Skip to content

Nairobi, Kenya

We watch this region, and we do something about it.

Seraph Cyber is a security practice and a platform. The practice puts analysts on your estate; the platform keeps the programme running after they leave. Both are fed by the same thing — what our clients' own people report catching, which is intelligence no global feed replicates.

What we watch

Global vendors see Kenya as a region. We see it as the dataset.

These figures come from the platform, not from this page. They are the same numbers our analysts work from, refreshed every five minutes.

141,196Vulnerabilities cataloguedMatched against the technologies each client actually runs.
1,682CISA known-exploitedFlagged where exploitation has been observed in the wild.
176Threat actors profiledMapped to MITRE ATT&CK techniques and tooling.
What we do not hold

Breach and infostealer monitoring runs behind a strict redaction boundary. Recovered credential values are read only to set an exposure flag and are never written to our systems — only field names survive ingestion. If your security team wants to walk that boundary with us, we will show you the code path.

How the practice works

One loop, four moves

Everything we do runs on the same circuit. Each pass through it makes the next assessment sharper and the next simulation more like the real thing.

01

Report

A Report button in Outlook and Gmail. One click sends the full message to an analyst Threat Inbox, attributed to the organisation that caught it.

02

Analyse

Reports meet the catalogue: known-exploited flags, profiled actors, and breach-exposure monitoring of client domains.

03

Simulate

Campaigns modelled on what is actually circulating here this quarter — safe, measured, department by department.

04

Train

The people who clicked get the course that closes their specific gap. Completion tracked, repeat-clickers surfaced.

Our own standard

What you will not find on this site

A security company's marketing claims get read as a sample of its engineering claims. So this site holds one evidence standard, and it is enforced by the software that publishes it rather than by whoever happens to be editing.

No unsourced figures

Every number is either read live from the platform, as above, or carries the date and method it was measured by. A statistic without a source cannot be published — the publish is refused, not flagged for later.

No anonymous testimonials

A quote needs a named person, a named organisation and written permission on file, or the section does not exist. “CEO, Tech Startup” persuades nobody and signals that the named version was not obtainable.

No borrowed certifications

No compliance badge appears here until one has been earned. When we hold an attestation it will be named, dated and verifiable; until then the Trust page describes how the system actually behaves.

No hotlinked client marks

Client logos are self-hosted with permission recorded against each one. A cybersecurity firm serving its clients' marks from an origin it does not control is a supply-chain question we would rather not have to answer.

Working with us

Bring in the team, or run the platform

Most organisations start with one and end up with both — the assessment finds the exposure, the platform closes it and keeps it closed.

Seraph CyberServices
Engagement

Bring in the team

Analysts on your estate, with the regional intelligence picture in hand. Scoped to your environment, delivered with a report your board can read.

Seraph CTIPlatform
Subscription

Run the platform

Simulations, training and one-click reporting in a closed loop — priced per seat, with the published rate on the page and a calculator to model your own.