OMU-2026·scope: enforcing·engines: online·UGX marketUganda · authorized operations only

Capabilities

Built for the work a security team actually does

Omukuumi is organized around the security domains a fintech company cares about — not around a pile of installed tools. Capabilities are scoped, risk-rated, and evidence-backed by design.

Web & API

  • Endpoint discovery and mapping
  • Authentication & session review
  • Authorization (BOLA / IDOR) analysis
  • OWASP-class checks
  • JWT / OAuth / OIDC review

Network

  • Asset & service discovery
  • Segmentation review
  • TLS / cipher posture
  • Exposed management interfaces
  • Infrastructure config review

Threat intel

  • IOC enrichment
  • Domain / IP intelligence
  • CVE correlation
  • Relationship mapping
  • Leaked-secret detection

Fintech

  • Payment API flows
  • Webhook & signature security
  • Mobile-money integrations
  • Transaction authorization
  • Settlement / refund logic

Inside the agent

Three engines hold the line

Scope engine

A hard boundary written before any work starts. Targets, exclusions, window, and expiry are enforced on every tool call.

Policy engine

Tool calls are classified by risk and permission. High-risk or state-changing actions wait for an operator decision.

Evidence engine

Requests, responses, status codes, and context are captured before and after each action — the report is built from records, not memory.