Trust & Security
How this is actually run.
Precise, verifiable claims only: no compliance badge is displayed here that isn’t backed by a real audit. This is a one-person consultancy: I personally configure and am responsible for every system listed below.
Confidentiality
Every engagement starts with clear confidentiality terms before any project or client detail is discussed in depth.
Data exposure
Sensitive systems, like production business data or admin dashboards, are never shown publicly without explicit client permission. Where a system can’t be shown safely, the Work page uses masked previews or a gated walkthrough instead of an open link.
Authentication & access
Authentication for this site’s administrative systems is handled by Firebase Authentication (Google-managed identity infrastructure) with two-factor authentication on account access.
Secrets & key management
API keys and secrets are stored in Google Cloud Secret Manager, scoped to least privilege, and rotated on a defined schedule.
Transport security
All traffic to this site is served over TLS, enforced at the edge.
Third-party processors
Third-party services used to operate this site (Sanity, HubSpot, Resend, Plausible, Cal.com, and Google Cloud/Firebase) are each bound under GDPR-standard Data Processing Agreements.
Vulnerability disclosure
This site publishes a security.txt file (RFC 9116) for responsible vulnerability disclosure.
Capacity & continuity
I intentionally limit myself to 3–4 new advisory engagements per quarter, so every client gets direct, hands-on attention rather than being spread across an unbounded roster.
I'm also the founder of Gabe Foundation (opens in a new tab), a community foundation in Nairobi funded entirely by this consultancy's income, currently in its founding stage. Noted here for transparency about where that income goes.
Where this page is still growing
Security practices here are informed by the OWASP Top 10. This is a solo operation and has not undergone independent third-party audit. That’s stated plainly rather than implied otherwise. Formal data-handling documentation is still being written up and will be published here once finalized, not filled with placeholder claims in the meantime. Formal technical certifications are also real and verified, and available on request.
Ask a specific security question