Start with the thing the user touches.
A button, flow, form, or API. If the small path is confusing, the larger system only adds more noise.


about
I am Omar Al Sumih, Co-Founder & CTO at Mara. I work on products and systems that need clarity and security from the start, and I care about the details users do not always see: data, permissions, edge cases, and what happens after the first real use.
A button, flow, form, or API. If the small path is confusing, the larger system only adds more noise.
Permissions, data, edge cases, and production defaults. Small details show whether a product is ready or only pretending.
Mara, Daraa, Bootsec, Saqr, and the lab all come from the same loop: build it, break the assumption, fix it, then keep what is worth keeping.
projects
Saudi-first conversational wellbeing platform.
I work on turning the experience into a clear path: simpler flow, clearer boundaries, and stronger trust in daily use.
Co-Founder & CTO.
Open MaraA security baseline for small projects before launch.
It checks early mistakes: exposed secrets, weak defaults, and assumptions that should not reach production.
InfoSec experiment.
Open GitHubA Python tool for watching file changes.
It records a directory as a reference point, then shows what changed, appeared, or disappeared after that.
Security utility.
Open GitHubAn open-source repo intake tool for AI coding agents.
It structures the first read of a repository: what should be understood first, and what should be surfaced before an agent starts editing.
Open-source tool.
Open GitHubAn open-source Arabic-first helper for course registration flows.
It tries to make Saudi university portal flows easier to read and easier to use, instead of leaving students inside a scattered process.
Open-source student tool.
Open GitHubAn experiment for automating checks and launch readiness.
A way to make repeated security checks easier to track and less dependent on individual memory.
Security automation experiment.
Open Daraa
Local AI Lab
Understanding a system starts at its limits, not only at the final demo.
A local environment where I test models away from the polished demo layer. I care less about whether the model runs once, and more about how it behaves under pressure, where its limits appear, and what becomes visible when the API stops hiding the details.
Local testing before trusting the ready-made interface.
security papers
security paper 01
A space for short security research experiments, from MIZAN to MCP security notes: risk, privacy boundaries, and trust points before launch.




help
Security-focused startup product builds, product reviews, and working prototypes.
I am still a student, so I learn in the way that reveals the thing, not the way that decorates it.
I learn by building, not by long explanations. I start with a small version that runs, then pressure it with strange inputs, permissions, errors, and usage limits. That is where information security becomes a way to read the system, not a label above it.

Saudi
Our real wealth lies in the ambition of our people and the potential of our younger generation.
Mohammed bin Salman, Vision 2030