Skip to main content

Compliance & Certifications

AfriRoute operates under recognized security and privacy frameworks and supports the data-protection laws of the African markets it serves.


๐Ÿ… Certifications & Attestationsโ€‹

FrameworkScopeStatus
ISO/IEC 27001Information Security Management SystemCertified
SOC 2 Type IISecurity, Availability, ConfidentialityAttested (annual)
PCI DSS Level 1Payment card processingCompliant (payments scope)
GDPREU data subjectsCompliant
ISO/IEC 27018Cloud PII protectionAligned

Audit reports (SOC 2, ISO certificates) are available to enterprise customers under NDA via the Trust Center.


๐ŸŒ Regional Data Protectionโ€‹

AfriRoute supports compliance with key African data-protection regimes:

Country / RegionRegulation
NigeriaNDPR / NDPA
KenyaData Protection Act 2019
South AfricaPOPIA
GhanaData Protection Act 2012
EthiopiaPersonal Data Protection Proclamation
Pan-AfricanAfrican Union Malabo Convention alignment

Data residency: tenants are pinned to a home region (East / West / Southern Africa), and customer data stays in-region except where the tenant explicitly opts into cross-region failover.


๐Ÿงพ Data Protection Principlesโ€‹

flowchart LR
COL[Lawful collection] --> MIN[Data minimization]
MIN --> PUR[Purpose limitation]
PUR --> RET[Retention limits]
RET --> DEL[Secure deletion]
  • Minimization โ€” only data needed to deliver the service is collected.
  • Purpose limitation โ€” message content is used to deliver and report, not for unrelated processing.
  • Retention โ€” data is kept only as long as required by contract, regulation, and configured tenant policy.
  • Right to erasure โ€” data subject deletion requests are honored via documented workflows.

๐Ÿ‘ค Data Subject Rights (GDPR / POPIA / NDPA)โ€‹

RightHow AfriRoute Supports It
AccessTenant can export records via API/dashboard
RectificationTenant-controlled data is editable
ErasureDeletion workflow with audit record
PortabilityStructured export (JSON/CSV)
Restriction / objectionProcessing flags per tenant configuration

A Data Processing Agreement (DPA) is available; AfriRoute acts as a processor for customer-submitted personal data.


๐Ÿ’ณ Payments Compliance (PCI DSS)โ€‹

The Payments service operates in a segmented PCI scope:

  • Card data is tokenized; raw PANs are never stored by application services.
  • The cardholder-data environment is network-isolated with restricted, logged access.
  • Quarterly ASV scans and annual penetration tests are performed.
  • Mobile-money flows follow each provider's certification requirements.

๐Ÿชช Identity & Biometric Dataโ€‹

Identity verification involves sensitive biometric data, handled with elevated controls:

  • Stored field-level encrypted with dedicated keys (see Encryption โ†’).
  • Access is least-privilege and logged per read in the audit trail.
  • Retention is limited to the verification purpose and applicable law; raw images are purged after the retention window.

๐Ÿšจ Breach Notificationโ€‹

On a confirmed personal-data breach, AfriRoute follows regulatory timelines โ€” including the GDPR 72-hour authority-notification window and equivalent obligations under POPIA, NDPA, and Kenya's DPA. Affected customers are notified without undue delay through the incident response process.


๐Ÿ“‹ Shared Responsibilityโ€‹

AfriRouteCustomer
Platform security, certifications, infraLawful basis for messaging recipients
Encryption, access control, auditConsent / opt-out management
Sub-processor due diligenceSecure handling of received data
Breach detection on platformSecuring API keys & endpoints


Last Updated: May 2026