireshark, Pass-the-Hash, ARP spoofing
Detection and forensics
Elasticsearch, Kibana, Filebeat, ModSecurity log analysis, Cowrie, Autopsy and The Sleuth Kit, timeline reconstruction
Languages
Python, JavaScript, TypeScript, Bash, SQL, Flask, Java, PHP, C# (.NET) with Supabase PostgreSQL