About Me

I'm Nicholis, or as I'm known online, TrueWinter, a software and website developer from South Africa. I also find and responsibly disclose security vulnerabilities, helping companies to patch these before they can be maliciously used by an attacker.



  • Node.js
  • PHP
  • Bash
  • Java (very basic)


  • HTML
  • CSS
  • JavaScript
  • jQuery
  • Bootstrap
  • Website Security


  • Linux
  • DNS
  • pfSense
  • IPv4 Addresses and Subnets
  • WireGuard and GRE
  • BGP (basic)
  • Email (basic)


Company Role Period
Redacted for privacy IT Manager November 2016 - Present
Redacted for privacy is a business in the tourism industry. I manage all of their IT infrastructure, including computers, servers, routers, access points, phones and tablets. I also manage the website, where I try to ensure that it is responsive (easily adapts to different screen sizes) and all pages load as fast as possible. I was also tasked with creating a custom point of sales system to satisfy the needs of the business.
Independent Security Researcher January 2019 - Present
I work independently as a security researcher and bug bounty hunter. I have reported security vulnerabilities to many companies, including Vodafone, Citrix, and Freshworks.
Endless Hosting Signups and Support Team September 2019 - August 2021
Endless Hosting is a free web host offerred by Endless Group, a US-based non-profit. I volunteered at Endless Hosting, handling support tickets, and handled signup requests when they used a manual signup system.