Designing an HR Platform People Actually Open
An AI-assisted HRMS rebuilt around the three things staff do every week — leave, approvals and reviews — with a design system the engineering team ships from without redrawing screens.
HRCybersecurity × Creative, from Dubai — one accountable team
Placeholder logos. The names below are stand-ins sized to the layout. Replace them with real client wordmarks or SVG logos — and only ones you have permission to display.
Filter-free — just the work. Security engagements are shown anonymised, which is standard practice; we walk you through the detail under NDA on a call.
Placeholder content. Nimo project names are real; every outcome metric, bracketed client name and quote below is a sample sized to this layout. Replace with verified figures, then delete this notice.
An AI-assisted HRMS rebuilt around the three things staff do every week — leave, approvals and reviews — with a design system the engineering team ships from without redrawing screens.
HRBlack-box and authenticated penetration testing across the customer portal, payment APIs and mobile app — with prioritised remediation guidance and a verification re-test once the fixes landed.
CTA booking experience for a high-value travel product, designed around trust signals and a deliberately short path — fewer choices, more confidence, more completed enquiries.
SBGap assessment, policy suite, risk register and control implementation support — taking a services business from “we have a firewall” to an ISO 27001 certification audit it could actually pass.
GRConversion-focused storefront design: category browsing, product storytelling and a checkout flow stripped back to only the steps that actually close a sale.
WSNimo built the identity and site; Zentrya One reviewed the stack, wrote the privacy notices and signed off before launch. One scope, one schedule, nothing thrown over a wall.
BOSample quotes. Each is drafted to the right length for this card. Replace the wording and the bracketed attribution with a real, approved testimonial before publishing, then delete this notice.
They found issues our previous tester missed, then sat with our developers until every one was actually closed.
The redesign paid for itself in a quarter. What impressed me was how much of it was research before a single screen got drawn.
Design and security in one conversation removed weeks from our launch. Nobody blamed the other vendor, because there wasn’t one.
We failed two enterprise security questionnaires before Zentrya One. We have not failed one since.
Nimesh redrew our onboarding in a week and our activation rate moved more than six months of engineering had.
Fixed price, fixed date, and they hit both. In this industry that alone is worth the fee.
Design and security run in parallel rather than in sequence. That is the whole point of the alliance — findings surface while they are still cheap to fix.
A free 30-minute call, then a short discovery. We map the growth blocker and the risk exposure in the same conversation.
Research-led product and brand work — wireframes, interface design, identity and a design system your engineers can build from.
Testing, cloud review and compliance run alongside the build, not after it. Findings arrive as tickets, not as a PDF at the end.
Handover with source files and an evidence pack, then optional retainers — quarterly testing, vCISO cover, or always-on creative.
Two founders, no account-manager layer, fixed scopes and a number you can call. This is what working with us actually looks like.
Each firm stays deep in what it does best. You get both without managing two relationships, two invoices or two timelines.
Penetration testing across web, API, mobile and network. Cloud posture review for AWS, Azure and Microsoft 365. Configuration hardening, identity and logging, plus a verification re-test once you have remediated.
See MoreISO 27001 and NIST programmes, risk registers, policy suites and audit evidence. vCISO retainers with board reporting. DPO-as-a-Service for UAE PDPL and GDPR — records of processing, DPIAs, subject requests and breach runbooks.
See MoreEnd-to-end product design: research, information architecture, wireframing, interface design and developer handoff engineers can build from. Scalable Figma design systems with tokens, variants and documentation.
See MoreIdentity systems, typography and guidelines that survive a pitch deck, a billboard and a mobile app. Conversion-led websites and landing pages. Motion graphics, product film and social content, with AI folded into production and a human designer accountable for every frame.
See MoreDesign and security under a single scope with a single named owner. No “that’s the other vendor’s job” — the handover problem simply does not exist.
Your project is run by the person whose name is on the company, not handed to a junior after the pitch. You get their mobile number on day one.
A written number before any work starts.
