Trust & Security

How this is actually run.

Precise, verifiable claims only: no compliance badge is displayed here that isn’t backed by a real audit. This is a one-person consultancy: I personally configure and am responsible for every system listed below.

Confidentiality

Every engagement starts with clear confidentiality terms before any project or client detail is discussed in depth.

Data exposure

Sensitive systems, like production business data or admin dashboards, are never shown publicly without explicit client permission. Where a system can’t be shown safely, the Work page uses masked previews or a gated walkthrough instead of an open link.

Authentication & access

Authentication for this site’s administrative systems is handled by Firebase Authentication (Google-managed identity infrastructure) with two-factor authentication on account access.

Secrets & key management

API keys and secrets are stored in Google Cloud Secret Manager, scoped to least privilege, and rotated on a defined schedule.

Transport security

All traffic to this site is served over TLS, enforced at the edge.

Third-party processors

Third-party services used to operate this site (Sanity, HubSpot, Resend, Plausible, Cal.com, and Google Cloud/Firebase) are each bound under GDPR-standard Data Processing Agreements.

Vulnerability disclosure

This site publishes a security.txt file (RFC 9116) for responsible vulnerability disclosure.

Capacity & continuity

I intentionally limit myself to 3–4 new advisory engagements per quarter, so every client gets direct, hands-on attention rather than being spread across an unbounded roster.

I'm also the founder of Gabe Foundation (opens in a new tab), a community foundation in Nairobi funded entirely by this consultancy's income, currently in its founding stage. Noted here for transparency about where that income goes.

Where this page is still growing

Security practices here are informed by the OWASP Top 10. This is a solo operation and has not undergone independent third-party audit. That’s stated plainly rather than implied otherwise. Formal data-handling documentation is still being written up and will be published here once finalized, not filled with placeholder claims in the meantime. Formal technical certifications are also real and verified, and available on request.

Ask a specific security question