Most Kenyan businesses discover a security problem the same way — a customer reports something strange, a payment fails oddly, or a partner's compliance team asks a question nobody can answer. By then the question is no longer "are we exposed?" but "how long have we been?"

An Authorized Web & API Security Assessment answers that question on your terms, under written permission, before someone else answers it for you.

Who this is for

SMEs, startups, NGOs, and established teams running a public web application, a customer portal, or an internal API that touches personal or financial data. It is particularly relevant if you are:

What gets reviewed

The assessment uses the OWASP Top 10 and the OWASP API Security Top 10 as its structural baseline, verified by hand rather than by scanner output alone. Automated tooling finds candidates; a human confirms whether each one is actually exploitable in your context.

Review AreaWhat Is Examined
Authentication & SessionLogin flows, session lifetime, token handling, password-reset abuse paths, multi-factor coverage.
AuthorizationBroken object-level authorization (BOLA), privilege escalation between roles, tenant isolation.
Input HandlingInjection surfaces, unsafe deserialization, file-upload handling, server-side request forgery.
API SurfaceUndocumented and legacy endpoints, rate limiting, mass assignment, excessive data exposure in responses.
ConfigurationSecurity headers, TLS configuration, CORS policy, verbose error output, exposed admin paths.
Secrets & CredentialsKeys in client bundles, repository history, environment misconfiguration, third-party token scope.
Data ProtectionPII at rest and in transit, logging leaks, retention behaviour, KDPA lawful-basis alignment.

The boundary — permission before testing

RULES OF ENGAGEMENT
No assessment begins without a signed scope defining exactly which hosts, applications, and endpoints are in scope, which are explicitly excluded, the testing window, and the escalation contact. Testing is non-destructive by default. Denial-of-service, social engineering of staff, and any activity against systems outside the agreed scope are excluded as a matter of policy, not negotiation.

What you receive

Evidence and method

The methodology behind this service is documented publicly rather than asserted. See the SOC incident walkthrough for triage and investigation approach, and the KDPA Developer Checklist for how regulatory obligations are translated into code-level controls. Commercial delivery experience is recorded in the Munar security baseline and handover.

How engagements start

Most clients begin with the Secure Digital Workflow Assessment, a fixed-scope two-to-three-week discovery engagement that establishes the current-state map and identifies whether a deeper technical assessment is warranted. It is the cheapest way to find out what you actually need.

START HERE

Engagements begin with a fixed-scope scoping call. Clear decisions before code, and no obligation to proceed to follow-on build work.

Request a Scoping Call →

Related: Secure Automation & AI Workflow Review · All services