About Us

The security division of a house built on stewardship.

Stratafort acquires, invests in and operates exceptional businesses for the long term. Stratafort Cyber exists because in every one of those businesses — and in every firm we now protect — we found the same truth: trust is the real asset on the balance sheet.

Our Story

Born inside an investment house. Built for the trust economy.

Most cyber security companies are founded to sell software. Stratafort Cyber was founded to answer a harder question, asked inside a holding company that stewards businesses for decades rather than quarters: what actually protects the value of a firm whose entire product is confidence?

The answer was never a single product. It was a discipline — measure the real exposure, close it in order of consequence, watch continuously, and be ready for the day everyone hopes never comes. That discipline became a division, and the division became a practice serving law firms, healthcare providers, accountancies and professional organisations across South Africa and beyond.

And because the discipline demanded it, we built our own engine to run it on: purpose-built server infrastructure on premium custom-engineered hardware, with a proprietary AI layer woven through assessment, monitoring and triage. Client intelligence is processed on machines we own — never on rented, shared platforms — at a tempo conventional practices cannot schedule.

We operate the way our clients do: quietly, precisely, and with an acute awareness that reputations take decades to build and one leaked file to lose. We publish no client lists. We name no tools. We let the quality of the work carry the name.

Operating Facts
  • A Division of Stratafort
    Backed by a private investment house, not venture quotas.
  • Headquartered in South Africa
    Serving professional firms locally and internationally.
  • Sector-specialised
    Legal, healthcare, financial and professional practices — firms bound by confidentiality.
  • Framework-aligned
    Practice aligned to POPIA, the NIST Cybersecurity Framework and ISO/IEC 27001 principles.
  • Sovereign infrastructure
    Purpose-built server infrastructure on premium custom hardware — owned and operated end-to-end.
  • AI-augmented operations
    A proprietary AI layer runs through assessment, monitoring and triage — boutique discretion, industrial throughput.

"We treat every client's data the way a fiduciary treats a mandate — as something held, not owned."

Stratafort Cyber · Operating Principle
What We Stand On

Four values. Zero exceptions.

These are not wall posters. They are the tests every deliverable, every finding and every recommendation must pass before it reaches you.

I

Discretion

Your engagement, your findings and your exposures are treated with the same privilege you extend to your own clients. NDAs welcomed. Tradecraft never disclosed.

II

Precision

Accuracy is a hard constraint. We report what the evidence supports — severity-ranked, verifiable, free of inflation. Fear is not a methodology.

III

Vigilance

Exposure is not an annual event, so neither is our attention. Monitoring is continuous, intelligence is current, and new risks are surfaced when they appear.

IV

Accountability

Senior practitioners scope, execute and stand behind every engagement. When we put a finding in writing, we are prepared to defend it in your boardroom.

How We Engage

Professional to professional.

You will recognise the manner of working, because it is your own: conflict-aware, confidentiality-first, evidence-led, and allergic to overstatement. Here is what that means in practice.

  • Evidence before opinion

    Every engagement begins with measurement of your actual estate. Recommendations trace to verified findings, never to a product catalogue.

  • Findings you can act on alone

    Our assessments include immediate containment actions your own team can take without us. We earn the ongoing relationship; we do not engineer dependence.

  • Board-grade communication

    Deliverables are written for principals and partners: severity-ranked, plain-language, defensible — the document you could hand to your insurers or your regulator.

  • Urgency without alarmism

    When something is critical we say so plainly, and when it is minor we say that too. Calibrated severity is how trust survives a long relationship.

  • Confidentiality as default

    We are comfortable under NDA from the first conversation, and our own operational security is engineered to the standard we recommend to you.

The Standard We Hold

Rigour you can audit.

Behind every executive summary is a methodology built to withstand scrutiny — yours, your insurer's, and if it ever matters, the Information Regulator's.

Method · Coverage

Hundreds of checks, one estate

Each external assessment runs 400+ technical checks across your domains, email authentication, infrastructure hygiene and credential exposure — compiled into a single severity-ranked picture.

Method · Intelligence

Breach & dark web sourced

Findings draw on breach corpora, infostealer intelligence and dark web sources spanning multiple years — so you learn about exposed credentials before someone uses them.

Method · Reporting

Referenced & reproducible

Every engagement carries a unique reference, every finding an identifier, every severity a definition. What we report today can be re-tested and defended tomorrow.

Meet Us Properly

The best introduction is a finding you didn't know about.

Request a confidential consultation and we will show you, with evidence, how your firm currently looks from the outside.

Speak to us confidentially