Every week, Kenyan businesses lose money, data and customer trust to attacks that could have been prevented. A leaked customer list, a hacked website, or a payment system that can be tricked into confirming payments that never happened: these aren't just "IT problems". They're business problems, and many of them start with how the software was built.

At Greenlix Technologies, we treat security as part of the design, not something added at the end. Here's what that looks like in practice for every system we build, whether it's a rent collection platform, a school management system or a custom M-Pesa integration.

1. Security starts in the requirements meeting

Before we write a single line of code, we ask questions most clients don't expect: What data will this system hold? Who should see it? What would happen if it leaked?

The answers shape the whole design. A hospital system holding patient records needs stricter controls than a public product catalogue. By identifying sensitive data early, we decide where it's stored, who can access it and how long it's kept, before it becomes expensive to change.

2. Built for Kenya's Data Protection Act

The Data Protection Act, 2019 requires organisations that handle personal data to protect it and use it only for clear, lawful purposes. Our team includes data protection training from CIPIT, Strathmore University, and we build the Act's principles into the software itself:

  • Consent: forms clearly explain how data will be used, and record the person's agreement.
  • Data minimisation: we collect only what the system genuinely needs.
  • Access control: staff see only the records their role requires.
  • Right to deletion: administrators can remove a person's data when it's no longer needed or when they ask.

This makes compliance much easier for our clients, and it shows customers that their information is in good hands.

3. Protection against the most common attacks

The OWASP Top 10 is a widely used list of the most critical web application security risks. We design against these risks as standard practice. A few examples:

SQL injection

Attackers try to slip database commands into forms and web addresses to read or delete data. We use prepared statements for every database query, so anything a user types is treated as plain data, never as a command.

Cross-site scripting (XSS)

If a system displays user input without care, an attacker can inject code that runs in other people's browsers. We escape all output and filter rich text so only safe formatting is allowed.

Forged requests (CSRF)

Every form in our systems carries a secret security token, so another website can't trick a logged-in user into performing actions they didn't intend.

Unsafe file uploads

Uploaded files are checked for their real type and size, renamed, and stored in folders where scripts can't run.

4. Strong sign-in and access control

Stolen or guessed passwords remain one of the easiest ways into a system. Our admin areas include:

  • Securely hashed passwords: passwords are never stored in readable form, so even a database leak doesn't reveal them.
  • Two-step verification: after the password, a one-time code is sent to the user's email.
  • Lockouts: repeated wrong attempts temporarily block sign-in, stopping guessing attacks.
  • Automatic sign-out after a period of inactivity.
  • Role-based access and an activity log, so you always know who did what, and when.
  • Security alerts by email whenever a password is changed or reset.

5. Safe M-Pesa and payment integrations

Payment systems are a prime target, because a single weakness can mean goods released for money that never arrived. When we integrate M-Pesa (Daraja API) or other gateways, we follow a few firm rules:

  • Never trust the browser. Amounts and account numbers are set and checked on the server, not taken from what the user's device sends.
  • Confirm before you release. A payment is only marked as paid after the confirmation from the payment provider has been received and checked against the expected amount and account.
  • Every transaction is recorded with its receipt number, so duplicates are rejected and reconciliation is automatic.
  • API keys stay secret: credentials are stored in protected configuration files, never inside web pages or shared code.

6. Encryption, backups and recovery

We deploy systems over HTTPS, so data travelling between your users and the server is encrypted. Behind the scenes, we set up regular, automatic backups stored separately from the main server, and we test that they can actually be restored. If something does go wrong, whether it's a hardware failure, a mistake or an attack, your business can be back up quickly.

7. We test our own systems like an attacker would

Our team is trained in ethical hacking and cyber security analysis through Cyber Shujaa at USIU-Africa. Before a system goes live, we deliberately try to break it: testing sign-in pages, forms, file uploads and payment flows for weaknesses. Anything we find is fixed and re-tested before launch.

It's far cheaper to find a weakness in testing than to explain a data breach to your customers.

8. Security doesn't stop at launch

New threats appear every month. After go-live, we help clients keep their systems safe with software and plugin updates, SSL certificate renewals, monitoring for unusual activity, and practical cyber security awareness training for staff, because many attacks begin with a convincing phishing email rather than a technical flaw.

A quick security checklist for your business

Whether or not Greenlix built your system, ask your provider these questions:

  1. Is all traffic to the system encrypted with HTTPS?
  2. Are passwords hashed, and is two-step verification available for administrators?
  3. Can you see who changed what, and when?
  4. Are backups automatic, stored separately, and tested?
  5. Are payments confirmed on the server before goods or services are released?
  6. When were the software and its plugins last updated?
  7. Does the system help you meet your obligations under the Data Protection Act?

If you're unsure of any answer, it's worth a conversation.

Let's build something secure together

At Greenlix Technologies, we believe secure software should be the standard, not an expensive extra. Whether you need a new system, a security review of an existing website, or a safe M-Pesa integration, we're here to help.

Talk to our team about secure software or call us on 0742 806 790.