Compliance & Certifications
AfriRoute operates under recognized security and privacy frameworks and supports the data-protection laws of the African markets it serves.
๐ Certifications & Attestationsโ
| Framework | Scope | Status |
|---|---|---|
| ISO/IEC 27001 | Information Security Management System | Certified |
| SOC 2 Type II | Security, Availability, Confidentiality | Attested (annual) |
| PCI DSS Level 1 | Payment card processing | Compliant (payments scope) |
| GDPR | EU data subjects | Compliant |
| ISO/IEC 27018 | Cloud PII protection | Aligned |
Audit reports (SOC 2, ISO certificates) are available to enterprise customers under NDA via the Trust Center.
๐ Regional Data Protectionโ
AfriRoute supports compliance with key African data-protection regimes:
| Country / Region | Regulation |
|---|---|
| Nigeria | NDPR / NDPA |
| Kenya | Data Protection Act 2019 |
| South Africa | POPIA |
| Ghana | Data Protection Act 2012 |
| Ethiopia | Personal Data Protection Proclamation |
| Pan-African | African Union Malabo Convention alignment |
Data residency: tenants are pinned to a home region (East / West / Southern Africa), and customer data stays in-region except where the tenant explicitly opts into cross-region failover.
๐งพ Data Protection Principlesโ
flowchart LR
COL[Lawful collection] --> MIN[Data minimization]
MIN --> PUR[Purpose limitation]
PUR --> RET[Retention limits]
RET --> DEL[Secure deletion]
- Minimization โ only data needed to deliver the service is collected.
- Purpose limitation โ message content is used to deliver and report, not for unrelated processing.
- Retention โ data is kept only as long as required by contract, regulation, and configured tenant policy.
- Right to erasure โ data subject deletion requests are honored via documented workflows.
๐ค Data Subject Rights (GDPR / POPIA / NDPA)โ
| Right | How AfriRoute Supports It |
|---|---|
| Access | Tenant can export records via API/dashboard |
| Rectification | Tenant-controlled data is editable |
| Erasure | Deletion workflow with audit record |
| Portability | Structured export (JSON/CSV) |
| Restriction / objection | Processing flags per tenant configuration |
A Data Processing Agreement (DPA) is available; AfriRoute acts as a processor for customer-submitted personal data.
๐ณ Payments Compliance (PCI DSS)โ
The Payments service operates in a segmented PCI scope:
- Card data is tokenized; raw PANs are never stored by application services.
- The cardholder-data environment is network-isolated with restricted, logged access.
- Quarterly ASV scans and annual penetration tests are performed.
- Mobile-money flows follow each provider's certification requirements.
๐ชช Identity & Biometric Dataโ
Identity verification involves sensitive biometric data, handled with elevated controls:
- Stored field-level encrypted with dedicated keys (see Encryption โ).
- Access is least-privilege and logged per read in the audit trail.
- Retention is limited to the verification purpose and applicable law; raw images are purged after the retention window.
๐จ Breach Notificationโ
On a confirmed personal-data breach, AfriRoute follows regulatory timelines โ including the GDPR 72-hour authority-notification window and equivalent obligations under POPIA, NDPA, and Kenya's DPA. Affected customers are notified without undue delay through the incident response process.
๐ Shared Responsibilityโ
| AfriRoute | Customer |
|---|---|
| Platform security, certifications, infra | Lawful basis for messaging recipients |
| Encryption, access control, audit | Consent / opt-out management |
| Sub-processor due diligence | Secure handling of received data |
| Breach detection on platform | Securing API keys & endpoints |
๐ Related Documentationโ
Last Updated: May 2026