Skip to main content
Kakero/Services
01 / Services — What we ship

Three things.
Done exceptionally well..

Each engagement focuses on one of three core capabilities — or the natural intersection between them. We don't pad the menu.

01 / Security consulting

Security that moves your risk profile.

Most security work is theater — long reports, vague remediations, no behavior change. We do the opposite: focused threat modeling, prioritized findings, and concrete fixes your team owns after we leave.

What you get
  • Threat model document
  • Prioritized findings (severity-tagged)
  • Hardening playbook
  • 30-day remediation support
Not for
  • ×Compliance-checkbox audits
  • ×Penetration tests for marketing
  • ×Long-term retained security teams
threat-surface · weekly scan
Live · 2 min ago
CRITICAL
Exposed S3 bucket — production logs
IAM policy too broad · public read
Fix
HIGH
CVE-2024-3094 · legacy-auth-svc
Patched upstream v1.4.2 · 2d ago
Track
MEDIUM
Rate limit missing on /v2/users
Recommend 100 req/min · burst 250
Review
RESOLVED
SSO callback domain mismatch
Fixed PR #4881 · 3d ago
View
2,847 endpoints
19 findings
4 critical · resolved
02 / AI integration

AI that survives production.

Demo-quality AI is everywhere; production-quality AI is rare. We build LLM-powered features with the boring stuff baked in from day one — evals, prompt-injection hardening, retrieval that retrieves the right thing.

What you get
  • Production-grade RAG / agent system
  • Eval suite (offline + online)
  • Cost & latency monitoring
  • Prompt-injection & abuse defenses
Not for
  • ×Pure research projects
  • ×Foundation-model training
  • ×AI strategy decks without code
eval run · billing-agent · v3.4
Live
Customer wants refund for a double charge from May 12.
stripe.lookup_chargestripe.refund_partial(420)
0.94 ✓
User asks why their password was changed last night.
auth.audit_loguser.delete (refused)
0.87 ✓
Ambiguous "downgrade" — tier or seats?
escalate.human(billing)
0.91 ✓
94.2% pass rate
142ms P95
$0.003 /req
03 / Web modernization

Legacy stacks, brought forward.

WordPress sites stuck in 2014, jQuery dashboards no one wants to maintain, multi-page monsters bleeding conversion. We rebuild them as fast, modern, maintainable systems — without losing what already works.

What you get
  • Modern stack rebuild (Next.js / Astro)
  • EN/JP localization at routing layer
  • Lighthouse 100 across the board
  • Editorial workflow your team can use
Not for
  • ×Greenfield "launch in 2 weeks" projects
  • ×Pure design work without code
  • ×WordPress theme tweaks
strangler-fig migration · Q3 progress
Live
checkout
100%
identity
92%
billing
74%
notifications
48%
analytics
12%
5/6 domains in flight
0 hrs downtime
43% infra cost cut
§ OVERLAP
Where they meet

Most projects sit
in the overlap.

Security touches AI. Modernization touches both. Tell us what you're building and we'll scope it — usually it's a blend.

Security
AI
Modernization
ka · ke · ro
SecurityAI

Hardened agents

Prompt-injection defenses, audited tool calls, sandboxed actions.

AIModernization

Eval-driven rewrites

Replace brittle batch pipelines with streaming RAG that you can actually measure.

ModernizationSecurity

Defended migrations

Strangler-fig cutovers that close the legacy attack surface as they go.

§ TIERS
Shape of an engagement

Three sizes.
All fixed-price.

Most projects fall into one of these. If yours doesn't, write us anyway — we'll tell you honestly.

Audit
2 weeks
Best for: a written second opinion before you commit
  • Architecture review
  • Threat-surface map
  • Prioritized findings
  • No code changes
Defend
Quarterly
Best for: keeping a shipped system honest
  • On-call response
  • Drift checks
  • Quarterly architecture review
  • Cancel anytime
Not sure which one fits?

Most projects span two.
Tell us what you're building.

Two paragraphs about the system and the deadline. 48-hour reply, with the names of the people who'd staff it.