VUNVAULT
Establishing secure channel
Africa-rooted · Worldwide defense

We were built where the internet is hardest to defend.

VUNVAULT is a Nairobi-headquartered offensive security firm. We run adversary emulation, penetration testing and continuous attack-surface mapping for SACCOs, fintechs, M-Pesa gateway providers and enterprises — teams whose uptime is measured in livelihoods, not service credits.

412 Sensors Online
1,284 Assets Monitored
12,904 Threats Blocked
1.2s Mean Patch Time
Mission & Vision

Security work that survives contact with reality.

Most assessments are written for auditors. Ours are written for the engineer who has to ship the fix before Monday. That single bias shapes everything below.

Our mission

To make advanced offensive security reachable for the institutions that carry African economies — SACCOs, fintechs, payment gateways and public infrastructure — by pairing adversary-grade tooling with plain-language reporting that a board can actually act on.

We do not sell fear. We map exposure, prove impact, and hand back a prioritised path out of the blast radius.

Our vision

A continent where a two-person IT team in Kisumu has the same defensive leverage as a Tier-1 bank in Zurich. That means automation, telemetry and continuous validation — not annual PDFs.

We are building the sensor network, the academy and the tooling to close that gap permanently.

Core Pillars

Three disciplines. One engagement.

Every VUNVAULT engagement is delivered against the same three pillars — the technical, the regulatory and the human. Drop one and the other two collapse.

01

Precision Offense

Adversary emulation that mirrors the tradecraft actually landing on East African targets — not a generic scanner dump.

  • Web, API and mobile penetration testing
  • Custom fuzzing pipelines & zero-day research
  • Purple-team validation against your SIEM rules
02

Regulatory Mastery

Findings mapped to the framework your regulator actually cites — so remediation doubles as evidence.

  • Central Bank of Kenya cyber requirements
  • Kenya Data Protection Act & GDPR alignment
  • ISO 27001 / SOC 2 control evidence
03

Capacity Building

A finding you can't reproduce is a finding you can't fix. We train your team to hold the line after we leave.

  • VUNVAULT Academy learning tracks
  • Developer secure-coding workshops
  • Incident-response tabletop exercises
Contributors & Core Team

The people behind the defense.

Four disciplines, one floor. Every engagement is staffed by the people below — not subcontracted, not anonymised behind a logo.

Portrait of Amara Njoroge

Amara Njoroge

Lead Offensive Security Engineer

OSCP CRTO 9+ yrs Nairobi, KE

Leads VUNVAULT's red-team engagements across SACCOs, fintechs and M-Pesa gateway providers. Amara specialises in web application penetration testing, custom parameter fuzzing pipelines and zero-day research — the kind of work that finds the bug a scanner's signature list will never reach. She has disclosed seven responsibly-handled vulnerabilities in payment and identity platforms operating in East Africa, and runs the internal exploit-development review that every VUNVAULT finding passes through before it reaches a client report.

Web Pentesting Parameter Fuzzing Zero-Day Research Burp Suite API Security Exploit Dev
/team/amara-njoroge
Portrait of Daniel Mwangi

Daniel Mwangi

Security Automation & Recon Architect

Automation Recon 7+ yrs Remote · KE

Builds the reconnaissance and validation engine underneath every VUNVAULT engagement. Daniel owns the multi-threaded SSL/TLS validation tooling, the endpoint-crawling pipeline that turns a single domain into a scored asset map, and the Python and Bash automation that keeps the whole stack reproducible. His rule is blunt: if a check cannot run unattended at 03:00 against a 4,000-host estate and return the same result twice, it does not ship. He also maintains the internal patch-validation CLI used to confirm remediation before we close an engagement.

SSL/TLS Validation Endpoint Crawling Python Bash Multi-threading CI Automation
/team/daniel-mwangi
Portrait of Fatima Hassan

Fatima Hassan

Threat Intelligence Analyst

Threat Intel OSINT 6+ yrs Mombasa · KE

Owns the zero-day tracking feed and the attack-surface mapping methodology that opens every engagement. Fatima spends her week correlating NVD entries, vendor advisories and VUNVAULT sensor telemetry into a single exploitation-status view, and profiling how WAFs actually behave against the payloads we throw at them. Her briefings on ransomware playbooks targeting East African SACCOs are now read by security teams in four countries. She writes the weekly threat note that goes to every retainer client.

Attack Surface Mapping WAF Analysis CVE Correlation MITRE ATT&CK OSINT Threat Briefings
/team/fatima-hassan
Portrait of Brian Otieno

Brian Otieno

Compliance & Governance Lead

ISO 27001 GDPR 10+ yrs Nairobi, KE

Translates raw technical findings into the language regulators and boards actually use. Brian owns the Central Bank cybersecurity standards mapping, GDPR and Kenya Data Protection Act framework alignment, and the rules-of-engagement and non-disclosure agreements that govern every engagement VUNVAULT accepts. He also authors the Academy compliance curriculum and sits in on every scope call, because the fastest way to break a client is to test something nobody authorised you to touch.

CBK Standards GDPR Mapping ISO 27001 NDAs & RoE Policy Design Curriculum
/team/brian-otieno
System Telemetry

What our sensors are seeing right now.

A live slice of the VUNVAULT sensor network — the same telemetry that feeds client dashboards and our weekly threat note.

VUNVAULT Sensor Network Live
--:--:-- UTC
Sensors Online
412/412
All nodes nominal
Assets Monitored
1,284
▲ 36 this week
Threats Blocked
12,904
Rolling 30-day window
Mean Time to Patch
1.2s
Automated validation
Real-Time Security Alerts auto-refresh · 8s
Critical CVE-2026-21447
Apache Struts 2 — OGNL injection RCE
Web & API · CVSS 9.8 · 14:36:45 UTC
Unpatched
Critical CVE-2026-0091
Cisco IOS XE — Web UI authentication bypass
Network & Edge · CVSS 9.1 · 14:35:12 UTC
In progress
High CVE-2026-3327
Oracle WebLogic — deserialization RCE
Web & API · CVSS 8.8 · 14:32:01 UTC
Unpatched
High CVE-2026-18820
Windows Print Spooler — privilege escalation
Endpoint · CVSS 8.1 · 14:28:55 UTC
Patched
Critical CVE-2025-53112
Google Chrome V8 — type confusion in JIT
Endpoint · CVSS 9.6 · 14:25:11 UTC
Patched
Medium CVE-2025-18820
SQL injection in unsanitised search parameter
Web & API · CVSS 5.3 · 14:21:40 UTC
Unpatched
Status Counters
Active zero-days 1,284
Weaponized in the wild 37
Critical unpatched 46
Patched (YTD) 37,910
Client estates covered 96
Patch Coverage 68%

Refreshed continuously from NVD, vendor advisories and the VUNVAULT sensor network. Times shown in UTC. Telemetry is aggregated and contains no client-identifying data.

No cost · No commitment

See your attack surface the way we see it.

Start with a free external vulnerability scan, or talk to an engineer about a full adversary-emulation engagement mapped to your regulator's framework.