Abdul Mannan Qayyum
← Work

KingSec

Shipped

VantriqSec’s first flagship: a local-first external security assessment tool, released as v0.2.0 and currently pre-commercial.

KingSec is the first flagship product from VantriqSec, an early-stage cybersecurity company based in Pakistan and founded by Abdul Mannan Qayyum. VantriqSec follows a services-led approach; KingSec is being developed to support scoped external assessments.

Current release

v0.2.0 has been released and merged into main. KingSec runs locally and supports unauthenticated external assessments of authorized targets. It brings together findings from six scanner integrations: Nmap, Nuclei, Nikto, ffuf, Gobuster, and OWASP ZAP, with PDF and HTML report generation.

The release is pre-commercial. Engineering figures and remediation status in this case study are reported by the founder.

Engineering

The backend uses Python with a hexagonal architecture, separating core assessment logic from scanner integrations. The founder reports approximately 4,300 backend tests. The React and TypeScript frontend has 31 pages, with SQLite storage and Alembic database migrations.

The aim is a local assessment workflow that makes findings, report coverage, and scanner limitations clear to the operator.

Reliability and remediation

The founder reports completion of eight-plus remediation phases, covering broken scans, scanner timeouts, missing web-scanner findings, misleading “Sound” status handling, and fabricated CVE references. Documentation review also removed 12 false claims and nine unsupported claims.

This work focuses on making scan results and reports reflect what the assessment actually covered. An assessment’s usefulness depends on both its findings and a clear account of checks that failed or were incomplete.

Scope and commercial readiness

KingSec’s current scope is unauthenticated external assessment: an accessible first pass for organizations preparing for a fuller engagement. It is not a penetration test, SOC, SIEM, EDR, or enterprise platform. Every report discloses its coverage limits and must be read within the scans actually performed.

Four prerequisites remain before sale:

  • A complete walkthrough by a first-time customer to validate the workflow.
  • Clarification of Nmap licensing for the intended commercial use; an answer is pending.
  • Review of the service agreement and assessment authorization by Pakistani commercial counsel.
  • Two report corrections: asset attribution and port-related severity.

The release milestone demonstrates development progress; commercial availability depends on completing this work.

What comes next

Attack Path Intelligence Platform is a planned, separate product intended to consume KingSec findings and explore relationships between security weaknesses. Development has not started.