VUNVAULT
Establishing secure channel
Enterprise Security Solutions

Application penetration testing, surface reconnaissance and proactive threat mitigation.

VUNVAULT combines manual, human-led penetration testing with continuous automated attack-surface reconnaissance. Every engagement is delivered under a mutual NDA, mapped to the compliance frameworks your regulator actually audits against, and handed back with remediation steps your engineers can ship.

NDA-backed OWASP-aligned Central Bank ready Africa-rooted · Worldwide
Free Security Tools

Run OSINT reconnaissance from your browser

Three free lookups powered by the same enumeration engine behind our paid assessments. No account, no commitment, nothing stored.

vunvault-cli v2.4.0 — osint --interactive
IDLE

Resolves reverse DNS, WHOIS ownership and geolocation for a domain or IPv4 address.

Try:

Simulated reconnaissance for demonstration purposes. Never query systems, addresses or device identifiers you do not own or have written authorisation to investigate.

Core Security Services

Everything we test, and why it matters

Each engagement is scoped, executed and reported by a named lead analyst — never a fully automated scan dressed up as an assessment.

Web Application Penetration Testing

Manual testing across the OWASP Top 10 — injection, authentication and session flaws, broken access control, SSRF and insecure deserialisation — plus targeted parameter fuzzing and business-logic abuse that scanners never reach.

OWASP Top 10 Parameter Fuzzing Broken Access Control

Attack Surface Reconnaissance

Subdomain enumeration, certificate-transparency mining, SSL/TLS certificate tracing and service fingerprinting — surfacing the shadow IT, forgotten staging hosts and unmanaged APIs that quietly widen your perimeter.

Subdomain Enumeration CT Logs Shadow IT

WAF & Defense Verification

We attack your defences the way an adversary would: rule-evasion encoding, rate-limit and anti-automation validation, payload stress testing and bypass chains that prove whether your WAF, CDN or bot-management layer actually blocks what it claims to.

Rule Evasion Rate Limiting Payload Stress

IT & Network Troubleshooting

When something is broken and nobody can explain why: DNS diagnostics, record-consistency audits, connectivity tracing, MTU and routing faults, firewall rule review and misconfiguration hunting across hybrid estates.

DNS Diagnostics Connectivity Firewall Checks

Cloud & Mobile Security

API gateway configuration reviews, cloud IAM and storage exposure checks, mobile application testing (Android & iOS) and dedicated M-Pesa / fintech integration audits covering callback validation, replay protection and settlement integrity.

API Gateway M-Pesa / Fintech Mobile App Tests

Compliance & Reporting

Executive briefing decks for the board, developer-ready technical remediation guides for the engineering team, and audit evidence packs mapped to GDPR, ISO 27001, ODPC and Central Bank supervisory requirements.

Executive Briefing Remediation Guide Audit Evidence
Plans & Pricing

Transparent scope. Transparent pricing.

Every tier below lists exactly what is tested, what you receive and how long it takes. No hidden line items, no vague "from" pricing.

Starter Security Audit

Entry
$249 / scan

For a single web application, micro-site or lightweight API endpoint that needs a fast, honest read on its exposure.

Scope & deliverables
  • Automated vulnerability scan covering the OWASP Top 10
  • Up to 20 endpoints / parameter routes analysed
  • Standard SSL/TLS and HTTP header misconfiguration checks
  • Automated PDF report with risk severity ratings (Critical → Low)
  • Remediation checklist with 7-day email support
  • 3-day turnaround time

Not included: manual exploitation, business-logic testing, re-tests.

Start with Starter

Full-Scope Pen Test & Compliance Ready

Regulated
$1,499 / project

For enterprise applications, fintech and M-Pesa integrations, and SACCO platforms that need regulatory sign-off before go-live.

Scope & deliverables
  • Deep black-box & gray-box manual penetration testing
  • Unlimited endpoint coverage within the defined target domain
  • Authentication bypass, privilege escalation and session-handling testing
  • Executive briefing PDF + developer-focused technical remediation guide
  • Full NDA, GDPR and Central Bank / regulatory compliance documentation
  • 2 free re-tests within 60 days

Includes scoping call, rules-of-engagement document and named lead analyst.

Scope a Pen Test

Enterprise Security Retainer

Custom
Custom / annual

For multi-domain infrastructure that needs continuous threat monitoring rather than a point-in-time report.

Scope & deliverables
  • Continuous 24/7 attack-surface monitoring & alerting
  • Quarterly penetration tests across all in-scope domains
  • Custom API and integration security audits
  • Dedicated security architect embedded with your team
  • Incident-response escalation with defined SLA guarantees
  • Board-ready quarterly risk reporting

Pricing is derived from asset count, domain footprint and required response SLA.

Talk to an Architect

All tiers include encrypted report delivery, a named engagement lead and a rules-of-engagement document signed under mutual NDA. Prices exclude applicable taxes. Re-test windows are measured from the date the final report is delivered.

VUNVAULT Academy

Upskill your in-house engineering team

We train the people who build and defend your systems. Hands-on modules on secure coding practice, real-world attack vectors, and the same automated CLI tooling our analysts use in live engagements — delivered on-site in Nairobi or remotely for distributed teams.

Explore Training Tracks
Next step

Request an assessment under mutual NDA

Send us your target scope, compliance deadline and preferred timeline. We reply with a written scope, rules-of-engagement draft and a fixed quote — usually within one business day.

NDA on request · Scope before invoice · No data retained