DataCore Analytics

Security & Data Protection

How we protect data entrusted to us, and an honest account of what is switched on today.

Our whole proposition is that African institutions can trust us with unpublished research data, patient-derived genomes and surveillance results. Security is not overhead here; it is the product.

This page describes what we do. Where something is planned rather than live, it says so.

Controls In Place

Applied to every engagement.

01

Written Agreement First

No data is accepted before an agreement covering scope, storage location, retention period, access, authorship and intellectual property. Where a study involves human subjects we ask for the ethical approval reference.

02

Encrypted Transfer

Data is transferred over TLS through signed, time-limited upload links directly into project-scoped cloud storage. Files never pass through our web server.

03

Integrity Verification

A SHA-256 checksum is computed in your browser before upload and re-verified on arrival. A mismatch means a corrupted transfer and we ask you to resend rather than analysing it.

04

Named, Logged Access

Only your assigned analyst and one reviewing consultant can read your project data. Access is logged, and the log is available to you on request.

05

Encryption At Rest

Objects are encrypted at rest by default. Customer-managed encryption keys are available for projects whose data governance requires them.

06

Defined Retention

Data is returned, retained for the agreed period, or securely deleted according to your agreement. Lifecycle rules enforce this automatically rather than relying on someone remembering.

What We Will Never Do

These are contractual, not aspirational:

  • Reuse client data for another project, for method development, or to train machine learning models, without written permission
  • Share data between clients, or pool datasets across engagements
  • Name you as a client or describe your project publicly without your written agreement
  • Deposit your data in a public repository unless you ask and the consent framework allows it
  • Accept research data by email or consumer file-sharing link

Our Free Tools Hold Nothing

A different model entirely

The Analysis Workbench and Results Visualiser have no server-side component that touches your data. The workbench writes CSV and JSON files in your browser; the visualiser reads result files with the browser's own FileReader and parses them locally.

You can verify both claims by opening your browser's network tab while you use them — there are no data requests. This is deliberate: several African countries restrict moving genomic or health data offshore, and a tool requiring upload would be unusable for exactly the people we built it for.

Being Straight About What Is Not Yet Live

Single sign-on

Our analysis tools currently sit behind a sign-in that is a user-interface control rather than a security boundary. Single sign-on through our identity provider is configured in code but not yet switched on, and the pages say so plainly when you open them.

We are comfortable publishing that because those tools hold no client data. We would not be comfortable if they did, and we will not describe them as access-controlled until the enforcement is real.

Client portal

The client portal runs in preview mode with illustrative sample data. It performs no authentication and serves no real project data. It exists so prospective clients can see what they would get.

Certification

We are not ISO 27001 certified. We have adopted the Annex A control list as an internal checklist and will pursue certification when a client contract requires it, rather than claiming a posture we have not been audited against.

Regulatory Position

Where we sit

  • Kenya Data Protection Act 2019 — we are registered in Kenya and operate under it
  • GDPR — applies whenever we handle data on EU subjects or work with EU institutions, which happens via European collaborators and funders
  • National frameworks — Nigeria's NDPA, Ghana's DPA and South Africa's POPIA all apply depending on where samples originate
  • Cross-border transfer — several African countries restrict moving health or genomic data offshore. Tell us your constraint and we will select storage regions accordingly
  • Special category data — genomic data is inherently re-identifiable. We treat de-identification as risk reduction, never as anonymisation

Research use only

Our services are provided for research purposes. They are not validated or approved for clinical diagnosis, treatment decisions or individual patient management.

Reporting a problem

If you believe you have found a security issue with this site or our tools, email [email protected] with the subject line "Security". We will acknowledge within one working day. Please give us reasonable time to fix an issue before disclosing it publicly.

Contact DataCore Analytics

Tell us about your data and we will scope it — free, within one working day.

+233 558 017 827

Free scoping call · reply within 1 working day Get a Quote