Services
Four practices, one team. Most of the work is in regulated sectors — banking, government, critical national infrastructure — where an architecture has to satisfy an auditor as well as an engineer.
We build the capability to see an attack and answer it. That means the architecture and the tooling, but also the parts usually left out of a proposal: who is on call, what they do at three in the morning, and how the team keeps working once we have gone.
Segmentation, identity, privileged access and the controls that make an estate defensible rather than merely monitored.
Standing up a SOC end to end: tooling, log pipelines, detection engineering, triage runbooks and escalation.
Building MSSP capability — the service catalogue, the tiering, and the staffing model that survives handover.
Reviewing an existing estate against its real risks, then sequencing the fixes by what actually reduces exposure.
Designing and securing enterprise environments across all three major clouds. Most organisations arrive with something already running; the work is usually to make it defensible without stopping it.
Landing zones, identity and conditional access, key management, workload protection and governance at scale.
Account structure, network segmentation, IAM boundaries and the guardrails that keep them in place.
Project and folder design, service accounts, VPC controls and the policy to hold them.
Moving workloads without inheriting old assumptions, and reviewing what has already moved.
Large-scale server and data centre programmes, delivered across Africa, Europe and the Middle East — including government-level deployments where the requirements are set by regulation rather than preference.
Site, topology, power and network design through to build supervision and acceptance.
Compute, virtualisation and storage design, capacity planning, hardening and lifecycle replacement.
The detailed documentation a competitive tender turns on: architecture, topology, security controls and implementation specifications, written to the sector’s compliance requirements.
Business continuity and disaster recovery planning, backup architecture and restore procedures that have actually been rehearsed.
We design and build web and mobile applications end to end — product, interface, backend, payments and cloud deployment — and then run them. PopVibe is our own, which is where the practice was proved rather than described.
Working out what the thing should do before writing it, then designing screens people can use without a manual.
Web and mobile applications, APIs, real-time video and messaging, built to be maintained rather than demonstrated.
M-Pesa, card and PayPal integrations, with reconciliation and receipts that survive an audit.
Deployment, monitoring, backups and the ongoing work of keeping something live once the launch is over.