Summary

  • Computer Sales & Services can be connected to a specific Tanzanian operator rather than merely to a common trading name. AFRINIC records AS327792 to an organisation of that name at the same Dar es Salaam address shown on the company website, and registry contacts use the css-tz.com domain.
  • The network footprint is current and measurable. AFRINIC records two active Tanzanian IPv4 allocations totalling 3,072 addresses, while RIPEstat showed AS327792 announcing both aggregates and several more-specific routes on July 15, 2026.
  • Public routing observations showed two neighbouring networks, Liquid Telecommunications and Aptus Solutions. That is useful evidence of more than one visible path relationship, but it does not establish physically separate circuits, independent landing routes, automatic failover or an availability commitment.
  • The commercial promise remains underspecified. CSS markets hardware, repair, connectivity, software, security systems, backup power, hospitality software and internet access, but the reviewed pages did not publish a service-level agreement, incident targets, recovery evidence, infrastructure locations, subprocessor schedule or a clear split between services CSS operates and products it resells.

A common name makes identity the first technical control

Searching for Computer Sales & Services produces unrelated businesses in several countries. That is not a minor branding inconvenience. A buyer who attaches a quotation, support number or bank instruction to the wrong company record can complete a technical assessment while still failing to identify the party responsible for delivery. For a business with a descriptive name, identity has to be assembled from matching details rather than assumed from the words above the door.

The strongest public join for the Tanzanian CSS begins with AFRINIC's record for AS327792. The registry lists the autonomous system as active, names organisation ORG-CA11-AFRINIC as Computer Sales & Services, gives a second-floor Empire Tower address at the corner of UN Road and Mathuridas Street in Dar es Salaam, and identifies administrative and technical contacts using @css-tz.com email addresses. The company's current contact page gives the same Empire Tower location, postal code 20834, several Tanzanian telephone numbers and [email protected]. Name, address and domain therefore line up across a network registry and the commercial site.

The company's history page says CSS was formed in 1996 as a seller and maintainer of computers, accessories and photocopiers. It describes appointments involving Gateway computers, Lanier office equipment and Stellar data-recovery products, followed by internet service at Hotel Sea Cliff in 2003 and a Sea Cliff Village branch in 2004. Those statements establish the story CSS tells about its development from equipment support into connectivity. They are company claims, not incorporation documents or proof that every old appointment remains in force.

One government publication supplies a narrower form of service evidence. Tanzania's Public Procurement Regulatory Authority journal of April 9, 2024 records a November 2023 minor-value award by PPRA to Computer Sales & Services Limited for the supply of a laptop, valued at TZS 10,743,000. The notice shows that a business under the longer legal-style name supplied a defined technology product to a public buyer. Because that entry does not include the supplier's address or registration number, the exact corporate join should still be confirmed rather than inferred solely from the similar name.

That remaining gap matters at contract stage. The AFRINIC organisation is named Computer Sales & Services, the procurement entry adds Limited, and the website footer and contact page do not expose an incorporation number, taxpayer number or named contracting officer. A purchaser should ask for a current company extract, tax identity, registered address and signing authority, then reconcile those fields with the quotation, invoice, bank account, support domain and AFRINIC organisation. The public material supports a strong operating-identity match; it does not by itself settle every legal-identity field.

The offer is an IT portfolio, not a single cloud product

CSS's services page spans several different operating models. It markets computers, laptops, workstations and servers; hardware and software repair; software installation and ongoing support; fibre and wireless connectivity; website design; custom software; security products; generators and uninterruptible power systems; hospitality software; and internet access for homes and businesses. These activities may be useful together, particularly for a customer that wants one local supplier to coordinate equipment, networking and field support. They do not share one assurance model.

A laptop sale is principally a product, warranty and replacement obligation. A repaired server depends on workshop skill, parts availability and preservation of customer data. Internet access depends on access circuits, upstream routing, capacity management and fault restoration. Custom software adds source ownership, deployment, maintenance and security obligations. A generator or UPS introduces fuel, batteries, load testing and maintenance intervals. Hospitality software adds reservation data, availability and payment dependencies. Calling all of this technology service obscures the different failure modes that need to appear in a contract.

The history also helps explain the breadth. CSS presents itself as an equipment company that moved into data recovery, local networking and internet connectivity, rather than as a cloud platform built around a standard compute or storage catalogue. That distinction should shape procurement. The useful comparison is not automatically CSS versus a hyperscale cloud. Depending on the requirement, it may be CSS versus a hardware reseller, an access provider, a field-maintenance contractor, a systems integrator or a software developer. A buyer first needs to define which role CSS will actually perform.

