How we protect data entrusted to us, and an honest account of what is switched on today.
Our whole proposition is that African institutions can trust us with unpublished research data, patient-derived genomes and surveillance results. Security is not overhead here; it is the product.
This page describes what we do. Where something is planned rather than live, it says so.
Controls In Place
Applied to every engagement.
Written Agreement First
No data is accepted before an agreement covering scope, storage location, retention period, access, authorship and intellectual property. Where a study involves human subjects we ask for the ethical approval reference.
Encrypted Transfer
Data is transferred over TLS through signed, time-limited upload links directly into project-scoped cloud storage. Files never pass through our web server.
Integrity Verification
A SHA-256 checksum is computed in your browser before upload and re-verified on arrival. A mismatch means a corrupted transfer and we ask you to resend rather than analysing it.
Named, Logged Access
Only your assigned analyst and one reviewing consultant can read your project data. Access is logged, and the log is available to you on request.
Encryption At Rest
Objects are encrypted at rest by default. Customer-managed encryption keys are available for projects whose data governance requires them.
Defined Retention
Data is returned, retained for the agreed period, or securely deleted according to your agreement. Lifecycle rules enforce this automatically rather than relying on someone remembering.
What We Will Never Do
These are contractual, not aspirational:
- Reuse client data for another project, for method development, or to train machine learning models, without written permission
- Share data between clients, or pool datasets across engagements
- Name you as a client or describe your project publicly without your written agreement
- Deposit your data in a public repository unless you ask and the consent framework allows it
- Accept research data by email or consumer file-sharing link
Our Free Tools Hold Nothing
A different model entirely
The Analysis Workbench and Results Visualiser have no server-side component that touches your data. The workbench writes CSV and JSON files in your browser; the visualiser reads result files with the browser's own FileReader and parses them locally.
You can verify both claims by opening your browser's network tab while you use them — there are no data requests. This is deliberate: several African countries restrict moving genomic or health data offshore, and a tool requiring upload would be unusable for exactly the people we built it for.
Being Straight About What Is Not Yet Live
Single sign-on
Our analysis tools currently sit behind a sign-in that is a user-interface control rather than a security boundary. Single sign-on through our identity provider is configured in code but not yet switched on, and the pages say so plainly when you open them.
We are comfortable publishing that because those tools hold no client data. We would not be comfortable if they did, and we will not describe them as access-controlled until the enforcement is real.
Client portal
The client portal runs in preview mode with illustrative sample data. It performs no authentication and serves no real project data. It exists so prospective clients can see what they would get.
Certification
We are not ISO 27001 certified. We have adopted the Annex A control list as an internal checklist and will pursue certification when a client contract requires it, rather than claiming a posture we have not been audited against.
Regulatory Position
Where we sit
- Kenya Data Protection Act 2019 — we are registered in Kenya and operate under it
- GDPR — applies whenever we handle data on EU subjects or work with EU institutions, which happens via European collaborators and funders
- National frameworks — Nigeria's NDPA, Ghana's DPA and South Africa's POPIA all apply depending on where samples originate
- Cross-border transfer — several African countries restrict moving health or genomic data offshore. Tell us your constraint and we will select storage regions accordingly
- Special category data — genomic data is inherently re-identifiable. We treat de-identification as risk reduction, never as anonymisation
Research use only
Our services are provided for research purposes. They are not validated or approved for clinical diagnosis, treatment decisions or individual patient management.
Reporting a problem
If you believe you have found a security issue with this site or our tools, email [email protected] with the subject line "Security". We will acknowledge within one working day. Please give us reasonable time to fix an issue before disclosing it publicly.
