For hospitals, hotels and factories in Kenya

Your business already has a public record.

Here is one, for a hotel that does not exist. Four public sources, read by a person, explained in the words an owner actually uses. We will do the same for your domain, free, and send it back in one to two business days.

We read public records — DNS, mail records, certificate transparency logs and the domain registry. We never connect to your website or servers, never log in, and never test your defences. This is not a penetration test.

Record acaciagardens.example

Read 2026-07-21 · four sources, three groups · public records only

DNS · mail posture

dig +short acaciagardens.example MX TXT

MX 10 mx1.mailhost.test.
TXT "v=spf1 include:_spf.mailhost.test ~all"
TXT _dmarc "v=DMARC1; p=none; rua=mailto:dmarc@acaciagardens.example"

F-01 High

Anyone can send mail as this hotel

DMARC is published but set to p=none, which asks receiving servers to do nothing about a failure. SPF ends in ~all, a soft fail, so a forged message is delivered rather than refused. A booking confirmation sent from a stranger’s server, addressed as this hotel, reaches the guest.

Certificate transparency

crt.sh?q=%25.acaciagardens.example

2026-05-02 *.acaciagardens.example
2025-11-18 booking-admin.acaciagardens.example
2024-07-30 vpn-nairobi.acaciagardens.example

F-02 Medium

Two names nobody meant to publish

Every certificate ever issued for a domain is written to a public log, permanently, by design. These two name systems rather than pages. We read the log, which is a third party’s; we did not go and look at either host.

Domain registry · RDAP

rdap.example-registry.test/domain/acaciagardens.example

status clientTransferProhibited
expires 2027-03-19
ns ns1.hostpartner.test, ns2.hostpartner.test

F-03 Clear

The registrar lock is on

clientTransferProhibited means the domain cannot be moved to another registrar without being unlocked first. Domain theft is a real way Kenyan businesses lose their email overnight, and this door is shut. Reports rarely say what is working.

Worked example. acaciagardens.example is a fictional business on a domain reserved by RFC 2606, as are the .test hostnames beside it. It is not a customer and the records are illustrative.

The obligation

None of this is our opinion. It is the statute, the regulator’s own enforcement record and the national threat figures.

Sources

  • Data Protection Act 2019
  • Registration Regulations 2021, Third Schedule
  • ODPC enforcement record
  • Digital Health Act 2023
  • Communications Authority / KE-CIRT quarterly reports
  • Serianu Africa Cyber Security Report 2024/25

The law already applies to you. Being small is not the exemption most owners think it is.

  • Registration is mandatory for two of our three sectors, at any size

    Under the Third Schedule of the 2021 Registration Regulations, health administration and the provision of patient care and hospitality must register with the Office of the Data Protection Commissioner regardless of size. A six-room guest house is covered on the same basis as a chain.

    Outside those sectors a business is exempt only if its annual turnover is below KES 5 million and it employs fewer than 10 people — both conditions, not either. Registration costs KES 4,000 for a micro or small business up to KES 40,000 for a large one, and the certificate runs for 24 months.

  • The fine has a ceiling and a cap, and the cap is the part that matters

    An infringement can cost up to KES 5,000,000 or 1% of annual turnover, whichever is lower, per infringement.

    Read that qualifier carefully, because most people quoting this number at you will leave it off. For a business turning over KES 40 million a year, 1% is KES 400,000 — a tenth of the headline. The ceiling is real and so is the cap, and a supplier who only tells you the frightening half is telling you the half that sells.

    Administrative penalties issued by the ODPC
    Date Organisation Sector Penalty issued
    Dec 2022 Oppo Kenya Consumer electronics KES 5,000,000
    Sep 2023 Casa Vera Lounge Hospitality KES 1,850,000

    These are amounts actually issued, not the statutory maximum. The regulator has since announced inspections of the hospitality sector.

  • The duties are technical, and they do not end

    The Act expects security safeguards, audit trails and event monitoring, regular testing of your software for weaknesses, and notification of a breach within 72 hours. Hospitals carry the Digital Health Act 2023 on top of that, and health services can be designated critical information infrastructure, which raises the stakes again.

    A dated report on your external exposure, and a record of what you changed after it, is evidence for one of those duties. It is not compliance, and we will not sell it as compliance. Compliance covers what you collect, what you tell people, how you store it, who you share it with and how your staff are trained. This is one technical control out of many, documented.

