Security, Data Protection & Governance
VoiceInsights Africa
Implemented controls, and what no one here holds
“Every Voice. Every Language. Every Insight.”
Security architecture overview
Nothing in this document is a certification, and it says so before a reviewer has to ask.
Identity
Authentication with scoped authorisation; privileged roles carry a second factor.
Isolation
Multi-tenant architecture in which tenant isolation is an implemented boundary, not a convention.
Encryption
In transit over TLS and at rest, including voice recordings and transcripts.
Auditability
Material access, permission, review, export and disposal events remain attributable.
Retention
Follows law, consent, contract and legal holds; recovery copies inherit the same controls.
Publication
Evidence lineage, review, approval, correction and withdrawal govern what is released.
Identity, access and tenant isolation
Role-based access
Authorisation is decided per request against the role the session carries. A field session reaches its own assigned work rather than the organisation’s, and an office role reaches what its permissions allow.
Separate doors
Field staff sign in with a project code, an enumerator ID and a PIN. The email-and-password door refuses them by name and says which door to use, because an enumerator reaching the office door would hold a wider session than the work requires.
| Integration | State |
|---|---|
| Channels | Live |
| Offline app | Live |
| Email delivery | Live |
| Rest api | Configured per deployment |
| Exports | Configured per deployment |
| Sso | Configured per deployment |
| Scim | Configured per deployment |
| Bi tools | Configured per deployment |
| Instrument import | Format implemented, never connected |
| Dhis2 | Format implemented, never connected |
Data protection and applicable law
Applicable law
Implementations are designed to support obligations under Tanzania’s Personal Data Protection Act, No. 11 of 2022, alongside the applicable agreement. Where a programme falls under the EU GDPR or another regime, those obligations are assessed and documented during implementation. No independent assessment of GDPR alignment has been carried out, and none is claimed.
Processing location
Processing location, subprocessors, residency requirements and transfer safeguards are assessed during implementation and documented contractually. We do not claim a universal data-residency location for every provider. The subprocessor and processing-location registers are published and read live.
Safeguarding, research ethics and responsible AI
Safeguarding
Sensitive identifiers are never requested unless a project specifically requires them under written justification. Access restriction, escalation and referral practices are configured for the approved collection context.
Responsible AI
AI contributions remain candidate intelligence until reviewed. AI does not approve evidence, decide, or authorise publication, and must never fabricate consent, authority, approvals or provenance.
Safeguarding automation is never determinative: a signal prompts a human decision and the record keeps what was decided and by whom.
Independent assurance status
What is published
15 standing procurement documents are published and can be supplied immediately, including the security overview, the trust register, the subprocessor register, the data protection position and the responsible AI position.
What requires a third party
A further 6 documents require an independent party. We hold none of them, and each is listed at that state rather than promised. A data processing agreement and a business continuity plan are in preparation.
Contact us
“Every Voice. Every Language. Every Insight.”
Tanzania — Head Office
Ali Hassan Mwinyi Road, Kisutu3rd Floor, Haidary Plaza
P.O. Box 77139
Dar es Salaam, Tanzania