Total Scans
0
All time
Critical Findings
0
Across all scans
Security Score
—
Latest scan
Trust Score
—
Latest scan
Compliance
—
Kenya DPA & POPIA
Recent Scans
No scans yet. Run your first scan above.
Severity Breakdown
Run a scan to see severity data.
Code Vulnerabilities CVE references & fix instructions
Run a scan to see vulnerability details.
Compliance Scores
Run a scan to see compliance scores.
Regulation Clauses Violated
Run a scan to see clause violations.
Risk Surface
Is your website putting customers at risk?
AfriProtec checks if criminals can compromise your website to steal customer data, deface your brand, or impersonate your business. Enter your website address above.
Customer Data Skimming
Detects malicious code that silently copies payment card details and personal data as customers type
Phishing Clone Detection
Identifies weaknesses that allow criminals to create convincing fake versions of your website to deceive your customers
Payment Gateway Security
Verifies your checkout process cannot be intercepted to redirect customer payments to criminal accounts
Defacement Risk
Checks whether attackers could replace your website content with criminal messaging, damaging your reputation overnight
Example Finding
Malicious Script Vulnerability Found
CRITICAL
An attacker can inject code to steal your customers' credit card data at checkout. Affected customers would have no idea their payment details were captured.
Risk Surface
Are your developers accidentally exposing your business?
Connect your code repository and AfriProtec will scan every file for leaked passwords, exposed access keys, and vulnerabilities that could give criminals a backdoor into your systems.
Leaked Database Passwords
Finds login credentials, database passwords, and secret keys that developers accidentally saved inside the code
Proprietary Code Exposure
Identifies accidentally public repositories where confidential business logic and trade secrets are visible to anyone
Backdoor Tracking
Detects hidden code planted by malicious actors or insiders that allows unauthorized remote access to your systems
Supply Chain Compromise
Checks external software packages your developers rely on for known attacks where criminals poison widely-used tools
Example Finding
Exposed Production Credentials in Code History
CRITICAL
Your developers accidentally uploaded a live access key to a cloud service. Anyone who finds it has unauthorized access to your corporate data and can rack up charges on your account.
Risk Surface
Can criminals send emails pretending to be your company?
If your email domain is not protected, criminals can send convincing emails from your exact address to your clients, board, and suppliers — impersonating you to steal money or data. Enter your company domain to check.
Domain Impersonation
Checks if criminals can send emails that appear to come from your exact company address without being blocked
CEO Fraud Vulnerability
Assesses how easy it is for attackers to impersonate your executives and trick employees into transferring funds
Invoice Hijacking Risk
Detects whether criminals can intercept or spoof your payment requests to redirect money from your suppliers and clients
Mail Server Exposure
Finds insecure mail server configurations that allow unauthorized access to your company email accounts and archives
Example Finding
Domain Vulnerable to Identity Impersonation
CRITICAL
Criminals can send emails from your exact company address to scam your clients into paying fake invoices. Your clients would have no reason to doubt the sender because it appears genuine.
Risk Surface
Are there open doors into your network criminals can walk through?
AfriProtec scans your network perimeter to find exposed entry points — databases, remote access tools, and unprotected services that attackers actively search for. Enter your company domain or IP address.
Enter your company domain (recommended) or public IP address — AfriProtec resolves IPs from domain names automatically.
⚙ Detect My IP
Exposed Database Ports
Finds database servers directly accessible from the internet — giving attackers direct access to all your stored data
Unencrypted Protocols
Detects connections that transmit passwords and data in plain text, allowing anyone on the same network to intercept them
Firewall Gap Detection
Identifies weaknesses in your network defences that leave internal systems reachable despite having a firewall in place
Remote Access Vulnerabilities
Checks remote working tools and VPN gateways for known weaknesses attackers use to break in without credentials
Example Finding
Critical Internal Port Exposed to Internet
CRITICAL
Your database server is directly accessible from the internet without requiring a password. An attacker can connect from anywhere in the world and download or delete your entire customer database.
Risk Surface
Is your cloud storage leaking company data to the public?
Cloud misconfiguration is the single most common cause of corporate data breaches. AfriProtec connects directly to your cloud provider to identify exposed storage, over-privileged accounts, and insecure configurations.
