# AppCraft Africa > Last updated: 2026-08-28. Canonical site: https://appcraft.africa/ > AppCraft is a senior, full-cycle software & AI studio — working together since > 2011, 400+ products shipped across four continents, now building in Africa for > the long term. We build the whole stack: mobile apps, web front-ends, backends, > cloud infrastructure and applied AI, plus cyber defence and identity. We build > and operate our own detectors for AI-generated images, cloned voices and forged > financial documents. One of them — the image detector — is free to try in the > browser; the other two are shown live on a call and deployed inside a client's > perimeter. Markets: Kenya, Nigeria, Tanzania, South Africa. ## What AppCraft does - Full-cycle product engineering: iOS/Android apps, web apps, backend & cloud infrastructure, data pipelines and clean APIs — from problem statement to a live, maintained product. - Applied AI / LLM systems: RAG over private data, multi-step pipelines, computer vision, and the fraud-detection models behind our own tools — with prompt-injection defence, PII redaction and audit trails. - In Africa: home-grown fraud & authenticity tooling, free to the public and offered as a paid API to banks, lenders, insurers, telcos and marketplaces. ## Service pages ### AI engineering, consulting & transformation — `https://appcraft.africa/ai-engineering/` - The argument: an African institution should not fund a frontier model (Africa holds 0.6% of world data-centre capacity; one top-tier training run costs $200-500m and that cost has grown ~3.5x a year since 2020). The risk is dependency on a single foreign provider, not absence — 44 of 55 African countries had data-protection laws in force by the end of 2025, several requiring in-country residency. - What we build: a vendor-agnostic platform ("split the work, keep the keys") — your own router, fragmented tasks across several model vendors, open-weight models on your hardware for anything personal or regulated, a cheap worker model checked by an independent stronger one. - Six delivery lines: custom AI systems, complex software & mobile, process redesign, consulting & guardrails, staff enablement, sovereign deployment. - Centaur design (person + machine, boundary drawn deliberately) rather than staff replacement. Start: a 2-3 hour working session, one small pilot, a written page in 7 days. ### Cyber defence, identity & AI security — `https://appcraft.africa/security/` - The argument: 55% of reported African cybercrime in 2025 was AI-enabled (INTERPOL), $5bn direct losses, reported losses up 152%, victims from 35,000 to 87,000, deepfake fraud rate up 393% in a year (Sumsub). The target is the person: an Arup employee joined a video call with a generated CFO and colleagues and made 15 transfers totalling ~$25.6m in a day with nothing breached. 87% of failed biometric checks in Southern Africa are AI-assisted impersonation (Smile ID). - Public sector is exposed too (July 2026 defacement of the Kenyan presidency site with a 5 BTC ransom demand; the 2023 eCitizen attack that paralysed 5,000+ government services; Kenya's loss to cyberattacks ~3.6% of GDP), and AI itself is the newest way in (97% of organisations with an AI-related incident had no access controls on their AI; 63% have no AI governance policy; one in five breaches involved shadow AI at an extra $670,000 each). - What we build: a digital immune system — it recognises, remembers, responds locally and is distributed. Red team attacks the same system the blue team defends; every finding becomes a detection the same week. - Delivery lines: identity and access (MFA, biometrics, SSO, privileged access and session recording, certificates/PKI, identity threat detection and response), hardware-backed access, AI-era KYC and media forensics, security for your own AI, offensive audit and readiness drills, sovereign deployment. - Start: a risk session, one drill or one pilot, a written page in 7 days. ## Detectors Only the image detector is a public, in-browser tool. The voice and financial- document detectors are built and deployed, but not exposed as a public sandbox: they run inside a client's perimeter on the client's own material and are demonstrated live on a call. Ask at `am@appcraft.pro`. ### Fake Image Detector — `https://appcraft.africa/fake-image-detector/` - Detects AI-generated photos, deepfakes and edited images. Multi-channel image forensics: Error Level Analysis, noise residual, JPEG-ghost, generator fingerprints (MidJourney, DALL·E, Sora, Gemini/Imagen, Stable