ALKAMAR Investment Limited

Services

What we do

Four practices, one team. Most of the work is in regulated sectors — banking, government, critical national infrastructure — where an architecture has to satisfy an auditor as well as an engineer.

Cybersecurity

We build the capability to see an attack and answer it. That means the architecture and the tooling, but also the parts usually left out of a proposal: who is on call, what they do at three in the morning, and how the team keeps working once we have gone.

Attacks stopped at layered defences, with a security operations console watching
Layers stop most of it. The console is there for the part that gets through.

Security architecture

Segmentation, identity, privileged access and the controls that make an estate defensible rather than merely monitored.

Security operations centres

Standing up a SOC end to end: tooling, log pipelines, detection engineering, triage runbooks and escalation.

Managed security services

Building MSSP capability — the service catalogue, the tiering, and the staffing model that survives handover.

Assessment and remediation

Reviewing an existing estate against its real risks, then sequencing the fixes by what actually reduces exposure.

Cloud

Designing and securing enterprise environments across all three major clouds. Most organisations arrive with something already running; the work is usually to make it defensible without stopping it.

Azure, AWS and Google Cloud above one shared layer of identity, network and policy guardrails
One control layer — identity, network, policy — over all three clouds.

Microsoft Azure

Landing zones, identity and conditional access, key management, workload protection and governance at scale.

Amazon Web Services

Account structure, network segmentation, IAM boundaries and the guardrails that keep them in place.

Google Cloud

Project and folder design, service accounts, VPC controls and the policy to hold them.

Migration and review

Moving workloads without inheriting old assumptions, and reviewing what has already moved.

Servers & data centre

Large-scale server and data centre programmes, delivered across Africa, Europe and the Middle East — including government-level deployments where the requirements are set by regulation rather than preference.

Server racks linked by a core network spine to a storage array and cloud
Racks, spine, storage and cloud — designed as one estate, not four projects.

Data centre design

Site, topology, power and network design through to build supervision and acceptance.

Server estates

Compute, virtualisation and storage design, capacity planning, hardening and lifecycle replacement.

Low-level design

The detailed documentation a competitive tender turns on: architecture, topology, security controls and implementation specifications, written to the sector’s compliance requirements.

Continuity and recovery

Business continuity and disaster recovery planning, backup architecture and restore procedures that have actually been rehearsed.

Apps & websites

We design and build web and mobile applications end to end — product, interface, backend, payments and cloud deployment — and then run them. PopVibe is our own, which is where the practice was proved rather than described.

A website and a mobile app wired to an API, a database and payments
The two surfaces a customer sees, and the three they should never have to.

Product and interface

Working out what the thing should do before writing it, then designing screens people can use without a manual.

Engineering

Web and mobile applications, APIs, real-time video and messaging, built to be maintained rather than demonstrated.

Payments

M-Pesa, card and PayPal integrations, with reconciliation and receipts that survive an audit.

Run and operate

Deployment, monitoring, backups and the ongoing work of keeping something live once the launch is over.

See what we have built →