Services

Four things, done properly.

The list is short on purpose. Everything below is work we do ourselves — nothing here is subcontracted out and resold, and nothing is offered that we cannot stand behind afterwards.

Custom software development

Operational systems built around a problem that is costing you money, time or visibility — not a template bent to fit.

  • Multi-tenant web applications with real role-based access
  • Mobile apps for low-end Android and intermittent network
  • Mobile-money aware: payment status, reconciliation, arrears
  • Reporting that answers what management actually asks

Scoped and quoted per project

Hosting & managed care

Somebody has to own the server on Monday morning. Deployment, monitoring, backups, patching, and a report each month that says what happened.

  • Deployment and environments, staging separate from production
  • Uptime, domain-expiry and SSL-certificate monitoring
  • Scheduled backups, with restores actually tested
  • A written monthly report: uptime, backups, what changed

Monthly retainer

Security assessment

A passive review of what your organisation exposes to the public internet, delivered as evidence with risk ratings — not opinion.

  • TLS/SSL configuration, protocol support, certificate review
  • HTTP security headers and HTTPS enforcement
  • Email security DNS records — SPF, DKIM, DMARC
  • Public exposure review and a prioritised remediation plan

Fixed scope, fixed price

Graduate engineering programme

Fresh graduates working on real client systems that are going to production — under supervision, with every change reviewed before it ships.

  • Structured curriculum across Spring Boot, Next.js and Flutter
  • Production-bound tickets, not toy exercises
  • Multi-tenant architecture, mobile money and data-protection practice
  • Weekly demos, monthly review, and an honest reference at the end

By cohort · applications open

Hosting & managed care

Somebody has to own the server on Monday morning.

Most systems do not fail at launch. They fail eighteen months later, when the certificate expired, the backup had been silently failing since March, and the person who set it up has moved on. These tiers exist so that does not happen to you.

Essential

For a site or small system that simply has to stay up.

On requestper month

  • Hosting on managed infrastructure
  • Uptime monitoring with alerting
  • Domain and SSL expiry monitoring
  • Weekly backups, retained 30 days
  • Security patching
  • Email support, next business day
Ask about Essential

Assured

For a system where a bad morning is a business problem.

On requestper month

  • Everything in Managed
  • Annual passive security assessment
  • Documented disaster-recovery procedure
  • Log retention and access review
  • Named incident-response contact
  • Agreed response time, in the contract
Ask about Assured

Every tier is a written agreement with a named scope. Hosting region is agreed before deployment — where your data is allowed to live may be set by your regulator, not by us.

Security assessment

What a passive assessment covers — and what it does not.

Scope is agreed in writing before anything begins. Everything below is observable from outside your organisation, using non-intrusive methods, and nothing is exploited.

What is covered

  • Website availability and response behaviour
  • HTTPS enforcement and SSL/TLS configuration
  • TLS protocol and cipher support
  • HTTP security headers
  • Email security DNS records (SPF, DKIM, DMARC)
  • Public network exposure
  • Certificate transparency and subdomain discovery
  • Public DNS security configuration

What is out of scope

  • Active exploitation of any kind
  • Authenticated or admin-portal testing
  • API and business-logic testing
  • Source code and database review
  • Internal network assessment
  • Denial-of-service or brute-force testing

You receive a written report: findings with evidence, risk ratings, practical remediation steps, items needing internal verification, and a prioritised plan. A passive assessment is a starting point — it does not replace a full penetration test, and we will tell you when you need one.

Graduate programme

The gap between a computer science degree and a production system.

Rwanda graduates capable engineers every year who have never seen a system with real users, real money and real consequences in it. We close that gap by putting them on ours — supervised, reviewed, and paid attention to.

