Scope · the register
Everything we read, and everything we leave alone.
This is the page to forward to whoever is asked whether it is safe to let us do this. Five sources, one of which runs inside your own browser; two checks deliberately switched off until you prove the domain is yours; and a list of things we will not do at any tier or any price. Set out as a register rather than a pitch, so it can be checked line by line.
01 The sources
Five things we read, and who publishes each one
Every row below is already published about your domain by somebody other than you — your DNS operator, a certificate log run by a third party, the domain registry. We are reading the same records a criminal would start with, and we are reading them in the same way: from the outside, with no privileges, and with nothing installed anywhere.
| Source | What it shows | Who publishes it | Reaches your systems? |
|---|---|---|---|
| DNS records A · AAAA · MX · NS · TXT | Where your website resolves, who runs your nameservers, which mail servers you publish, and what stray records an old supplier left behind. | Your DNS operator, answered by whichever nameservers are authoritative | Yes — one ordinary public lookup |
| Mail posture SPF · DKIM · DMARC | Whether a stranger can send email that appears to come from your domain to your guests, patients or suppliers. | You, in the TXT records above — no separate source is queried | No — read from the same lookup |
| Certificate transparency CT logs | Every HTTPS certificate ever issued for your domain, including the internal-sounding hostnames a business never meant to publish. | Certificate authorities and log operators — third parties, not you | No |
| Domain registry RDAP | Your registrar, when the registration expires, and whether the domain is locked against transfer. | The registry and your registrar | No |
| Password check In your browser · optional | Whether a password you use has appeared in a known public breach. You choose whether to run it at all. | A public breach index run by Have I Been Pwned | No — and nothing reaches us either |
The password check is the one row you control completely: it runs on your device, only the first five characters of a fingerprint of the password are sent, and they go to a public breach index rather than to us. There is no page on this site that asks you to type a password and send it here. Background on all five sources: what a stranger can already see.
02 The claim
The same sentence is returned by our intake service in every response, so the page and the contract cannot drift into two different promises.
Stated exactly, including the part that is not absolute
What we do
We read public records — DNS, mail records, certificate transparency logs and the domain registry. We never connect to your website or servers, never log in, and never test your defences.
What we will not tell you is that nothing of ours ever reaches anything of yours. Looking up a domain asks whichever nameservers are authoritative for it, and those may be machines you or your provider run — so a lookup of the ordinary kind every mail server on the internet makes to find you is the one point of contact. Any supplier claiming their outside-in check reaches nothing at all is describing something that cannot be done.
Everything else in the register above is read from records held by third parties. Nothing we do opens a connection to your website, your ports or your applications, and on a domain whose control you have not verified that is enforced in our software rather than promised in our marketing.
03 Switched off
Two useful checks we are not allowed to run yet
These are worth having and we are not withholding them to sell you something. They connect to your systems, Kenyan law requires your permission first, and permission means a record that you gave it — not a checkbox on a form anybody could have ticked.
| Check | What it would tell you | Why it is off | What turns it on |
|---|---|---|---|
| What your website actually serves | Whether an admin panel, an old staging site or a forgotten application is reachable from the public internet. | It requires an HTTP request to your server, which is a connection to your system. | Domain verification — about ten minutes, and the check is still free |
| How your TLS is configured | Whether your certificate, protocol versions and cipher configuration are current, and when the certificate expires. | It requires a TLS handshake with your server, which is a connection to your system. | Domain verification — about ten minutes, and the check is still free |
| Changing anything you own | Nothing on its own. This is the fix work rather than the reading. | We would be altering your configuration, so your instruction has to exist as a record. | A paid engagement you asked for. The sprint that connects to your systems needs verification or written authorisation as well |
Proving domain control takes about ten minutes: a DNS record we give you, a file on your web server, or a code sent to an address at your own domain. The reason the line is drawn here rather than somewhere more convenient is Kenya's Computer Misuse and Cybercrimes Act 2018, as amended in 2025, which separates reading what is published from connecting to somebody's system to test it. The second needs their written authority, and Kenya has no responsible-disclosure safe harbour.
04 Never
Not at any tier, and not at any price
-
We do not attempt to break in
No exploitation, no password guessing, no attempt to get past anything. This is not a penetration test, a security audit or a vulnerability scan, and we do not sell one. Nothing changes that at any tier or any price.
-
We do not test your people
No phishing simulations, no calls to your reception pretending to be a supplier, no approaches to your staff at all. If you want that done, it is a real and useful exercise and somebody else sells it.
-
We do not assess a domain nobody asked us to
A snapshot exists because somebody at that business asked for it and confirmed they were authorised to, and their confirmation is stored with the exact wording they were shown. A business can also ask us never to assess its domain, and we keep that refusal permanently.
-
We do not publish what we find
Findings go to the business, privately. We do not name anybody in marketing, do not use a serious finding as a sales lever, and do not write case studies about somebody else’s weaknesses. Where something has wider public consequences, the route in Kenya is the national response team, KE-CIRT, not a press release.
-
We do not watch anything afterwards
A snapshot is one day’s picture. No monitoring, no alerting, no incident response and no response-time commitment. The monthly option is a person re-reading the same public records and writing to you, which is a different thing and is described as one.
-
We do not sell you compliance
Nothing here makes a business compliant with the Data Protection Act. It is documented evidence about one technical control — your external exposure — which is a real part of what the Act expects and is not the whole of it.
05 What you get
A person reads all of it before it is sent. That is the expensive part of this service and it is the reason the report is short.
Five records in, one plain-language report out
What comes back is not a dump of the records above. It is an A to E rating with the findings that produced it, a stated confidence level, the three issues that matter most for a business like yours in ranked order, what is already working, and a 30-day plan. It arrives by email in one to two business days.
It also states its own limits on the front page. A free snapshot rests on external evidence alone, so it is never rated high confidence, and it cannot see your internal network, your staff devices, your point-of-sale or your Wi-Fi. Read a complete worked example — thirteen findings on a fictional hotel — in the sample report, or read how one is produced.
One free snapshot per domain every 30 days. We read public records — DNS, mail records, certificate transparency logs and the domain registry. We never connect to your website or servers, never log in, and never test your defences. This is not a penetration test.
Find out what a stranger already knows about your business
One domain, read from public records, written up by a person and emailed to you in one to two business days. Free. Nothing to install, no payment details, no account.