Built for institutions that require proof.
Security posture, compliance documentation, encryption standards, and incident response. All published. All verifiable.
Standards we are measured against.
NDPR Compliance
Full compliance with the Nigeria Data Protection Regulation. Data classification, consent management, retention policies, and processing records documented and audited.
ISO 27001 Aligned
Information security management system aligned to ISO 27001:2022 controls. Access control, cryptography, operations security, and supplier relationships all documented.
SOC 2 Type II (In Progress)
Audit underway with an independent CPA firm. Trust Services Criteria covering security, availability, and confidentiality. Report available upon completion.
NITDA Registered
Registered technology provider with the National Information Technology Development Agency. Registration documentation available for procurement.
NIST CSF Aligned
Security practices mapped to the NIST Cybersecurity Framework. Identify, protect, detect, respond, and recover functions are all covered.
WCAG 2.2 AA
All customer-facing interfaces and internal tools designed to WCAG 2.2 Level AA accessibility standards. Verified through automated and manual testing.
How we protect data.
Every system we operate applies encryption, access control, and audit logging to data at every stage of its lifecycle.
Encryption in transit
TLS 1.2 minimum, TLS 1.3 preferred. HSTS enforced. All internal service-to-service communication encrypted with mutual TLS.
Encryption at rest
AES-256 encryption for all stored data, including databases, backups, and object storage. Keys managed via cloud KMS or HSM.
Access control
Least privilege by default. Multi-factor authentication required for all administrative access. Access reviews conducted quarterly.
Audit logging
All authentication, authorization, and data access events logged immutably. Logs retained per policy and available for audit review.
Data residency
Client data stored in the region specified in your agreement. African and European regions supported. Data never leaves the agreed jurisdiction.
Data retention and deletion
Documented retention schedules per data category. Secure deletion on contract termination with certificates of destruction available.
How we detect and respond.
Continuous monitoring
24/7 monitoring of all managed systems for anomalous behavior, failed authentications, privilege escalations, and data access patterns.
Vulnerability management
Automated scanning of dependencies, container images, and infrastructure. Critical vulnerabilities patched within 7 days. High within 30 days.
Penetration testing
Independent third-party penetration testing conducted at least twice per year. All findings remediated and documented.
Incident response
Documented incident response plan. Triage within 15 minutes for critical events. Client notification within 24 hours of confirmed breach.
Backup and recovery
Automated daily backups encrypted at rest. Monthly restore drills. Recovery point and time objectives defined per system.
Business continuity
Documented business continuity plan, tested annually. Multi-region failover for critical systems. Recovery objectives published per service.
Who we work with.
We are transparent about every third party that processes client data. The full subprocessor list is maintained and available on request.
Cloud infrastructure
Google Cloud Platform and Amazon Web Services. Both covered by enterprise DPAs and standard contractual clauses.
Communication and support
Google Workspace for internal email and collaboration. Zendesk or equivalent for client support if used.
Monitoring and error tracking
Sentry for application error tracking. Grafana Cloud or self-hosted Prometheus for metrics. No client PII included in telemetry.
Payment processing
Paystack for Nigerian transactions, PayFast for South African transactions. Card data is never stored on our infrastructure.
What we will send you.
Verified procurement teams and security reviewers can request the following under NDA. Typical turnaround is 2 business days.
Security whitepaper
Full documentation of security architecture, controls, and practices. Written for technical reviewers.
SOC 2 report (when complete)
Independent audit report covering security, availability, and confidentiality Trust Services Criteria.
ISO 27001 control matrix
Mapping of our controls against ISO 27001:2022 Annex A. Includes implementation status for each control.
Data processing agreement
Standard DPA template ready for execution. Covers data categories, processing purposes, subprocessors, and retention.
Incident response plan
Documented procedures for detection, triage, containment, notification, and postmortem. Shared with enterprise clients under NDA.
Penetration test summary
Executive summary of most recent independent penetration test. Full report available on-site during procurement review.
Found something? Tell us.
We welcome responsible disclosure of security vulnerabilities in our systems, products, and infrastructure. Reports are acknowledged within 24 hours and triaged within 72 hours.
We do not pursue legal action against researchers who act in good faith and follow responsible disclosure practices.
Need to complete a security review?
Send us your questionnaire or security requirements. We'll respond with the documentation your review team needs.