Cybersecurity services in Rwanda and across Africa

Manual VAPT, regulator-aligned assessments, red teaming, managed monitoring and training for banks, fintechs, telecoms, government, healthcare and other regulated institutions. Find what prompted your search below; each route leads to the service that answers it.

Start from what prompted the search

Most engagements start because a regulator, a partner or the board asked for one. Find your situation, then the service that answers it.

  • A BNR filing is due

    Banks, microfinance institutions and payment service providers supervised by the National Bank of Rwanda.

  • Your SWIFT attestation needs an independent assessment

    Institutions on the SWIFT network with an annual CSP attestation to support.

  • Law N° 058/2021 applies to the data you hold

    Any organisation in Rwanda that holds personal data: government, healthcare, telecoms, fintech and more.

  • A partner, investor or customer asked for a pentest

    Due diligence, vendor onboarding, a product launch or a tender requirement. Start with the scope they asked for.

  • You want to know whether your team would detect an attack

    For organisations that want to test their detection and response as well as their systems. If a penetration test is the better first step, we say so.

  • You need a configuration or architecture review

    Before a migration, ahead of an audit, or when you need a clear view of your posture.

  • You want cover between annual tests

    Your attack surface changes with every release, and an annual test sees it on one day.

  • Your people need training

    Staff, IT teams and management, with evidence your regulator can review.

  • Your team needs tooling built for your stack

    Security checks in your pipeline, or scanners that understand your business logic.

How an engagement works

The same six steps for every testing engagement, from the first call to the closure letter.

  1. Scoping call

    A free call about the systems, the deadline and who is asking for the test. Book it directly, or write to us and we reply within 24 hours. If scoping needs system detail, we sign an NDA first.

  2. Fixed-price proposal

    Scope, method, timeline and a fixed price, within 48 hours of the call.

  3. NDA and authorisation

    An NDA before any system detail is shared, then written authorisation and a signed scope before testing starts. The authorisation names the people who will carry out the testing.

  4. Testing

    Manual testing inside the agreed scope and window, with a timestamped log of every action, shared on request.

  5. Report and debrief

    An evidence-led report written by hand, presented to your technical team and management, in person where possible.

  6. Re-test and closure letter

    One re-test round is included: every Critical and High finding, plus any Medium fixed by the re-test date. A closure letter records the result.

How pricing works

  • Fixed price per engagement. We quote after the scoping call, so the price reflects your actual scope.
  • Paid per milestone. Each payment falls due when you accept the milestone it covers.
  • Re-test included. The re-test round and closure letter are part of the price.
  • Extras at the day rate. Anything outside the agreed scope is optional and charged at the day rate.

We do not publish a rate card: two tests with the same name can differ widely in scope.

Your data stays confidential

An NDA is signed before any system detail is shared. Test evidence is encrypted at rest and destroyed on a date we agree with you. We never name a client publicly without written permission.

How we handle your data

Let us help you choose the right engagement

Book a free call. We will tell you which engagement answers your trigger, including when a smaller one is the better first step.