Amazon Web Services
Microsoft Azure
Google Cloud Platform
Public Storage Bucket Exposed
Finds cloud storage folders that are set to publicly readable, making internal files and backups visible to anyone with a browser
Unencrypted Backups
Identifies database and file backups stored without encryption, meaning stolen storage equals stolen data
Over-Privileged Accounts
Detects staff or service accounts that have admin-level access to everything, turning any compromised account into a full breach
Exposed Config Files
Scans for configuration files containing passwords, connection strings, and credentials stored in accessible cloud locations
Example Finding
Public Corporate Storage Exposed
CRITICAL
An internal storage folder containing customer data is accessible to anyone on the internet without a password. This constitutes a reportable data breach under Kenya DPA requiring notification within 72 hours.
Connecting your cloud account requires read-only API credentials — AWS Access Keys, an Azure Subscription ID, or a GCP Service Account key. These are used only during the scan and never stored permanently.
For a quick check of your public-facing infrastructure without credentials, use Website Scan instead.
For a quick check of your public-facing infrastructure without credentials, use Website Scan instead.
Risk Surface
Are your staff feeding confidential data into AI tools without your knowledge?
When employees use AI chatbots like ChatGPT with company data, that data may be stored, used for AI training, or transferred across borders — violating Kenya DPA data residency requirements. Connect your workspace to find out.
📄
Upload Network Logs
Drop a CSV, JSON, or TXT network log file here, or click to browse
Processed entirely in your browser — never uploaded to our servers
Processed entirely in your browser — never uploaded to our servers
Unauthorized AI Tool Usage
Detects employees using AI tools like ChatGPT, Copilot, or Gemini with company data outside approved policy
Customer Data Leaked to Public AI
Identifies instances where personal or confidential customer data was submitted to an external AI service without consent
Cross-Border Data Transfer Violation
Flags data sent to AI providers in foreign jurisdictions without the required safeguards under Kenya DPA
Prompt Injection Risk
Finds AI-powered features in your products that can be manipulated by users to extract confidential system data
Example Finding
Protected Customer Data Sent to External AI
CRITICAL
Staff uploaded customer records into ChatGPT, violating Kenya DPA requirements on data residency and cross-border transfer. The organization is liable for a regulatory fine and must notify affected customers.
Risk Surface
Are your company passwords already in criminal hands?
Criminals trade stolen corporate credentials on hidden markets. If your passwords are already compromised, attackers can log in as your staff right now — without triggering any alarms. Enter your company email address or domain to check.
Leaked Staff Passwords
Checks if employee login credentials have appeared in known breach databases and are available to criminals right now
Executive Credentials Exposed
Specifically monitors whether CEO, CFO, or senior management login details are circulating on criminal marketplaces
Brand Mentions on Criminal Forums
Scans underground forums for discussions targeting your company, indicating criminals are actively planning an attack
Corporate Email Compromise
Detects if business email accounts have already been accessed by unauthorized parties based on breach intelligence data
Example Finding
Active Executive Credentials on Dark Web
CRITICAL
Login details for senior management accounts were found in a recent breach database and are actively being sold. An attacker could use these to access your systems, approve fraudulent transactions, or impersonate leadership in email communications.
Risk Surface
How secure are the companies you trust with your data?
60% of data breaches originate through a supplier or partner. Before signing a contract or sharing customer data, enter your third-party supplier or partner website to assess their security posture.
Enter your third-party supplier or partner website address above
Supplier Security Failure
Rates the overall security maturity of the supplier — a weak supplier is a direct risk to every business that connects to them
Payment Gateway Risk
Verifies the security of payment processors you depend on so customer transactions cannot be intercepted or stolen
Downstream Breach Exposure
Checks whether a past security incident at your supplier may have already exposed data you shared with them
Compliance Gap at Vendor
Identifies whether your supplier meets Kenya DPA, POPIA, or other regulatory standards required when processing your data
Example Finding
Critical Failure at Main Software Supplier
CRITICAL
Your integrated supplier has an expired security system creating a backdoor into your network. Any attacker who discovers this can pivot through the supplier connection directly into your internal systems.
Risk Surface
How far could an attacker get inside your network right now?
BAS safely replicates the techniques real attackers use against internal systems — without causing any damage. You discover your actual exposure before criminals do.
Target System
BAS simulates attacks on your internal infrastructure. Only use on systems you own and have written authorisation to test.
Ransomware Propagation Risk
Measures how quickly ransomware could spread from one infected device across your entire office network and servers
Internal Credential Weakness
Tests whether weak or reused passwords on internal systems would allow an attacker to escalate access across the company
Detection System Bypass
Determines whether your antivirus and monitoring tools would actually alert you during an active attack or miss it entirely
Privilege Escalation Path
Maps the exact steps an attacker would take to go from a normal staff account to full administrative control of your systems
Example Finding
Network Vulnerable to Ransomware in 4 Minutes
CRITICAL
If one office computer is infected, our simulation confirms attackers could lock your entire file server within 4 minutes. All company files, financial records, and customer data would be encrypted and held for ransom.
