CEMAC · UEMOA
Security assurance for African financial institutions.
Penetration testing, regulatory-readiness assessment and phishing-awareness programmes — scoped in writing before we start, delivered in French and English, and evidenced in a portal your regulator can verify.
What that means in practice
A signed scope before anything is touched
Every engagement begins with a written authorization naming the exact systems in scope and the exact window they may be tested in. It stays in your portal as a permanent record of what you permitted — and what you did not.
Findings in a portal, not an inbox
A report emailed around lives forever in a dozen mailboxes you no longer control. Yours lives in one place, where access is auditable and you can revoke it.
Attestations your counterparty can check
Share a link and a correspondent bank or examiner confirms the attestation is genuine — with no account, no login, and no sight of your findings.
How an engagement works
Six stages, and you can see all of them.
Most firms show you the beginning and the end. The record between them is what a regulator actually asks for.
Scope
A fixed scope and a fixed price, agreed before anything starts. You receive a statement of work naming the deliverables — not an hourly estimate that grows.
Authorize
You sign a scoped, time-boxed authorization listing the systems and the window. Testing does not begin until it is signed.
Test
We test what the authorization names, within the window it sets, using the methodology the statement of work describes.
Deliver
Findings arrive in your portal, severity-rated with a CVSS score, each written in both French and English.
Remediate
Mark a finding remediated and request a retest from the portal. Every status change is appended to a record that neither you nor we can alter or delete afterwards.
Attest
A signed attestation of what was tested and what was fixed, carrying a verification link a third party can check independently.
Why us
Your regulator’s language, not a translation of someone else’s.
Findings are written in French and English by the people who found them — not machine-translated after the fact. Each one is mapped to the specific controls it implicates in the frameworks you actually answer to, so a board conversation starts from “the COBAC domains and PCI requirements at issue”, not from a list of forty technical findings.
Our own posture
We publish the controls we run.
A security firm’s own security is its most credible claim. We state specifically how your data is protected, and every claim on our trust page names a control we actually operate — with anything still on the roadmap marked as roadmap, not quietly implied.
Tell us what needs assessing.
A short conversation is usually enough to say whether we are the right firm, what the engagement would cover, and what it would cost.