About
A new Kenyan company, saying so.
We have no track record to point at, no customer logos and no certifications, and we are not going to invent any. What we offer instead is a service you can judge before you engage us, a set of rules we work under in public, and an honest account of what we cannot do yet.
01 What we do
There is no dashboard, no login, no monitoring and no automated scanning. That is a description of the product, not a roadmap tease.
We read the public record and explain it in plain language
A business gives us a domain name and a work email address. A person then reads what is already published about that domain — the DNS records, the mail settings those records describe, public certificate transparency logs, and the public domain registry entry — works out which of it actually matters for a business of that kind, and writes a report. It arrives by email, normally within one to two business days. That is the whole of the free service, and at launch it is most of the company.
Everything else we sell follows from somebody reading that report and asking us to do the work rather than describe it: setting up email authentication properly, dealing with staff credentials that have appeared in a public breach, closing down things that should not be reachable from the internet. All of it is done by people. The prices are published for everything except the managed tier, which we quote after a conversation because we do not yet have a number we could defend.
02 Why we built it
An infringement can cost up to KES 5,000,000 or 1% of annual turnover, whichever is lower, per infringement. We quote it with the qualifier every time, because for most businesses reading this the turnover figure is far lower, and the headline number alone would be a scare rather than a fact.
The gap in this market is not technology. It is price and plain language.
A penetration test from a Nairobi consultancy starts around KES 100,000 and can reach a million. Managed security runs from KES 200,000 a month. Both are appropriate for a bank. Neither is available to a 40-room hotel, a six-bed clinic or a family-owned factory — which is most of the businesses that now sit squarely inside Kenya's data protection regime.
Those businesses are not short of warnings. They are short of a specific, sourced, readable answer to one question: what can a stranger see about us right now, and which part of it should we deal with first? That question can be answered from public records alone, without touching anybody's systems, for very little money. So we answer it for free and charge for the fixing.
The regulatory context makes it urgent rather than optional. Hospitals and hospitality businesses must register with the ODPC whatever their size, the regulator has already issued fines and announced sector inspections, and the Act expects businesses to review and test their systems regularly — and to be able to show that they did. The long version of that is written up as a guide: the Data Protection Act for Kenyan SMEs.
03 The rules we work under
Stated in public so you can hold us to them
-
Principle 01
Passive by default, and enforced rather than promised
For a domain whose control has not been verified, we read public records only: DNS, mail posture derived from DNS, certificate transparency logs, and the public registry entry — plus a password check that runs entirely in the visitor's browser. No TLS handshakes with your servers, no HTTP requests to your website, no port probing. This is a constraint in our software and in how a request is recorded, not a policy somebody could relax on a busy afternoon. Checks that connect to your systems unlock only after domain verification or written authorisation.
-
Principle 02
We will not claim to be invisible
Reading DNS means asking whichever name servers are authoritative for a domain, and those may belong to the business or to its provider. Any company telling you their outside-in check reaches nothing of yours at all is describing something that cannot be done. That single lookup is the only contact a free snapshot involves, and we say so rather than let you assume more.
-
Principle 03
Every number on this site traces to a source
Statutes, the regulator's own enforcement record, and published national figures from KE-CIRT and Serianu. If a claim cannot be traced it does not go on the site — which is why you will not find a statistic here about how many Kenyan SMEs are attacked, or what a breach costs on average. We do not know, and neither does anybody quoting those numbers at you.
-
Principle 04
A person reads every report before it is sent
Automated tools produce pages of alarming findings, some of which are wrong, and an owner cannot tell which. Ours does not go out until somebody has checked that each finding is real and that the explanation makes sense to a non-technical reader. It costs us time and it caps how fast we can grow. It is also the product.
-
Principle 05
We say what we could not see
Every report states its own limits: what was looked at, what was out of reach, and how much confidence the rating deserves. A free snapshot is never rated high confidence, because it rests on external evidence alone. A company trying to impress you would leave that page out.
-
Principle 06
We do not sell compliance, and we do not sell fear
No report from us makes a business compliant with the Data Protection Act; compliance is broader than any technical control and stays with you. And no fine figure appears here without its statutory qualifier. If an argument only works when the numbers are exaggerated, it is not an argument.
-
Principle 07
Findings go to you, privately, first
We do not publish findings about a business, name anybody in marketing, or use a serious finding as a sales lever. If something has wider public consequences, the route for that in Kenya is the national response team, KE-CIRT, not a press release.
04 What we are not
This list will get shorter. Publishing it while it is long is the point: it is the same honesty the reports are written with, applied to ourselves.
The things a competitor would leave off this page
- We are not a platform. No dashboard, no login, no monitoring, no alerting, no automated scanning, and no automated confirmation email. A person handles each request.
- We are not ODPC-registered yet. We are registering as a data controller ourselves and will publish the number here when the certificate is issued. Until then we do not claim to hold one.
- We have no customers to name. No logos, no testimonials, no case studies, no ratings, no "trusted by". When we have customers who agree in writing to be named, they will appear — and not before.
- We hold no certifications. Not ISO 27001, not anything else.
- Our legal documents are drafts. They are written and published so you can read them, and they are with counsel. Every one carries a draft banner until that review is finished. Read them here.
05 Who we are
Legal entity: {{LEGAL_ENTITY}} — the company you would
actually be contracting with.
ODPC registration: {{ODPC_NUMBER}} — published once the
certificate is issued.
The people, when they are ready to be named
Reconesys is a small founder-run company in Nairobi. We have deliberately not written biographies for people who have not approved them, and we will not publish stock photographs of strangers at laptops in their place. When the founders supply their own words, they go here:
{{FOUNDER_BIOS}}
Until then, the honest version is this: judge the work rather than the people. Read the sample report, and read how it is produced. That is what we would want to see from a company we had never heard of.
One free snapshot per domain every 30 days. We read public records — DNS, mail records, certificate transparency logs and the domain registry. We never connect to your website or servers, never log in, and never test your defences. This is not a penetration test.
Find out what a stranger already knows about your business
One domain, read from public records, written up by a person and emailed to you in one to two business days. Free. Nothing to install, no payment details, no account.