Questions · answered plainly
The questions a careful buyer asks first.
Grouped by what is actually being asked: is this legal, can we be trusted, what happens to our data, and what will this not do. Questions about money — what things cost, how you pay, why there is no price on the managed tier — are answered on the pricing page instead.
01 Legality
Whether this is allowed, and who gets to ask for it
- Is it legal for you to read these records about my business?
- Yes, and the distinction matters. Everything a free snapshot reads is already published by somebody: your DNS operator, the certificate transparency logs run by third parties, and the domain registry. Reading a published record is not access to a computer system. Connecting to your servers to test them is, and Kenya’s Computer Misuse and Cybercrimes Act 2018, as amended in 2025, requires your written authority for that — which is why those checks stay switched off until you verify the domain or authorise us in writing.
- Will your check show up in our logs?
- Not in your web server’s logs, because we make no request to your website. What we will not claim is that nothing of ours reaches you at all: looking up a domain asks whichever nameservers are authoritative for it, and if you or your provider run those, that query is one they could see. It is an ordinary public lookup of the kind every mail server on the internet makes to find you, and it is the only contact a free snapshot involves. Any supplier telling you their outside-in check reaches nothing at all is describing something that cannot be done.
- Someone could ask you to assess my domain without my permission. What stops them?
- Two things. A request carries a confirmation that the person making it is authorised to request an assessment of that domain, stored with the exact wording they were shown and the time they agreed to it — so there is a record rather than an assumption. And any business can ask us never to assess its domain: email us with "Do not assess" in the subject line and we add it to a permanent list, after checking that the request comes from somebody who can make it. We will never confirm to a third party whether a particular domain is on that list, because the refusal itself would otherwise become a way of finding out who had opted out.
- Do you report what you find to the regulator, or publish it?
- No. Findings go to the business that asked for them, privately. We do not name anybody in marketing, do not write case studies about somebody else’s weaknesses, and do not use a serious finding as a sales lever. Where something has consequences beyond one business, the route in Kenya is the national response team, KE-CIRT, and it is not a press release.
The full scope, source by source, is on what we check. The route for a business asking us never to assess its domain is on the contact page.
02 Trust
Judging a company with no track record
- Why should I trust a company I have never heard of?
- You should not, on our word. We are new, we have no customers we can name, no certifications and no track record, and we are not going to invent any of those. What we offer instead is a service you can judge before you engage us: a complete worked sample report you can read now, a published account of exactly what we read and what we refuse to touch, and our legal documents published in draft — including the ones that constrain us — so you can find the gaps before you rely on them.
- Do I need to install anything, give you a login, or open a firewall?
- None of those. There is nothing to install, no account to create, no agent, no password to hand over and no firewall change. You give us a domain and a work email address, and that is the entire input. If anybody asks a Kenyan business for a login in order to run a free external check, that is worth refusing.
- Is there a dashboard or a portal I log into?
- No. At launch there is no dashboard, no login and no automated pipeline: a person reads the records, writes the report and emails it to you. There is also no automated confirmation email, so if you do not hear back instantly nothing has gone wrong — a human being is doing the work. We would rather tell you that than imply a platform that does not exist.
- How long does it take, and what happens if it is late?
- One to two business days. Weekends and public holidays push it to the longer end. If it is going to take longer than that, we email you and say so rather than leaving you wondering. There is no service-level commitment behind that figure and we do not pretend there is one.
The strongest answer we have to this is the work itself: read a complete sample report, then read how it is produced and who we are today.
03 Your data
What we collect, keep, and hand back
- What do you actually collect from me, and what do you do with it?
- The domain you submit, a work email address, optionally your sector, and the record of the two confirmations you ticked. The email address is encrypted in our database, with the key held outside it. We use it to send your report and to answer you. We do not sell your data, we do not rent it, and we do not share it with anybody for their own marketing. Practical guidance emails are a separate, unticked choice you can withdraw at any time without affecting anything else.
- How long do you keep it?
- Your contact record for 24 months from the last time we heard from you, then it is erased. The report and the findings behind it for 12 months. The raw record extracts captured while writing a free report for 30 days, after which the report itself is the record. The proof of what you consented to is kept longer, because it is the evidence that you asked us — deleting that would leave us unable to show we were authorised. These are the draft retention periods and they are in the Privacy Policy, which counsel is reviewing.
- Can I get a copy of what you hold, or have it deleted?
- Yes, both, and you do not need to give a reason or use any particular form of words. Email us with "Data request" in the subject line, tell us the domain you submitted and the address you used, and say whether you want a copy, a correction, deletion, or to withdraw a consent. We may ask one question to confirm you are the person who made the request, because handing somebody else’s data to whoever asks for it would be the same failure in the other direction. The deadlines are set by law and differ by request — a copy of your data is seven days, free of charge, under the Data Protection (General) Regulations 2021 — and the Privacy Policy sets out each one.
- Does the password check send my password anywhere?
- No. It runs entirely inside your own browser. Your password never leaves your device, and neither does the full fingerprint of it — only the first five characters of that fingerprint are sent, and they go to Have I Been Pwned, a public breach index run by a third party. Because your browser makes that request itself, they can see your IP address, exactly as any website you visit can. They never receive your password, your full fingerprint, your domain or your email. Neither do we: there is no page on this site that asks you to type a password and send it to us.
The full account is in the Privacy Policy, published in draft while Kenyan counsel reviews it, alongside the technical note written for whoever is asked whether this is safe to allow.
04 Limits
What this will not do for you
- Is this a penetration test?
- No, and we will not call it one. A penetration test is an authorised attempt to break in, performed against systems you have given somebody written permission to attack. A snapshot reads records other people have already published about your domain. If what you need is a penetration test, Kenyan consultancies do them properly from around KES 100,000 and we will say so rather than sell you a substitute.
- Does a snapshot make us compliant with the Data Protection Act?
- No. Compliance covers how you collect personal data, what you tell people, how long you keep it, who you share it with, your supplier contracts and your staff training. A snapshot gives you dated documented evidence about one technical control — what your business exposes externally — which is a genuine part of the Act’s expectation that you review and test your systems regularly, and is not the whole of it. Anybody selling you compliance in a box is selling something that does not exist.
- Do you keep watching our domain after the report?
- No. Nothing watches your domain afterwards, nothing alerts you if something changes, and no sales sequence starts. If the report is useful and you want nothing else from us, that is a fine outcome. The monthly option is a person reading the same public records again and writing you a short note on what changed — not monitoring, not alerting, and not incident response.
- What can a snapshot not see?
- Everything inside your building. Your internal network, staff laptops, point-of-sale, Wi-Fi and clinical or production systems are invisible from outside, and we will not pretend to have seen them. It also cannot prove you are safe: it is the outside view on one day, so a clean result is good news about the outside and nothing more. The report states that on its front page, along with how much of the picture the rating rests on.
Stated before you engage us rather than after, because a supplier who tells you the limits first is easier to check than one who tells you the capabilities first.
One free snapshot per domain every 30 days. We read public records — DNS, mail records, certificate transparency logs and the domain registry. We never connect to your website or servers, never log in, and never test your defences. This is not a penetration test.
Find out what a stranger already knows about your business
One domain, read from public records, written up by a person and emailed to you in one to two business days. Free. Nothing to install, no payment details, no account.