Nairobi, Kenya
We watch this region, and we do something about it.
Seraph Cyber is a security practice and a platform. The practice puts analysts on your estate; the platform keeps the programme running after they leave. Both are fed by the same thing — what our clients' own people report catching, which is intelligence no global feed replicates.
What we watch
Global vendors see Kenya as a region. We see it as the dataset.
These figures come from the platform, not from this page. They are the same numbers our analysts work from, refreshed every five minutes.
Breach and infostealer monitoring runs behind a strict redaction boundary. Recovered credential values are read only to set an exposure flag and are never written to our systems — only field names survive ingestion. If your security team wants to walk that boundary with us, we will show you the code path.
How the practice works
One loop, four moves
Everything we do runs on the same circuit. Each pass through it makes the next assessment sharper and the next simulation more like the real thing.
Report
A Report button in Outlook and Gmail. One click sends the full message to an analyst Threat Inbox, attributed to the organisation that caught it.
Analyse
Reports meet the catalogue: known-exploited flags, profiled actors, and breach-exposure monitoring of client domains.
Simulate
Campaigns modelled on what is actually circulating here this quarter — safe, measured, department by department.
Train
The people who clicked get the course that closes their specific gap. Completion tracked, repeat-clickers surfaced.
Our own standard
What you will not find on this site
A security company's marketing claims get read as a sample of its engineering claims. So this site holds one evidence standard, and it is enforced by the software that publishes it rather than by whoever happens to be editing.
Every number is either read live from the platform, as above, or carries the date and method it was measured by. A statistic without a source cannot be published — the publish is refused, not flagged for later.
A quote needs a named person, a named organisation and written permission on file, or the section does not exist. “CEO, Tech Startup” persuades nobody and signals that the named version was not obtainable.
No compliance badge appears here until one has been earned. When we hold an attestation it will be named, dated and verifiable; until then the Trust page describes how the system actually behaves.
Client logos are self-hosted with permission recorded against each one. A cybersecurity firm serving its clients' marks from an origin it does not control is a supply-chain question we would rather not have to answer.
Working with us
Bring in the team, or run the platform
Most organisations start with one and end up with both — the assessment finds the exposure, the platform closes it and keeps it closed.
Bring in the team
Analysts on your estate, with the regional intelligence picture in hand. Scoped to your environment, delivered with a report your board can read.
Run the platform
Simulations, training and one-click reporting in a closed loop — priced per seat, with the published rate on the page and a calculator to model your own.