Nairobi, Kenya 0701 027171 · info@hantasoftwares.org
Software engineering & security

We build the systems. Then we try to break them.

A Nairobi software firm working across security, server-side engineering, data and delivery — usually on the same system, from the first commit to production and everything after it.

One system, five layers — pick one

What we do

Six lines of work. Most clients start with one and pull in the others as the system grows — which is the point of keeping them under one roof.

SEC

Cyber security

Find what is exposed, fix it in order of what an attacker would reach first, then check the fix held.

  • Penetration testing for web, mobile and internal networks
  • Cloud and configuration review — IAM, storage, secrets, network rules
  • Secure code review and dependency auditing
  • Hardening, logging and incident response planning
  • Data Protection Act, 2019 readiness reviews
  • Staff awareness sessions and phishing simulations
API

Server-side engineering

The engine room. APIs, background jobs, integrations and the databases underneath them.

  • REST and GraphQL APIs, authentication and permissions
  • Payment and telco integrations — M-Pesa Daraja, card gateways, bulk SMS
  • Database design, query tuning, migrations without downtime
  • Queues, scheduled jobs and event-driven services
  • Modernising legacy systems in stages, not big-bang rewrites
DAT

Data & analytics

Getting numbers out of the system that people actually trust enough to act on.

  • Pipelines from source systems into a warehouse
  • Dashboards and scheduled reporting for operations and finance
  • Data cleaning, deduplication and quality checks that run automatically
  • Forecasting and machine learning where it beats a simpler rule
  • Analytics that respect consent and retention rules from the start
SHIP

End-to-end product delivery

An idea taken all the way to a running product — scoped, built, tested, deployed, handed over.

  • Discovery and scoping with a written deliverables list
  • Web and mobile application development
  • Automated testing — unit, integration and end-to-end
  • Release pipelines, staging environments and rollback plans
  • Documentation and repository handover you own outright
OPS

Cloud, DevOps & reliability

Making deployment boring, and making sure someone finds out before your customers do.

  • CI/CD pipelines and infrastructure described in code
  • Containers, orchestration and environment parity
  • Monitoring, alerting and on-call runbooks
  • Backups with restore drills you watch us run
  • Cloud cost review and right-sizing
AUD

Technical audit & due diligence

An independent read on a codebase or vendor — for boards, investors and anyone about to sign.

  • Codebase health, architecture and key-person risk
  • Vendor and third-party integration review
  • Verification of what a system actually does versus what was promised
  • Written findings ranked by severity, with remediation effort estimated

How the work runs

The same five stages on every engagement. You always know which one we are in, and what has to be true before we move to the next.

01

Scope

We write down what exists, what is breaking and what success looks like. You get a scope document with deliverables, sequence, assumptions and the things we have explicitly left out — before any code is written.

02

Build

Small increments in a repository you own from day one, with an environment you can open at any point. Progress is reviewed against the scope document, not against a demo.

03

Test

Automated tests run on every change. Security work gets its own pass — we read the build the way someone attacking it would, and we tell you what we found even when it is our own code.

04

Deploy

Releases come out of a pipeline, not off a laptop. Infrastructure is described in code so it can be rebuilt from scratch. The rollback path is agreed before the first release, not during the first outage.

05

Operate or hand over

Monitoring, alerts and a restore drill you watch. Then a choice: keep us on retainer for patching and on-call, or take a documented handover and run it in-house. Both are normal endings.

Ten questions we ask first

Answer them here before you call us. Nothing is sent anywhere and nothing is stored — the questions run in your browser and the result is yours to keep or to send us.

Security self-check

This is not a scan.

No tool is touching your system. These are the ten questions we work through in a first meeting, in the order that usually matters. If you cannot answer one, that is the answer.

Takes about two minutes.

Ways to work with us

Three shapes of engagement. If you are not sure which fits, describe the problem and we will tell you which one we would propose — and say so if the answer is none of them.

Project

Best for
A defined outcome with an end — a new product, a migration, an integration.
You get
A scope document, milestone releases, tests, deployment and handover.
Scoped by
Fixed deliverables agreed up front, with change requests priced separately.

Retainer

Best for
A live system that needs continuous patching, monitoring and small improvements.
You get
Agreed monthly hours, an escalation route, and a monthly report of what changed.
Scoped by
A monthly hour block and a response commitment set in the agreement.

Assessment

Best for
A security test, a code audit or technical due diligence on a system you did not build.
You get
Findings ranked by severity, each with a fix and an effort estimate, plus one retest.
Scoped by
A fixed time box and a written list of systems in scope.

Questions we get asked

The same answers the front desk gives — it reads this section. If yours is not here, ask it there or call.

What does an engagement cost?

We quote after a scoping conversation. We do not publish a rate card because a two-week security assessment and a nine-month build are not comparable units. Tell us the system and the problem and you get a written scope with a number attached.

How soon can you start?

It depends on what is already in the queue. Ask and we will tell you the real answer rather than the one that wins the job. Assessments usually slot in faster than builds.

Will we own the code?

Yes. The repository sits in your account from the first commit, not handed over at the end. Same for infrastructure accounts, domains and secrets. If you fire us on a Tuesday, everything still works on Wednesday.

Can you work with our existing team and codebase?

Yes, and it is usually cheaper than starting again. We read the codebase first and tell you honestly whether it is worth extending or worth replacing — including when the honest answer costs us the bigger job.

Do you sign an NDA?

Yes, before we look at anything sensitive. Send yours, or ask and we will send ours.

What is penetration testing, and do we need one?

It is a controlled attempt to break into your system, run with your written permission and an agreed scope, ending in a report of what worked and how to close it.

You need one if you hold customer data, take payments, or have simply never had an outsider look. If you already know you are not patching, or that ex-staff still have accounts, fix that first — a test will only charge you to confirm it.

Are you compliant with the Data Protection Act?

Compliance under the Data Protection Act, 2019 sits with you as the data controller — no vendor can hold it on your behalf. What we do is a readiness review: what personal data you hold, where it lives, who can reach it, how long you keep it, and what is missing before anyone asks.

Which technologies do you use?

Chosen per problem, with the reasoning written into the scope document so you can disagree before it gets built. If you already have a stack and people who know it, we work inside it rather than replacing it to suit ourselves.

Do you work on site in Nairobi?

Yes, on site around Nairobi where it helps, and remote for everywhere else. Security work touching physical access or internal networks usually needs at least one day in the building.

What happens if we stop working with you?

A documented handover: architecture notes, runbooks, credentials transferred and a walkthrough with whoever takes over. Nothing is held hostage. A clean exit is a normal ending, not a failure.

How do we start?

Call or WhatsApp 0701 027171, or send the brief further down this page. Useful things to include: what the system does, what is going wrong, who maintains it now, and any deadline you are working against.

Do you support the system after launch?

If you want us to. A retainer covers patching, monitoring, on-call and small improvements, with a monthly report of what changed. If you would rather run it in-house, we set your team up to do that instead.

Tell us what is breaking

Or what you want built. A short description of the system and the problem is enough to start — we will come back with questions before we come back with a number.

Call or WhatsApp 0701 027171 +254 701 027171 from outside Kenya · Open WhatsApp
Email info@hantasoftwares.org Send code, logs or a scope document — anything that helps us understand the system.
Where we are Nairobi, Kenya On site around Nairobi, remote for everywhere else.
Add your name so we know who we are replying to.
Add a phone number or email address we can reach you on.
Describe the system and what is going wrong, in as much or as little detail as you have.
Send on WhatsApp

Goes straight to info@hantasoftwares.org. No account, no tracking, nothing stored on this site.