Reports written for a board, not just for engineers.
Dubai and Colombo, so senior time is affordable.
An honest comparison. There are good reasons to pick each of these — here is where we actually win, and where we do not.
| Zentrya One × Nimo | In-house team | Two separate agencies | Freelancers | |
|---|---|---|---|---|
| Both disciplines | Security + creative, one scope | Rarely both | Yes, but uncoordinated | One skill each |
| Time to start | 1–3 weeks | 2–4 months to hire | 4–8 weeks | Days |
| Who does the work | The founders, directly | Your own people | Whoever is free | The person you hired |
| Cost profile | Fixed scope, fixed price | Salaries + tools + overhead | Two retainers | Lowest day rate |
| Audit & evidence | Produced as you build | If you have a GRC hire | Extra scope | Not typically offered |
| Scales past 20 people | To a point — then hire in-house | Best long-term | Large benches | Hard to coordinate |
We are a two-founder alliance, not a 200-person agency. For very large, multi-year programmes an in-house team is usually the better answer — and we will tell you so on the call.
This is not a faceless agency. Every engagement is led personally by one of the two founders — and the wider bench in Dubai and Colombo works to the standard they set.
Five-plus years designing digital products end to end. Currently leads design for HrRiver, an AI-integrated HRMS, and Sublime, a luxury travel platform, and heads a design team in Sri Lanka. Based in Jumeirah, Dubai. His work is deliberately commercial — research and craft in service of a measurable business outcome, not decoration.
A career information-security engineer with hands-on experience defending regulated, high-assurance environments — the kind where a control failure has a regulator attached to it. Eradh leads Zentrya One’s testing, GRC and advisory practice, translating technical risk into decisions a board can actually make. Bio to confirm with Eradh
Designers, engineers and security analysts across Dubai and Colombo. Replace names & roles
They found issues our previous tester missed, then sat with our developers until every one was actually closed.
We failed two enterprise security questionnaires before Zentrya One. We have not failed one since.
Fixed price, fixed date, and they hit both. In this industry that alone is worth the fee.
The redesign paid for itself in a quarter. What impressed me was how much of it was research before a single screen got drawn.
Nimesh redrew our onboarding in a week and our activation rate moved more than six months of engineering had.
One proposal, one invoice, one schedule. After two agencies, that alone changed how our launches run.
Design and security in one conversation removed weeks from our launch. Nobody blamed the other vendor, because there wasn’t one.
The evidence pack went straight to our board. We did not have to translate a single page of it.
Two steps out of checkout and thirty-eight percent more carts. They argued for the simpler version and they were right.
A free 30-minute call, then a short discovery. We map the growth blocker and the risk exposure in the same conversation, and come back with a fixed-scope proposal. Typical start time is one to three weeks.
The founders, directly. Nimesh Fernando leads the design side, Eradh Jayasundara leads security. There is no account-manager layer and no handover to a junior after the pitch — you get a direct WhatsApp number on day one.
Fixed scope, fixed price — a written number before any work starts. No open hourly billing, change requests priced up front, and monthly or milestone terms.
That is the point of the alliance. Design and security run in parallel rather than in sequence, under a single scope with a single named owner — one proposal, one invoice, one schedule. Findings surface while they are still cheap to fix.
Handover with source files and an evidence pack: a security questionnaire pack, audit-ready artefacts and a free verification re-test. Reports are written for a board, not just for engineers. Optional retainers follow — quarterly testing, vCISO cover, or always-on creative.
Leadership is UAE-based in Jumeirah, Dubai, with a delivery team in Sri Lanka and Gulf-hours overlap. We deliver across six-plus countries — the UAE, Sri Lanka, the UK, Saudi Arabia, India and Australia. NDA on request.
Thirty minutes, no pitch deck. Bring the problem — a stalled launch, a failed security questionnaire, a site that gets traffic and no enquiries — and we will tell you what we would do about it.
Jumeirah 01, Dubai, UAE · Serving the UAE, Sri Lanka and global markets · NDA on request