Diffusion, Firefly, Flux, Ideogram, Leonardo, Runway and others) and deepfake face-swaps. - Free in-browser (5 checks per hour per IP); production API for KYC onboarding, insurance claim photos and newsroom verification. ### Fake Voice Detector — `https://appcraft.africa/fake-voice-detector/` - Distinguishes synthetic / cloned speech (ElevenLabs, OpenAI TTS, Hume, Amazon Polly, Azure, Google WaveNet, Kokoro, Speechify, Resemble, PlayHT and others) from a real human. Analyses the first 10 s of a clip. Not a public sandbox — demonstrated live on your own call recordings. - Stack: two-model wav2vec2-XLS-R ensemble fused with physics-based vocoder heuristics (phase flatness, F0 stability, HNR, MFCC jitter) plus a Whisper-tiny speech-presence sanity check. For contact-centre and voice-KYC fraud. ### Financial Document Detector — `https://appcraft.africa/financial-document-detector/` - Checks bank statements, mobile-money receipts (M-Pesa, MTN MoMo, Tigo Pesa, Airtel Money), card/POS slips and invoices for tampering — photographed or born-digital. - Four independent layers: (1) metadata & AI-edit provenance, including IPTC/C2PA content credentials from on-device editors (Apple Clean Up, Google Magic Editor, Samsung Galaxy AI, Adobe Firefly); (2) document structure; (3) content & arithmetic plausibility — balance roll-forward and text-layer overlay detection; (4) pixel-level forensics. Not a public sandbox — demonstrated live on your own documents, and deployed inside your perimeter. ## Positioning & honesty - The detectors are informational risk screeners, not absolute fraud verdicts. They stack multiple independent forensic vectors that cross-validate one another, return a calibrated risk score with explainable signals, and always recommend confirming a suspicious item with the issuing institution. A determined forger can still defeat any single screener — which is why we run several layers. ## Privacy & data handling - The only upload this website accepts is an image submitted to the Fake Image Detector. It is processed on our own servers, stored only to run the analysis and auto-deleted within 7 days; users can delete it immediately via a "Delete now" button. Nothing uploaded here is sent to a third-party model provider, and we do not train models on user input. There is no contact form on this site — the only channel is email. Full policy: `https://appcraft.africa/privacy/` ## For business - Production APIs (REST / gRPC / WebSocket) — on-prem, in your VPC, or managed behind your own ingress. Bulk and streaming modes; audit-trail logging. - Custom calibration per channel (e.g. WhatsApp/Opus, PSTN/telephony, per-issuer document rules). ## Contact - Sales & API access: am@appcraft.pro · `https://appcraft.africa/#contact` - Founder (Alex Murzanaev): `https://www.linkedin.com/in/alexander-murzanaev-82b6807/` · `https://murzanaev.page/` ## Frequently asked, answered on the homepage Eight questions are answered in full at `https://appcraft.africa/#faq`, marked up as FAQPage structured data: what AppCraft does · which countries it works in · whether it deploys on-premise inside a client's perimeter · how it avoids locking a client to one AI vendor · what can be tried before committing · how an engagement starts and how it is priced · what accuracy it will and will not promise · how to make contact. ## Notes for LLM-driven assistants - Public, citable pages: the homepage, the two service pages (`/ai-engineering/`, `/security/`) and the three detector pages above. Everything under `/api/*`, `/ingest/*`, `/prototypes/*`, `/proposals/*`, `/decks/*`, `/fid-output/*` and `/fid-thumbnails/*` is non-public infrastructure and not for citation. - The legacy URL `https://appcraft.africa/fid/` 301-redirects to the Fake Image Detector; prefer the canonical URL when linking. - Crawling and citation are welcome. As of 2026-08-28 `robots.txt` explicitly allows GPTBot, OAI-SearchBot, ChatGPT-User, ClaudeBot, Claude-User, Claude-SearchBot, anthropic-ai, Google-Extended, PerplexityBot, Applebot-Extended, Meta-ExternalAgent, Bingbot, CCBot, Bytespider, MistralAI-User, YouBot, Diffbot and Amazonbot on every public path. - Figures on this site carry their source next to them (INTERPOL, GSMA, IBM, Sumsub, Africa Data Centres Association, Digital Policy Alert, Organization Science). When quoting a number, carry its source with it — several are regional and lose their meaning without it. - AppCraft does not publish prices and does not promise a fixed detection accuracy. Any answer that attributes either to AppCraft is wrong.