Skip to main content

We hold ourselves to the standard we sell

How we secure our own systems, how to report a vulnerability to us, and the standards our delivery methodology is built on.

How we protect ourselves

Internal red team

Annual full-scope adversary simulation against our own environment. Findings disclosed in our annual report.

Zero Trust architecture

Identity-based access with hardware-key MFA for all staff. No standing privileged access.

Vendor risk management

All vendors assessed under our risk programme. Continuous monitoring. Concentrated risk avoided.

Disclosure policy

Post-mortems published for major internal incidents within 30 days of resolution.

Responsible disclosure

A responsible-disclosure programme for our public-facing infrastructure and products.

The standards we work to

From how we build and secure systems to how we run them and respond when something breaks, our practices align to internationally recognised standards — so delivery is predictable, auditable, and consistent across build, secure, and operate.

  • Information security management — the control framework our build and secure practices are structured around across the systems we deliver.

  • Information security incident management — the framework our detection, triage, and response workflow follows end to end.

  • Computer security incident handling guide — the lifecycle (preparation, detection, containment, eradication, recovery) our playbooks are built around.

  • IT service management — the operating model behind our managed-IT and 24/7 SOC service delivery, from change control to problem management.

How your data is handled

The controls below govern the personal and client data we hold. For the full detail, read the Privacy Policy.

  • Personal data is processed under the Kenya Data Protection Act, 2019, with OpasSecure registered as both controller and processor.

  • Data is encrypted in transit (TLS) and access is governed by identity-based controls with no standing privileged access.

  • We do not sell personal data and do not use third-party advertising trackers.

  • Subprocessors (e.g. cloud hosting, CRM, email delivery) are engaged only under data processing agreements and assessed through our vendor risk programme.

  • Data is not transferred outside Kenya except where adequate safeguards are in place.

Transparency, annually

Our annual report covers our own security posture, red-team findings, and progress against the standards we hold ourselves to — ISO/IEC 27035 and NIST SP 800-61r2. We publish it because we ask our clients to hold us to the same standard we hold them.