Bhavya Malhotra - Cybersecurity Enthusiast & Backend Developer

bhavya@portfolio:~

$ โ–Œ

scroll โ†“
who is this guy

Cybersecurity & Backend Development.

I'm Bhavya, currently pursuing senior secondary education while focusing on cybersecurity, backend development, and systems programming.

I've built projects ranging from web applications and desktop software, while continuing to develop my skills in security and software engineering.

4 projects shipped
2 certifications
17 years old
โˆž things left to learn
what i work with

Skills & Learning

Some I use confidently. Some I'm still figuring out. I'll be honest about both.

๐Ÿ”’

Security & Pentesting

Web App Security XSS SQLi CSRF / SSRF (learning) VAPT (learning) Burp Suite Nmap Wireshark Tenable Nessus (learning) Splunk (basics)
โšก

Backend Development

FastAPI Pydantic PyMongo MongoDB Atlas PyJWT JWT Auth Cookie Handling Discord.py SQLite
๐Ÿ–ฅ๏ธ

Frontend & Desktop

JavaScript (basics) HTML / CSS PyWebView yt-dlp Multithreading PyInstaller (learning)
๐ŸŒ

Networking & Forensics

Digital Forensics (basics) Network Fundamentals Wireshark More forensics (learning)
๐Ÿ’ป

Languages

Python JavaScript C (learning)
comfortable actively learning
things i've actually built

Projects

Real projects with real backend logic. UIs were AI-assisted - the systems behind them weren't.

Open Source Ecosystem

Rivora Ecosystem

An ecosystem for building modern Python web servers and frameworks around a shared application contract.

Rivora is the ecosystem I'm currently building around the Rivora Contract Protocol (RCP). RCP defines how applications, frameworks, and servers communicate, while Riven is the first server implementation built around it. I'm currently focused on HTTP/3 and QUIC, with WebTransport planned next.

what i'm building: RCP - an ASGI-like application contract optimized for HTTP/3, with schematics for HTTP/3 streams and WebTransport. Riven - an asynchronous Python server implementing RCP, providing the foundation for future RCP-compatible frameworks and servers
current focus: HTTP/3, QUIC, asynchronous networking, connection management, lifespan handling, logging, and RCP integration
Python RCP Riven HTTP/3 QUIC asyncio aioquic
PyPI Package

NetraX

An asynchronous Python wrapper for Nmap with typed models, structured exceptions, and built-in scan profiles.

Built to make Nmap easier to integrate into modern Python applications. Instead of dealing with subprocess management, XML parsing, and raw command output, NetraX provides an async API that returns structured dataclass models. It includes built-in scan profiles, configurable timeouts, permission checks, automatic Nmap validation, JSON/dictionary export, and detailed exception handling while remaining dependency-free.

what i learned: Async subprocess management, XML parsing, package architecture, dataclass modelling, exception design, PyPI publishing, semantic versioning, and project documentation
next steps: AI-powered report generation, additional scan profiles, richer reporting utilities, and continued expansion of supported Nmap data fields
Python asyncio Nmap XML Dataclasses PyPI
Discord Bot

VoiceForge

Temporary voice channels that create and delete themselves - no manual cleanup needed.

Started as a single-server bot, grew into a proper multi-server architecture with a control panel. The hard part wasn't making channels - it was carefully handling Discord API rate limiting so the bot doesn't get banned. Users create a voice channel, everyone joins, it disappears when empty. Clean, no clutter.

what i learned: Rate limiting strategies, multi-guild bot architecture, SQLite for persistent guild configs, Pydantic for config validation
still working on: Better control panel UI, more customization per guild
discord.py Pydantic SQLite Python
Web App

Fukray

Community website for a Discord server - with a real backend, not just static HTML.

The UI was AI-generated, but the backend is entirely mine - FastAPI with MongoDB Atlas, proper JWT auth with short-lived tokens (security over convenience), cookie handling, login and access management. Includes a quotes system where users can add and delete quotes using BSON ObjectID lookups and proper JSON/BSON type conversion. Security was the focus throughout.

what i learned: JWT expiry and refresh logic, BSON/JSON type handling, PyMongo aggregations, cookie security flags, FastAPI dependency injection
still working on: More features, maybe a refresh token flow
FastAPI PyMongo MongoDB Atlas PyJWT Python
Desktop App

RaagaX

A music player for Windows and Linux that streams directly from YouTube - no middle server.

UI and PyInstaller spec file were AI-assisted, but everything else is mine - FastAPI backend embedded in the app, yt-dlp for direct stream URLs (no buffering through a server), PyWebView for the native window. Multithreading to keep the UI from freezing on big playlists. Handles frozen vs non-frozen state paths, Linux dependency scripts, and Discord rich presence. Ships as a zip with a single exe.

what i learned: PyInstaller frozen paths, Linux build scripts, yt-dlp stream URL extraction, multithreading for audio, Discord IPC for rich presence
still working on: Speed and efficiency on large playlists - it's a known issue, actively fixing
FastAPI PyWebView yt-dlp Multithreading PyInstaller Python
verified learning

Certifications

๐Ÿ›ก๏ธ
Tutedude

Cybersecurity

Foundational cybersecurity concepts - threat landscape, defensive principles, attack vectors, and security practices.

view certificate โ†—
โš”๏ธ
Tutedude

Ethical Hacking

Ethical hacking methodology - reconnaissance, scanning, exploitation techniques, and responsible disclosure.

view certificate โ†—
๐Ÿ“š
In Progress

More coming soon

Currently working through TryHackMe rooms. More certifications on the way.

tryhackme profile โ†—
where i've been

Education

Apr 2014 โ€“ Mar 2023

Air Force School, Jammu

UKG through Class 8 - foundational years. School activities, building curiosity, figuring out what actually interests me.

Jul 2024 โ€“ Jun 2025

NIOS - Class 10 (Secondary)

National Institute of Open Schooling. Completed secondary education - the flexibility helped me spend more time actually building things.

May 2026 โ€“ Jun 2027 current

NIOS - Class 12 (Senior Secondary)

Currently in senior secondary. Parallel to this: building projects, studying security, and finding out what kind of developer I want to be.

let's connect

Let's Connect

I'm 17, still in school, and building stuff in my free time. If you have feedback on my projects, want to collaborate on something, or just want to talk about security - I'm genuinely happy to hear from you.