  • The volume behind it is not aimed at you, which is the problem

    KE-CIRT, Kenya’s national cyber response team, detected 4.56 billion threat events in the fourth quarter of 2025, a 441% rise on the quarter before, and 3.37 billion in the first quarter of 2026. Serianu puts Kenyan cybercrime losses at roughly USD 230 million — about KES 29.9 billion — across 2024 and 2025.

    Almost none of that traffic chose you. It is automated, it is indiscriminate, and it does not check how many rooms you have first.

The free snapshot

Four public records, and a list of everything we leave alone.

Read What the snapshot covers

  • DNS

    The records that point at your business

    Where your website resolves, who runs your nameservers, which mail servers you publish, and what stray records an old supplier left behind. The domain name system answers all of it to anyone who asks, which is what it is for.

  • SPF · DKIM · DMARC

    Whether a stranger can send email as you

    The three published settings that tell the world’s mail servers whether a message claiming to come from your domain is genuine. When they are missing or set to soft-fail, a criminal can email your guests, your patients or your suppliers from what looks like your own address, asking them to pay a different account. This is where Kenyan businesses actually lose money, and it is usually the cheapest thing on the list to fix.

  • CT logs

    What your own certificates have announced

    Every HTTPS certificate ever issued for your domain is written to a public log, permanently, by design. Those logs routinely carry internal-sounding names a business never meant to publish — a staging server, an old booking system, an admin panel. We read the log. We do not go and look at what it names.

  • RDAP

    What the registry says about the domain itself

    Who the domain is registered through, when it expires, and whether it is locked against transfer. An expired or unlocked domain is how a business loses its email address overnight, and it is a public registry record, not something of yours.

A fifth check — whether a password of yours appears in a known public breach — runs entirely inside your own browser and sends us nothing. Run it further down this page.

Not read What it does not cover

  • It is not a penetration test, a security audit or a vulnerability scan. We do not attempt to break into anything.
  • No TLS handshake with your servers, no HTTP request to your website, no port probing. Those require your permission under Kenyan law and stay switched off until you verify domain control or authorise us in writing.
  • Nothing inside your building. Your internal network, staff laptops, point-of-sale and Wi-Fi are invisible from outside, and we will not pretend to have seen them.
  • It cannot prove you are safe. It is the outside view on one day. A clean external picture is good news about the outside and nothing more.
  • It is not monitoring. No watching afterwards, no alerts, no incident response and no response-time commitment. Nothing happens after the report unless you ask.
  • It does not make you compliant with the Data Protection Act. It is documented evidence about one technical control. Compliance is broader and stays yours.

Being clear about this matters more to us than sounding impressive. Two of these — what your live site actually serves, and how your TLS is configured — need your permission before anyone may look, and they unlock once you verify that you control the domain.

We read public records — DNS, mail records, certificate transparency logs and the domain registry. We never connect to your website or servers, never log in, and never test your defences.

Our intake API returns this same sentence in every response, as passive_statement. The page and the contract cannot drift into two different promises.

How it works

Most of the work is ours, and one of the four steps is a person reading your results rather than a machine sending them.

Four steps. The third one is a human being, and that is the point.

  1. 01

    You send us a domain and a work email

    That is the whole form. Under a minute, nothing to install, no payment details and no account to create.

    You also confirm two things on the record: that you are authorised to request this for the domain, and that you understand it is not a penetration test. Both are stored with the exact wording you agreed to and the time you agreed to it, because an attestation nobody can reproduce is not a record.

  2. 02

    We read the four public records

    Your DNS records and the mail posture derived from them, the certificate transparency logs, and the public domain registry. We never connect to your website or servers, never log in, and never test your defences.

    This part is quick. It is also the part that requires no permission from you, which is exactly why the free tier stops here.

  3. 03

    A person reads the result and writes the report

    This is the slow part, and it is deliberate. Automated security tools are famous for producing pages of alarming findings that turn out to be wrong, and a hotel owner has no way to tell which is which.

    Nothing goes out until someone has checked that each finding is real, that the severity is honest, and that a non-technical reader can act on it. At launch that person is one of the founders. It costs us time, and it is the reason the report is worth reading.

  4. 04

    It reaches you in one to two business days

    By email, from a person. You get an A to E rating with the reasoning behind it, an honest confidence level, your top three issues ranked by what they would actually cost you, what is already working, and a 30-day plan naming who should do each thing — you, your IT provider, your host, or us.