The public pages do not provide that decomposition. There is no published product catalogue for managed compute, no virtual-machine or storage specification, no service boundary for the hospitality application, no named connectivity packages, and no public matrix separating vendor warranty from CSS labour. The website says its team can tailor solutions and provide ongoing support, but it does not state which assets are owned, which platforms are operated, which suppliers sit behind them or which obligations survive when a third-party product fails.

This is where a broad local supplier can create value and risk at the same time. One accountable team can reduce coordination work for a customer with a small technology staff. The same concentration can turn one service desk, one stock of spares or one escalation chain into the bottleneck across connectivity, endpoints, power and applications. The proper question is not whether the portfolio is impressively wide. It is whether each purchased layer has a named owner, measurable deliverable and credible fallback.

AS327792 is the clearest proof of an operating surface

The network record is more precise than the sales copy. AFRINIC registered AS327792 on September 19, 2014 and marked it active at the review point. Its record for 169.255.48.0/22 shows 1,024 IPv4 addresses allocated to the CSS organisation in Tanzania on the same date. A second record for 165.16.192.0/21 shows a further 2,048 addresses allocated in December 2016. Together the two blocks contain 3,072 addresses.

Allocation is only the first layer of evidence. RIPEstat's AS overview marked AS327792 announced on July 15, 2026. Its announced-prefix view returned both covering aggregates and eleven more-specific /24 routes. Twelve of the thirteen listed routes were visible throughout the returned July 1 to July 15 window; 165.16.194.0/24 appeared from July 8. Because the more-specific routes sit inside the two allocations, they must not be added together as extra address space. Their significance is operational: CSS was actively originating a deliberately segmented routing footprint, not merely holding dormant registry entries.

Names attached to the more-specific records offer cautious clues about use. Public routing presentations label several /24 routes for single-IP customers, one for servers and one for corporate customers. Such labels suggest that CSS has divided space among access or hosting functions. They are administrative descriptions, not a customer list, utilisation report or service inventory. They do not reveal how many addresses are assigned, which systems are live, whether customers receive routed or translated service, or where the equipment is installed.

The RIPEstat neighbour observation found two networks immediately to the left of AS327792 in visible paths on July 15. RIPEstat identifies AS30844 as Liquid Telecommunications and AS37349 as Aptus Solutions. Seeing two neighbouring networks is materially better evidence than a claim of redundancy with no route data. It shows that public routes reached CSS through two distinct autonomous-system relationships at the observation point.

It still does not prove end-to-end resilience. Both relationships could enter the same building, share a duct, depend on the same power system or converge elsewhere. One might be a preferred transit path and the other a limited or backup relationship. Public BGP does not disclose circuit capacity, commercial terms, optical diversity, failover timers, route filtering or whether a customer's last-mile connection uses either path. A buyer relying on resilient connectivity should request circuit identifiers, physical route diagrams, capacity and utilisation records, a failover procedure and the result of a recent controlled test.

Route-origin protection is another defined gap. RIPEstat returned unknown rather than valid or invalid when asked to validate AS327792's origin of each covering aggregate, 165.16.192.0/21 and 169.255.48.0/22, because no validating route-origin authorisation was present in those responses. Unknown is not evidence of a hijack or misconfiguration. It means the reviewed RPKI material did not provide cryptographic authorisation for those exact origin announcements. For an operator selling business connectivity, a route-security discussion should therefore cover current route objects, filtering, monitoring, incident contacts and a plan for valid origin authorisations.

The public network profile also leaves IPv6 unresolved. AFRINIC's reviewed allocation records were IPv4, and PeeringDB's CSS-net entry marked IPv6 service false while reporting no exchange or facility connections. PeeringDB is operator-maintained and its entry contains fields that may be old, including a very low traffic band, so it cannot establish current capacity or absence from every facility. It does show that the convenient public interconnection profile is too thin to answer a buyer's IPv6, facility or peering questions. Those answers need current prefixes, test addresses and a service schedule.

Local presence does not settle data locality

CSS has a public Dar es Salaam office and office hours. The contact page lists Monday to Friday from 8:00am to 5:30pm and Saturday from 9:00am to 2:00pm. For hardware delivery, workshop service and on-site support, a reachable local team can be a practical advantage over a remote-only supplier. The contact page, however, does not say whether network faults are accepted around the clock, how severe incidents are classified, when escalation begins or what restoration target applies outside those office hours.

