Security & compliance

Built to clear bank procurement.

Our posture is documented honestly. Where something is in progress or planned, we say so — we don't claim certifications we don't hold.

This page reflects current posture as of June 2026. Items marked In progress / Planned are not yet complete.

Data protection

Kenya DPA 2019
  • Consent on every PII response — an explicit consent record is captured per s.30 before any personal data is returned.
  • Data minimisation — responses are scoped; you receive only the fields your contract and OAuth scope allow.
  • Lawful basis — processing rests on consent and/or contract.
  • ODPC registrationIn progress

SOC 2

Planned

SOC 2 is on our roadmap and not yet certified. We do not claim Type I or Type II attestation today. We operate the controls listed below and can share our internal control documentation during due diligence.

Cross-border transfers

DPA 2019 s.48

Where processing or hosting takes place outside Kenya, transfers are covered by consent and/or Standard Contractual Clauses (SCCs), consistent with s.48 of the Data Protection Act 2019.

CBK outsourcing posture

Vendor due-diligence

A vendor due-diligence pack — covering our controls, sub-processors, and data flows to support your CBK outsourcing assessment — is available on request to data@karibu.africa.

Controls

  • TLS 1.2+ in transit
  • Secrets in a managed vault (never in the repo)
  • API-key rotation
  • Least-privilege OAuth scopes
  • Full audit logging
  • PII encryption at rest
  • Daily rate limits & quotas
  • Dependency & secret scanning in CI

Security questions or due-diligence requests: data@karibu.africa.