Live transaction rails
Mobile money, card and bank-transfer settlement in production, with reconciliation and dispute handling — not a sandbox integration.
Enterprise technology division — Jiranisoko Market Ltd
Jiranisoko Tech Solutions architects, engineers and operates artificial intelligence, cloud infrastructure and transaction-grade software for financial institutions, public-sector agencies and high-growth enterprises. Our standards are set by the systems our own group depends on every day.
Structured intake. A qualified engineering lead responds within two business days (EAT (UTC+3)).
Standards and frameworks governing our delivery
The group behind the engineering
Jiranisoko Tech Solutions is the technology division of Jiranisoko Market Ltd, a holding company with operating interests across multiple digital verticals. Chief among them is JiraniSoko Marketplace — a consumer marketplace carrying live M-Pesa payment rails, live fraud exposure and a live uptime obligation to the people trading on it.
This distinction matters to any institution evaluating an engineering partner. A consultancy that has never carried an on-call rota for its own revenue-bearing system is proposing architecture it has not been accountable for. We carry that rota. The disciplines we sell — observability, incident response, capacity planning, payment reconciliation, PCI scope control — are the disciplines that keep our own group solvent.
Mobile money, card and bank-transfer settlement in production, with reconciliation and dispute handling — not a sandbox integration.
A production system with a defined recovery objective, tested restores and a documented incident record.
Real fraud, real abuse, real scraping. Our security posture is shaped by attacks we have actually absorbed.
Capability taxonomy
Enterprise programmes rarely sit inside a single discipline. A payments modernisation is a cloud migration, an API engineering effort and a compliance exercise at the same time. We structure our practice so that one engagement can draw on all six without a change of vendor, contract or accountability.
We move organisations from AI ambition to production systems that carry measurable operational load — with the evaluation, guardrails and human oversight that make them defensible to a risk committee.
We design and operate cloud estates that are auditable, reproducible and cost-governed — where every environment is defined in code, every change is reviewable, and every deployment is a non-event.
We engineer multi-tenant products and internal platforms built to survive their own success — tenancy isolation, data partitioning and reporting designed in from the first sprint rather than retrofitted under load.
We build the money-movement layer: integration with mobile money and card rails, reconciliation that balances, and cardholder-data architectures scoped for audit from the first day rather than the first assessment.
We modernise the systems institutions already depend on, and expose them through interfaces that are versioned, contract-tested and defensible under security review.
We apply distributed ledger technology where it demonstrably outperforms a database — multi-party settlement, provenance and asset tokenisation — and we say so plainly when it does not.
How we are engaged
Where the scope is definable and the outcome is fixed, we carry the delivery risk. Where the scope will evolve and your team must own the result, we embed senior engineers inside your organisation. Where the decision precedes the build, we advise and step back.
Fixed-scope, end-to-end accountability. We take the requirement through architecture, engineering, security review, deployment and SLA-governed operation, and we are answerable for the outcome.
Senior engineering pods integrated into your workflow, your board, your standup and your definition of done. You direct the work; we own recruitment, retention, bench cover and technical quality.
Independent architectural, security and transformation counsel — including the assessment of work we did not build and would not be asked to rebuild.
Unsure which applies? Our intake determines it in four questions.
Operating headquarters — Eldoret, Kenya
Our location is a deliberate operating decision, not a concession. Eldoret gives us access to a deep, university-fed engineering base at a cost structure no Tier-1 city can match, in a time zone that overlaps the working day of every market we serve. What does not change with geography is the standard: the same architecture review, the same security gates, the same test discipline, the same code we would ship from anywhere.
The Gulf, continental Europe, the United Kingdom and South Asia all fall within a six-hour or better daily overlap on standard hours. The United States East Coast does not: on 08:30–17:30 EAT the overlap is 1.5 hours, extending to approximately 3.5 hours where an engagement is staffed on a staggered afternoon shift. We state that arrangement in the engagement terms rather than implying it here.
Advantage 01 currently states a cost advantage without a figure, because no comparison basis has been supplied. Before launch, either publish the rate differential with its basis (role, region, period) recorded against the metric, or leave the qualitative statement as written. Do not publish a percentage without the basis behind it.
Governance, compliance and service assurance
Every engagement is governed by a written service framework covering security controls, availability targets, data protection obligations and intellectual property transfer. These terms are available for review before contract, and our security documentation is released to prospective clients under non-disclosure agreement on request.
Information security management aligned to ISO/IEC 27001. Role-based access with least privilege, mandatory code review, dependency and secret scanning in CI, annual penetration testing, and a published responsible-disclosure channel.
Three contracted tiers with defined availability targets, severity-based response commitments and a service-credit regime. Measured monthly, reported to the client, and reconciled at quarterly service review.
Processing governed by a Data Processing Addendum meeting the Kenya Data Protection Act 2019 and GDPR Article 28 requirements. Data residency is selectable by region; sub-processors are disclosed and change-notified.
Client-commissioned work product vests in the client on payment. Source escrow available on request. Every engagement concludes with a documented handover: architecture records, runbooks and credential transfer.
| Tier | Availability target | P1 response | P1 resolution target | Coverage | Service credits |
|---|---|---|---|---|---|
| Platinum | 99.95% | 15 minutes | 4 hours | 24 × 7 × 365 | Yes |
| Gold | 99.9% | 1 hour | 8 hours | 24 × 5 plus on-call | Yes |
| Silver | 99.5% | 4 hours | 2 business days | 09:00–18:00 EAT | No |
These values illustrate the structure of the table. Each figure must be confirmed by whoever will be contractually bound by it, and the availability targets must be achievable on the underlying cloud provider SLAs before publication. Publishing a 99.95% target on infrastructure whose own composite SLA is lower creates an obligation that cannot be met.
Sectors we serve
Insights
Architecture decisions, delivery post-mortems and sector analysis from our engineering leadership. We publish the reasoning, including where it proved wrong.
Most of the cost of a PCI programme is decided at design time, by how much of the estate falls inside the boundary.
4 min read → Engineering noteA distributed ledger earns its complexity only when no single participant can be trusted to hold the record.
5 min read → Engineering noteRetrieval that ignores per-user access turns an assistant into a data breach with a friendly interface.
4 min read →Request for Proposal
Our intake is structured so that the first response you receive is technical. Tell us which of the following describes your position and we will route your enquiry to the engineering lead who owns that practice.
Enquiries are acknowledged within one business day and answered substantively within two business days. All submissions are treated as confidential; a mutual non-disclosure agreement is available before disclosure of scope.