We break systems
before attackers do.
Independent penetration testing, ERP and application security audits, and security-first builds for SACCOs, fintechs and retailers across East Africa.
Signed rules of engagement · No destructive testing
NDA-bound · ODPC-registered data handling
Discipline is the point.
An offensive-security partner is only useful if it can be trusted with production systems and confidential data. Four rules hold on every engagement.
Scoped & authorized
Testing begins only after a signed proposal, written authorization and agreed Rules of Engagement.
Non-destructive
No denial-of-service, no data alteration, no persistence, no unapproved social engineering.
Confidential by default
Findings, client identities and reports are shared only with authorized recipients.
Verified, not scanned
Every finding is manually confirmed and reproduced before it reaches your report.
What we're brought in to do
Assessment and assurance across the systems your business actually runs on — and, when you need it, the secure build itself.
Penetration Testing & VAPT
Web, API, network & mobile — manual testing mapped to real attack paths.
WEB · API · NETWORK · MOBILEERP & Systems Security Audit
Governance, configuration & business-logic review of the platform you run on.
Application Security
Secure code review, business-logic testing, independent code verification & handover.
Data Protection & Compliance
ODPC (Kenya) registration & readiness, remediation roadmaps, board risk narratives.
Security Retainer
Month-to-month implementation of recommendations and continuous posture management.
Secure Development
We design and build the platform with security engineered in, not audited on.
Engagements, anonymized
Client identities stay confidential. The sector, the systems, the finding themes and the outcome do not.
SACCO ERP Security Audit & Retainer
// Member-owned SACCO · Cloud core-banking / ERP platform
Full security audit of a cloud core-banking platform, its infrastructure and integrations, followed by an ongoing monthly retainer implementing the fixes.
Read the engagement →Regional Fintech VAPT
// Regional lending platform · Web application + supporting APIs
Comprehensive vulnerability assessment and penetration test of a regional lending platform, with an executive briefing to the board and a prioritized remediation roadmap.
Read the engagement →Mobile App Penetration Test
// Consumer-facing service · Mobile application (client, transport, API)
Mobile penetration test of a consumer-facing application under a signed Statement of Work, covering the client build, transport layer and backing APIs.
Read the engagement →Secure Commerce Platform Build
// Hardware retail chain · Headless CMS + storefront + mobile commerce app
Designed and built a headless CMS, storefront and mobile commerce app for a retail chain — access control, tenancy and payment flows engineered in from the schema up.
Read the engagement →A defined sequence, every time
You always know which phase we're in, what's been touched, and what comes next.
Scope & RoE
Targets, windows, limits, contacts — in writing.
Recon & mapping
Attack surface, data flows, trust boundaries.
Manual testing
Exploitation against approved assets only.
Verification
Every finding reproduced and impact-rated.
Executive briefing
Plain-language risk narrative for the board.
Remediation roadmap
Prioritized, owned, with target dates.
Retest & retainer
Confirm fixes; continue if you want cover.
Evidence a board can act on
No 400-page scanner dump. Four deliverables, each written to be used.
Verified findings register
Each finding reproduced, severity-rated, evidenced with the steps to confirm it.
Executive risk narrative
What it means for the business, in language the board reads without a translator.
Prioritized remediation roadmap
Accountable actions, sequencing and target timelines — not just "fix everything".
Free retest
We re-check remediated findings within the engagement window at no extra cost.
Start here
Ready to find out what an attacker would?
Every engagement starts with a confidential scoping call. Tell us the system, the timeline and the concern — we'll tell you what's realistic.