Scan History
No scan history yet.
⚠️ AfriProtec generates compliance evidence readiness assessments. This is not a regulatory certification or independent audit. System-verified controls (Level 5) are detected automatically. All other levels require human review. For ODPC, CBK, or ISO 27001 certification, engage an accredited auditor.
Evidence Levels
●●●●● System-verified by AfriProtec scan (highest credibility)
●●●●● AI-verified document
●●●●● Document uploaded
●●●●● Self-attested
●●●●● Not assessed
Loading compliance data...
Connect your tools so AfriProtec can scan continuously, alert your team instantly, and block vulnerabilities before they reach production.
Code Repositories
GitHub
Add a security check to every pull request. Vulnerabilities must be fixed before any merge is allowed.
GitLab
Scan every commit. Block merge requests with critical security issues. Full CI/CD pipeline integration.
Communication
Slack
Get instant security alerts in your Slack workspace when critical findings are detected.
Infrastructure
Cloudflare
Monitor DNS zones, SSL certificates, and WAF rules for security misconfigurations across your domains.
Amazon AWS
Continuously scan your S3 buckets, IAM policies, and compute instances for security misconfigurations.
Microsoft Azure
Monitor your Azure subscriptions for exposed storage accounts, overprivileged identities, and misconfigurations.
Productivity & Workspace
Google Workspace
Detect shadow AI usage and unauthorised data sharing across your Google Workspace environment.
Microsoft 365
Monitor your M365 tenant for shadow AI exposure and data leaving your organisation.
Account
Full Name
Email Address
Phone Number
Subscription
Current Plan
Free Trial — 2 scans
Team & Access
—
—
Audit Log
Loading activity...
Data Retention
Keep scan results for 90 days
Scan results older than 90 days are automatically deleted
Email alerts on new critical findings
Send an immediate email when a critical security issue is discovered
Notifications
Weekly Security Summary
Receive a weekly digest of your security posture and new findings
Scan Complete Notifications
Get notified in-browser when a scan finishes
Appearance
Dark Mode
Toggle between dark and light interface
Developer API Keys
Security
Password
Change your account password
Two-Factor Authentication
Add a second layer of security to your account
Active Sessions
Login History
Detailed login history with IP addresses is available on the Pro plan. Upgrade →
Two-Factor Authentication
Authenticator App (TOTP)
Use Google Authenticator, Authy, or any TOTP app to secure your account
SMS Backup Code
Receive a one-time code by SMS when logging in
Your Data
Download My Data
Export all your scan history and findings as JSON
Sign Out
Sign out of your AfriProtec account on this device
Danger Zone
Delete Account
Permanently delete your account and all scan data. This cannot be undone.
Domain Monitoring
Continuous 24/7 scanning of your website, email, and DNS records.
Add Domain
Monitored Domains
Loading...
Upgrade Your Plan
Choose the plan that fits your business. Secure payments via Paystack — cancel anytime.
Free Trial
KSh 0
/month
Try the platform — no card needed
- ✓ 2 on-demand scans
- ✓ Website scan only
- ✓ Full results report
- ✓ Basic Kenya DPA check
- ✗ Email / Network scans
- ✗ Dark Web monitoring
Current Plan
Starter
KSh 1,900
/month
Scan regularly, on your schedule
- ✓ 20 scans per month
- ✓ Website security scans
- ✓ Email domain scans (SPF, DKIM, DMARC)
- ✓ Network port & SSL scans
- ✓ Kenya DPA compliance reports
- ✗ Dark Web / BAS / Shadow AI
MOST POPULAR
Pro
KSh 9,900
/month
Unlimited scans, all threat types
- ✓ Unlimited scans
- ✓ Website — malware, defacement, skimmers
- ✓ Email — SPF, DKIM, DMARC, BEC
- ✓ Network — open ports, SSL, firewall
- ✓ Dark Web — breach & credential leaks
- ✓ Vendor Risk, BAS & Shadow AI
- ✓ Kenya DPA, POPIA & ISO 27001 reports
- ✓ AI-powered analysis per scan type
ENTERPRISE
Enterprise
Custom
tailored to your business
For teams & regulated industries
- ✓ Everything in Pro
- ✓ Phishing simulation campaigns
- ✓ Dedicated security analyst
- ✓ Custom compliance frameworks
- ✓ 24/7 continuous monitoring
- ✓ SLA guarantee
- ✓ Multi-user team access
🔒 Secure payment via Paystack · Cancel anytime · 14-day money-back guarantee