Built to clear bank procurement.
Our posture is documented honestly. Where something is in progress or planned, we say so — we don't claim certifications we don't hold.
This page reflects current posture as of June 2026. Items marked In progress / Planned are not yet complete.
Data protection
Kenya DPA 2019- Consent on every PII response — an explicit consent record is captured per s.30 before any personal data is returned.
- Data minimisation — responses are scoped; you receive only the fields your contract and OAuth scope allow.
- Lawful basis — processing rests on consent and/or contract.
- ODPC registrationIn progress
SOC 2
PlannedSOC 2 is on our roadmap and not yet certified. We do not claim Type I or Type II attestation today. We operate the controls listed below and can share our internal control documentation during due diligence.
Cross-border transfers
DPA 2019 s.48Where processing or hosting takes place outside Kenya, transfers are covered by consent and/or Standard Contractual Clauses (SCCs), consistent with s.48 of the Data Protection Act 2019.
CBK outsourcing posture
Vendor due-diligenceA vendor due-diligence pack — covering our controls, sub-processors, and data flows to support your CBK outsourcing assessment — is available on request to data@karibu.africa.
Controls
- TLS 1.2+ in transit
- Secrets in a managed vault (never in the repo)
- API-key rotation
- Least-privilege OAuth scopes
- Full audit logging
- PII encryption at rest
- Daily rate limits & quotas
- Dependency & secret scanning in CI
Security questions or due-diligence requests: data@karibu.africa.