Skip to main content
Tokyo · Available for new engagements

Security. AI.
Modernization.

A Tokyo studio for teams that need it shipped right. Bilingual EN/JP, scoped engagements, no theater.

12+
YEARS BUILDING
EN ↔ JP
BILINGUAL DELIVERY
GMT+9
TOKYO TIMEZONE
01 / SERVICES

Three things,
done exceptionally well.

We don't pad the menu. Each engagement focuses on one of three core capabilities — or the natural intersection between them.

WEB MODERNIZATION

Bring legacy stacks into the present.

WordPress sites stuck in 2014, jQuery dashboards no one wants to maintain, multi-page monsters bleeding conversion. We rebuild them as fast, modern, maintainable systems — without losing what already works.

Astro / Next.jsPerformance auditi18n / EN+JP
SECURITY

Pragmatic security, not security theater.

Threat modeling, audits, hardening, and incident response — focused on what actually moves your risk profile.

Security services
AI INTEGRATION

Ship AI features, not AI demos.

LLM-powered features that survive production — agents that actually work, evals that catch regressions, retrieval that retrieves the right thing. Built for reliability, not hype.

RAG & agentsEvalsPrompt-injection hardening
AUDITS & ADVISORY

A second pair of eyes on what you've built.

Performance, security posture, code review, infra. Written reports your engineers will actually read.

Performance auditLighthouse, Core Web Vitals, real-world load
Security postureThreat model + actionable hardening list
Tech-debt reviewWhat to keep, refactor, or rewrite
02 / APPROACH

Small engagements,
clear deliverables.

No standing retainers, no padding. We work in 4–8 week scoped engagements with explicit deliverables on day one.

01

Discovery

One week. We map your stack, talk to your team, and produce a concrete scope with deliverables, milestones, and pricing — fixed, not hourly.

02

Build

Four to six weeks of focused work. Weekly demos in your timezone. Direct Slack channel. Zero status meetings — progress is visible in the work.

03

Handoff

Documentation your team can actually use, runbooks, and a 30-day support window. Optional ongoing advisory if you want it. No lock-in.

03 / RECENT WORK

A few engagements,
anonymized.

Most of our work is under NDA. Here's a sample of recent engagements with the clients' details removed.

acme-corp.com
ACME
ProductsAboutContactJP
Tools that ship with you, not against you.
Industrial-grade machinery for teams that move fast.
Get a quote
Watch demo
© 2026 AcmeEN · 日本語
WEB MODERNIZATION

Rebuilt a 90-page corporate site as a static React stack

From WordPress + jQuery to Next.js. Lighthouse 100/100, content edited via Markdown, EN/JP locale at the routing layer.

−68% LCP
Core Web Vitals
B2B SaaS · Tokyo
support.acme.com/ai
AI Console
Inbox
Threads
Knowledge
Evals
Settings
Thread #4821 · ja-JPRESOLVED
Customer · 14:22
注文した商品が届かないのですが…
AI · suggestionconf 0.94
注文番号をお伺いできますか?追跡情報を確認します。
SEND
EDIT
EVALSfaithfulness 0.91grounded 0.88tone 0.76
AI INTEGRATION

Production RAG console for a multilingual support team

Retrieval that retrieves the right thing across EN/JP/ZH content. Eval suite catches regressions before they ship.

−42% time-to-resolve
Support tickets
Customer support
kakero.jp/reports/acme-fintech
PRE-LAUNCH AUDIT · v1.22026-04-22
Acme Fintech · Threat Model + Findings
2
CRITICAL
5
HIGH
11
MEDIUM
8
LOW
CRITAuth bypass via stale JWT signing keyauth/session
CRITUser PII in client-side error logslogging
HIGHMissing rate-limit on password resetauth/reset
HIGHS3 bucket — anonymous listinfra/s3
SECURITY

Threat-modeled an early-stage fintech before launch

Identified two critical pre-prod issues, hardened the auth flow, and shipped a prioritized remediation plan their team owns.

2 critical findings
Pre-launch audit
Fintech · Series A
04 / WHO YOU'RE WORKING WITH
Francisco Pena, founder of Kakero
Francisco PenaFounder · 個人事業主

Solo by design.
Selective by necessity.

I'm Francisco — security engineer turned full-stack consultant, now based in Tokyo. Twelve years across infra, application security, and web platforms. Before Kakero I worked with teams shipping multilingual products to global audiences and wanted to build something with the same standards but my own client list.

Kakero is intentionally a one-person studio. That means you work directly with the person who's reading your code, not an account manager. It also means I'm selective — three to four engagements running at a time, never more.

No status meetings
Async by default. Demos beat updates.
Fixed scope
Pricing in week one, not as we go.
Real handoff
Docs your team uses after I'm gone.
Talk to me directly
04 / GET IN TOUCH

Have something in mind?

Tell us about your project. We respond within one business day, in English or Español (calls available), or 日本語 (email only).