    Then nothing happens unless you ask. No sales sequence, no calls you did not request. If the report is useful and you want nothing else from us, that is a fine outcome.

What is not behind this yet

There is no automated pipeline, no dashboard and no login. Pressing submit does not fire a confirmation email — a person picks the request up and replies to you. Weekends and Kenyan public holidays push the turnaround to the longer end, and if it is going to take more than two business days we write and say so.

We would rather tell you that now than have you sitting waiting for an email that was never going to arrive.

Request a snapshot

One domain. One report. Written by a person.

Free, and free of the usual conditions: no payment details, no software, no account and no call unless you ask for one.

Cost
KES 0
Turnaround
1–2 business days
Delivered by
A person, by email
Repeatable
Once per domain per 30 days

We read public records — DNS, mail records, certificate transparency logs and the domain registry. We never connect to your website or servers, never log in, and never test your defences.

Free exposure snapshot

Tier 0 · passive only

Just the domain. No https://, no page address.
Where the report goes. A work address, not a temporary one — we cannot honour a later deletion request at an address that has disappeared.
Used on the report cover.
Before we start

Optional, and off by default

Not a penetration test

This form needs JavaScript

Your consent record is submitted as a structured document, which this page builds in your browser. Without JavaScript it cannot, so the form above will not send.

Write to us instead, at {{CONTACT_EMAIL}}, with your domain, your work email, and a line confirming that you are authorised to request this for the domain and that you understand it is not a penetration test. A person reads that mailbox and it reaches the same queue.

Runs in your browser

Check a password without giving it to anybody.

Including us. The password never leaves this device, and neither does the full fingerprint of it — five characters do, and five characters describe about one in a million passwords.

Transmission ledger

Stays here

  • The password you type.
  • 35 of the 40 characters of its SHA-1 fingerprint.
  • The comparison itself, and its result.

Leaves here

  • The first 5 characters of the fingerprint, sent to Have I Been Pwned at https://api.pwnedpasswords.com/range/.
  • Your browser’s IP address, disclosed to Have I Been Pwned the way it is to any site you visit. We do not control that and will not claim otherwise.

Password self-check

Client side · not a finding

Nothing is sent until you press the button, and what is sent is shown to you afterwards.

This is a self-reported observation, not something we collected. It changes no rating, appears in your report only if you tell us the answer, and there is no page on this site that accepts a password submission.

Pricing

A consultant-led penetration test in Kenya typically starts around KES 100,000, and managed security runs from KES 200,000 a month. That is the right product for a large organisation. It is not the right product for a 40-room hotel.

Prices you can read before you talk to anyone.

Reconesys price list · USD with KES equivalent
Offer What it is USD KES ≈129/USD
Free snapshot One domain. Four public records, read and written up by a person, back in one to two business days. Once per domain every 30 days. Free KES 0
Watch The same public records re-read every month on a domain you have verified, with a short written note on what changed. Not alerting, and not monitoring in the real-time sense — a monthly letter, delivered by hand at launch. USD 19 a month about KES 2,450
Fix sprint: Email & Domain Shield SPF, DKIM and DMARC set up properly, stray DNS records cleared, and the records re-read afterwards to show it worked. The fix most businesses turn out to need. USD 199 once about KES 25,700
Fix sprint: Breach Response Work out which staff accounts are affected, walk your team through resetting them in the right order, and harden whatever let it happen. USD 299 once about KES 38,600
Fix sprint: Website Cleanup Close the panels and services that should not be reachable from the public internet, and fix TLS and configuration problems. Requires domain verification or written authorisation, because this one involves looking at your systems directly. USD 399 once about KES 51,500
Managed protection Ongoing protection and a documented compliance trail for hospitals, hotels and factories, scoped to your sites, domains, staff identities and devices. Quoted after a short scoping conversation. Request a quote
  • Prices are set in US dollars and shown with the Kenyan shilling equivalent at about 129 shillings to the dollar (July 2026). You are billed in shillings, and the conversion moves with the rate.
  • There is no online checkout. We invoice you and you pay by M-Pesa, or by card on request. All paid work is delivered by people at launch.
  • Managed protection and deeper authorised assessments are quoted after a scoping conversation. We do not publish a figure for them, because we have not yet validated one and an unvalidated price is a number you would find out was wrong.

Full pricing, scope and what each sprint includes