Projects

SaaS · Human Cybersecurity

RoxShield

ROLEFounderNext.js 14NestJSPrismaPostgreSQL
applications (18 countries)
430
organizations (7 countries)
14
scoring signals
2
access tiers
3
01

The problem

The human factor remains the leading cause of security incidents in organizations: phishing, weak passwords, lack of awareness. Traditional tools (SIEM, EDR) protect technical infrastructure, but leave this risk largely unmeasured, especially for African businesses that can't afford costly awareness programs.

02

Constraints

The product had to guarantee strict data isolation between organizations of very different sizes, with no cross-visibility ever possible, while staying readable for non-technical decision makers who need to act on a risk signal without being security analysts. It also had to survive a major framework migration mid-build, when Next.js deprecated the middleware convention the access control logic relied on, without ever exposing a gap in authorization during the rewrite.

03

My role

Founder. Designed the multi-organization security architecture, the human risk scoring model, and the phishing simulation mechanism.

04

Key decisions

01

Data isolation as a security control, not a design option.

Every entity carries an organization identifier directly in the data model, and no cross-organization view exists at the application level, not even for administrators of other organizations. Access follows three strict tiers, and employees are structurally blocked from the admin dashboard at the routing level, not just by the interface, even with a direct link.

02

A composite score, not a single indicator.

Human risk can't rest on one signal without creating a false sense of security. The score combines an active signal (phishing simulation click rate) and a passive signal (training completion rate), rolled up into department and then organization scores. This reflects a real threat-modeling methodology, not just a display choice.

05

Solution

Next.js 14, NestJS, Prisma, PostgreSQL. Admin dashboard with human risk scoring, phishing simulation engine, training modules, strictly isolated multi-organization management.

06

Evidence

Selected into the inaugural Cyber4Africa cohort (UNDP/G7/Cisco), among 430 applications from 18 countries. 14 organizations across 7 countries are currently trialing the platform.

07

Outcome

Selection into the Cyber4Africa cohort moved the project from a self-built product to one backed by a structured institutional program. It is currently moving through the program's onboarding sequence: cybersecurity assessment, training, and individualized support for qualifying startups.

08

Reflection

Most cybersecurity platforms I knew were built for IT teams. They talked about logs, firewalls, endpoints. They assumed the human was a controlled variable. I started RoxShield from the opposite problem: what if the human was the network?

Scoring isn't a technical feat, it's an editorial choice. I could have built something complex, with dozens of variables. I chose two signals only: phishing simulation click rate, and training completion rate. A score nobody understands drives no behavior. An HR director who sees "Finance: 62%, High" knows what to do Monday morning. I chose actionability over apparent precision.

The real difficulty was data isolation, not the code. Technically, implementing multi-organization isolation isn't groundbreaking. What was hard was making the decision and holding to it, even when it would have been easier to allow cross-visibility to generate benchmarks. An organization trusting a platform with its security data needs to know it never leaks anywhere, not even to a Rostel administrator. Trust is the real product.

On AI, and why I chose not to use it. RoxShield doesn't rely on any LLM. Every score can be recalculated by hand. That choice has a simple ethical reason: when a system flags an employee as "high risk," that call can have real consequences for a career, a transfer, a review. I refuse to delegate that signal to a model whose weightings I can't explain to an HR director in five minutes. AI will come, but not before building a foundation of trust that lets it exist without deceiving anyone.

CONTACT

Let's talk about securing your systems.

Contact me