For graduates

  • Real, production-bound feature work reviewed before it ships
  • The full stack we run in production: Spring Boot, Next.js, Flutter
  • Multi-tenant SaaS architecture, mobile-money reconciliation, data protection
  • A clear picture of how an early-stage company actually operates
  • An honest reference based on work you actually did

For clients

  • More hands on your project without more risk
  • Every change reviewed by the engineering lead before merge — no exceptions
  • Supervised work is scoped to what a reviewer can genuinely check
  • No unreviewed change ever reaches a production system

This is a real part of how we work, not corporate social responsibility. A supervised graduate multiplies what we can build — but only when the work is consistent, reviewed and secure, which is why the programme is structured rather than ad hoc.

Selected work

A delivered engagement.

Security assessment

External security assessment for a Rwandan financial services company

A follow-up to an initial cybersecurity review that had flagged four areas as needing technical verification: email security, security headers, vulnerability management and banking cybersecurity controls.

We ran a passive, non-intrusive external assessment — SSL/TLS review, DNS email security checks, HTTP security header analysis, passive web application scanning, network reconnaissance and certificate transparency review — and delivered a written report with evidence, risk ratings, remediation steps and a prioritised plan.

  • ScopePassive external assessment, agreed in writing
  • FindingsNo critical or high-risk issues; configuration hardening gaps confirmed
  • DeliveredEvidence-based report, risk ratings, prioritised remediation plan
  • BoundaryNo exploitation, no authenticated testing, no internal access

The client is not named here. Engagement details are shared with prospective clients on request, with permission.

Questions

Asked before signing anything.

Who actually does the work?

Moses Sebagabo, the founder, does the engineering. Supervised interns take on scoped work as the company grows, and every change they make is reviewed before it ships. You will be talking to the person building your system, not an account manager.

Do you work with organisations outside Rwanda?

Yes, for development and assessment work. Hosting is a different question — where your data is allowed to live may be set by your regulator, not by us, so we agree the region before anything is deployed.

Who owns the code you write for us?

You do, for work commissioned and paid for as custom development. We keep ownership of our own general-purpose libraries and tooling, and we name those in the contract rather than leaving it vague. We do not reuse one client's business logic for another.

Do you handle payments or hold client funds?

No. We build systems that record payment status, reconcile payments and report on arrears. Money settles through a licensed payment service provider — our partnership is with Centrika, and funds move on its licensed rail. We never take custody of funds.

Where will our data be hosted, and who can see it?

Agreed with you before deployment, and written into the contract. Access is least-privilege: we hold only what is needed to run and support the system, access to production is logged, and we do not copy production data onto laptops or into third-party tools without your written approval.

What happens if something breaks at 6am?

On Essential, next-business-day email support — appropriate for a site that is not business-critical, and we say so rather than implying more. On Managed and Assured you get a named contact and a response time written into the contract. We commit to what we can meet: a promise of 24/7 cover that nobody actually answers is worth less than a stated window that always holds.

What happens to our system if you become unavailable?

You are not locked in, by design. The code lives in a repository you own, or is handed to you on request. Every system ships with a written deployment runbook — how it is built, where it runs, what the environment variables are, how backups are taken and restored. Standard tools and no proprietary framework, so another engineer can pick it up. We would rather you never need any of that, but you should not have to trust us on it.

Can you handle the size of our organisation?

Tell us the numbers and we will answer honestly. The systems we build are multi-tenant and designed for thousands of records and concurrent users — that is an architecture question, not a headcount question. Where a project needs more hands than we have, we will say so before the contract rather than after, and we will not take it on the assumption that it works out.

How are projects priced?

Development is scoped and quoted per project, with a deposit at the start and the balance against agreed milestones. Assessments are fixed scope and fixed price. Hosting is a monthly retainer. We do not do unpaid customisation, and we would rather re-quote a changed scope than absorb it silently.

Can you take over a system somebody else built?

Often, yes. It starts with a paid review of what exists — the code, the server, the backups and whatever documentation there is — so we can tell you honestly whether it should be maintained, refactored or replaced. Nobody benefits from us guessing at that for free.

Next step

A short conversation, before a proposal.

We would rather spend twenty minutes understanding the problem than send you a document that guesses at it. If we are the wrong people for the job, that is a useful outcome too.