Capabilities
Built for the work a security team actually does
Omukuumi is organized around the security domains a fintech company cares about — not around a pile of installed tools. Capabilities are scoped, risk-rated, and evidence-backed by design.
Web & API
- Endpoint discovery and mapping
- Authentication & session review
- Authorization (BOLA / IDOR) analysis
- OWASP-class checks
- JWT / OAuth / OIDC review
Network
- Asset & service discovery
- Segmentation review
- TLS / cipher posture
- Exposed management interfaces
- Infrastructure config review
Threat intel
- IOC enrichment
- Domain / IP intelligence
- CVE correlation
- Relationship mapping
- Leaked-secret detection
Fintech
- Payment API flows
- Webhook & signature security
- Mobile-money integrations
- Transaction authorization
- Settlement / refund logic
Inside the agent
Three engines hold the line
Scope engine
A hard boundary written before any work starts. Targets, exclusions, window, and expiry are enforced on every tool call.
Policy engine
Tool calls are classified by risk and permission. High-risk or state-changing actions wait for an operator decision.
Evidence engine
Requests, responses, status codes, and context are captured before and after each action — the report is built from records, not memory.