Contact
How to reach us — including the request to leave your domain alone.
Four routes, and one of them exists because a company that reads other people's public records has to be reachable by somebody who never asked it to. All of them reach a person; none reaches a ticketing system, because we do not have one.
01 The routes
Who to write to, and what to put in it
Before launch
The details shown as {{TOKEN}} on this page have not been published
yet. They are supplied by the founders in one edit before launch, and they are shown as
tokens rather than guessed at, because an invented address is worse than an obvious
gap. Until they are resolved, the request form on the home page is the only
working route, and it reaches a person.
-
Route 01 · general
Questions about the service, or about a report you received
Email
{{CONTACT_EMAIL}}, or call{{PHONE}}. Technical questions are answered by somebody who can actually answer them. If you are asking about a report, quote the reference number on it so we can find the record. -
Route 02 · a free snapshot
Requesting a report for your own domain
Use the form on the home page. It is the only intake route, and it exists so that the two confirmations carrying legal weight — that you are authorised to request an assessment of that domain, and that you understand this is not a penetration test — are recorded with the exact wording you were shown and the time you agreed to it. We cannot start from an email that skips them.
-
Route 03 · your data
A copy of what we hold, a correction, or a deletion
Email
{{CONTACT_EMAIL}}with "Data request" in the subject line. Tell us the domain you submitted and the address you used, and say which you want: a copy of what we hold, a correction to it, deletion of it, or withdrawal of a consent you previously gave. You do not need to give a reason, and you do not need any particular form of words.We may ask one question to confirm you are the person who made the request, because handing somebody else's data to whoever asks for it would be the same failure in the other direction. Withdrawing consent is recorded as a new entry rather than an edit to the old one, so the history stays honest. How quickly we must complete each kind of request is set out in the Privacy Policy, which is published in draft while counsel reviews it.
-
Route 04 · do not assess us
Asking us never to look at your domain
You are entitled to ask, and we will do it. Email
{{CONTACT_EMAIL}}with "Do not assess" in the subject line and the domain or domains concerned, and tell us your role at the business. We add them to a permanent do-not-assess list, and a request naming any of them is refused from then on.Two things to know, both deliberate. We may verify that the request comes from somebody who can make it, because otherwise anyone could suppress a business they do not run. And we will never confirm to a third party whether a particular domain is on the list: if we did, the refusal message itself would become a way of finding out who had opted out.
02 Formal notices
ODPC registration: {{ODPC_NUMBER}}. Published here once the
certificate is issued; until then we do not claim to hold one.
Our Terms and Privacy Policy are published in draft, pending review by Kenyan counsel.
In writing, on paper
Legal notices, regulator correspondence and anything you would rather send by post go to {{POSTAL_ADDRESS}}, addressed to {{LEGAL_ENTITY}}, which is the company you contract with when
you engage us.
You also have a route that does not run through us at all. If you are unhappy with how we have handled your personal data, you can complain to Kenya's Office of the Data Protection Commissioner. We would rather you told us first so we can fix it, but that right does not depend on our agreement and we will not pretend otherwise.
03 Our own systems
It would be inconsistent to spend a whole site explaining why we do not connect to your systems without permission, and then quietly invite strangers to connect to ours.
If you have found a problem with this site
Tell us at {{CONTACT_EMAIL}} and we will take it
seriously and reply. We do not run a bug bounty and we cannot pay for reports.
The rule we apply to other people's systems applies to ours in reverse: this is not an invitation to test them. Kenya's Computer Misuse and Cybercrimes Act 2018, as amended in 2025, has no responsible-disclosure safe harbour, so unauthorised probing of our systems puts you at risk regardless of your intentions. If you want to look properly, write first and we will talk about authorising it.