Security, Data Protection & Governance Brief

VoiceInsights Africa — Security, Data Protection & Governance Brief

Identity and access, tenant isolation, encryption, audit trail, retention, applicable law, safeguarding, responsible AI and the independent assurance position.

Document
VIA-BRIEF-SECURITY-DATA
Version
1.0
Audience
Public · Procurement
Published
2026-09-21
Last reviewed
2026-09-21
Language
English (canonical)

The document below is the full text. It is the same content as the PDF, from one source.

VoiceInsights Africa

Security, Data Protection & Governance

VoiceInsights Africa

Implemented controls, and what no one here holds

“Every Voice. Every Language. Every Insight.”

Version1.0
Published2026-09-21
DocumentVIA-BRIEF-SECURITY-DATA
AudiencePublic · Procurement

Security architecture overview

Nothing in this document is a certification, and it says so before a reviewer has to ask.

Identity

Authentication with scoped authorisation; privileged roles carry a second factor.

Isolation

Multi-tenant architecture in which tenant isolation is an implemented boundary, not a convention.

Encryption

In transit over TLS and at rest, including voice recordings and transcripts.

Auditability

Material access, permission, review, export and disposal events remain attributable.

Retention

Follows law, consent, contract and legal holds; recovery copies inherit the same controls.

Publication

Evidence lineage, review, approval, correction and withdrawal govern what is released.

The full profile. This brief is drawn from the Company & Capability Profile 2026, which carries every capability, its registered status and its limits in full. Where the two are read together, the profile governs.

Identity, access and tenant isolation

Role-based access

Authorisation is decided per request against the role the session carries. A field session reaches its own assigned work rather than the organisation’s, and an office role reaches what its permissions allow.

Separate doors

Field staff sign in with a project code, an enumerator ID and a PIN. The email-and-password door refuses them by name and says which door to use, because an enumerator reaching the office door would hold a wider session than the work requires.

IntegrationState
ChannelsLive
Offline appLive
Email deliveryLive
Rest apiConfigured per deployment
ExportsConfigured per deployment
SsoConfigured per deployment
ScimConfigured per deployment
Bi toolsConfigured per deployment
Instrument importFormat implemented, never connected
Dhis2Format implemented, never connected
Stated precisely. Single sign-on and SCIM user provisioning are configured per deployment rather than available by default. SAML and on-premise deployment are not offered. No government identity system is integrated, and no government accreditation is held or implied.

Data protection and applicable law

Applicable law

Implementations are designed to support obligations under Tanzania’s Personal Data Protection Act, No. 11 of 2022, alongside the applicable agreement. Where a programme falls under the EU GDPR or another regime, those obligations are assessed and documented during implementation. No independent assessment of GDPR alignment has been carried out, and none is claimed.

Processing location

Processing location, subprocessors, residency requirements and transfer safeguards are assessed during implementation and documented contractually. We do not claim a universal data-residency location for every provider. The subprocessor and processing-location registers are published and read live.

Consent and retention. Consent records reflect the collection context, language, scope and withdrawal conditions. Retention follows applicable law, consent, contractual policy and legal holds — institutional memory is not used to justify unlawful personal-data retention.

Safeguarding, research ethics and responsible AI

Safeguarding

Sensitive identifiers are never requested unless a project specifically requires them under written justification. Access restriction, escalation and referral practices are configured for the approved collection context.

Responsible AI

AI contributions remain candidate intelligence until reviewed. AI does not approve evidence, decide, or authorise publication, and must never fabricate consent, authority, approvals or provenance.

Safeguarding automation is never determinative: a signal prompts a human decision and the record keeps what was decided and by whom.

Independent assurance status

Held by no one here. VoiceInsights holds no SOC 2 report, no ISO/IEC 27001 certificate, no independent penetration test and no independently audited accessibility conformance. Each is listed in the procurement pack as requiring an independent party. Accessibility is a design target of WCAG 2.2 AA measured with automated testing at four viewports plus targeted manual checks — a measurement, not a conformance claim.

What is published

15 standing procurement documents are published and can be supplied immediately, including the security overview, the trust register, the subprocessor register, the data protection position and the responsible AI position.

What requires a third party

A further 6 documents require an independent party. We hold none of them, and each is listed at that state rather than promised. A data processing agreement and a business continuity plan are in preparation.

Contact us

“Every Voice. Every Language. Every Insight.”

Tanzania — Head Office

Ali Hassan Mwinyi Road, Kisutu
3rd Floor, Haidary Plaza
P.O. Box 77139
Dar es Salaam, Tanzania

Follow us

LinkedIn
X

VoiceInsights Africa · VoiceInsights Workspace
Security, Data Protection & Governance Brief · Version 1.0 · voiceinsightsafrica.com
VIA-BRIEF-SECURITY-DATA · Published 2026-09-21 · English (canonical)
Derived from the Company & Capability Profile 2026 and the governed capability registries. 126 master claims audited; 39 excluded as future or withheld.