Local corporate and network identity also does not answer where customer information goes. AFRINIC country code TZ describes the resource holder and allocations. It does not locate servers, software databases, backups, logs, remote administration or subcontractors. Even CSS's own public website illustrates the distinction. At the observation point, Google Public DNS resolved css-tz.com to 204.12.253.120; ARIN's record for that address places the containing allocation with WholeSale Internet in the United States rather than in AS327792. That says only where the public website address is registered. It does not show where CSS puts customer workloads, and it should not be used to infer that customer data leaves Tanzania.

The lesson is narrower and more useful: a Tanzanian office, Tanzanian ASN and Tanzanian address allocation cannot substitute for a data-location schedule. A buyer should ask CSS to name the facilities and countries used for each service component, including primary systems, replicas, backups, monitoring, support access and disaster recovery. The contract should also identify subprocessors, describe cross-border access, set retention and deletion rules, and explain what evidence will be supplied after termination.

Power deserves the same specificity. CSS markets diesel generators, UPS equipment and hybrid power solutions, which may make it a capable supplier of customer-site resilience. Selling backup-power equipment is not proof that CSS's own network nodes or any hosted service have tested power continuity. Procurement should separate the customer's installation from CSS-operated infrastructure and ask for maintenance responsibility, battery age, generator runtime, fuel arrangements, load-test dates and the dependencies that remain outside the backup design.

Support assurance begins where the contact page ends

The strongest support signal in the public material is that CSS publishes a physical office, several fixed and mobile numbers, an email address and opening hours. That makes the company more reachable than a service represented only by an order form. Its history and service descriptions also indicate a longstanding emphasis on maintenance and technicians. These are useful indicators of local labour, but they do not measure the support outcome a customer will receive.

For business-critical service, the missing unit is time. The reviewed pages did not publish acknowledgement targets, engineer-engagement targets, restoration targets, support severity definitions or service credits. They did not show an outage history, current status page, maintenance calendar or public escalation route. Nor did they distinguish a normal workshop queue from a network operations function. A promise of rapid repair or uninterrupted connectivity cannot be evaluated until those claims are converted into clocks, responsibilities and evidence.

A workable support schedule should name the staffed channels for each service, the hours covered, who may declare a critical incident and when an issue moves from first-line support to a network engineer, software developer, vendor or executive. It should define remote and on-site response separately, state travel and parts assumptions outside Dar es Salaam, and identify exclusions such as customer power, third-party software or damaged cabling. Monthly reporting should show ticket volumes, response and restoration distributions, repeated faults, capacity events and planned maintenance.

Recovery needs its own proof. The company's history refers to data recovery and its services include systems, software, power and connectivity, but the public pages do not publish backup scope, recovery points, recovery times or restore-test results. A customer should decide whether CSS is supplying a backup product, operating the backup, monitoring jobs, holding encryption keys, storing a second copy or accepting responsibility for restoration. A successful backup notification is not a successful recovery.

The relevant evidence is a restore of representative data or systems under agreed conditions, with elapsed time and exceptions recorded.

Exit is part of support accountability too. Hardware warranties, network addresses, software source, credentials, configurations, logs and customer data can each have different ownership rules. Before service begins, the customer should know which IP addresses can move, which equipment belongs to whom, how configurations will be exported, how administrator access will be transferred and how retained data will be deleted. A local relationship is most valuable when it can survive a personnel change and end cleanly without becoming a hostage to undocumented knowledge.

What the public record justifies

Computer Sales & Services is not merely a shop name attached to a thin website. The matching Dar es Salaam address and company-domain contacts connect the commercial presence to an active AFRINIC organisation. AS327792 was announcing both of its allocated IPv4 blocks at this review, and public paths exposed two neighbouring networks. Those facts justify treating CSS as a Tanzanian operator with a real network surface and a broader history in equipment and technology services.

They do not justify treating every line of the sales portfolio as an assured managed service. The public material does not establish current corporate authority, customer workload location, facility ownership, physical path diversity, IPv6 delivery, route-origin authorisation, achieved uptime, recovery performance, after-hours staffing or the limits of third-party responsibility. Those are not reasons to dismiss the company. They are the subjects a serious quotation and contract must resolve.

The practical rule is simple. Use the registry and route record to verify that the network identity is real. Use the company and procurement records to verify the counterparty and the kind of work it has performed. Then require service-specific evidence for the thing being bought: asset schedules for equipment, route and circuit evidence for connectivity, architecture and data-location schedules for hosted systems, response clocks for support, and restore tests for recovery. The name Computer Sales & Services describes a wide field.

Operating assurance begins only when that field is narrowed to accountable people, measurable systems and testable promises.