Trusted Voice Research Infrastructure for NGOs, Governments & Global Development Partners
Compliance

Compliance, Security & Trust

Review the implemented, configurable and externally reviewable controls that support privacy, safeguarding, accountable access and governed evidence.

Trust Center status model

One operating view of organizational trust.

Status language distinguishes current implementation from controls that depend on configuration, documentation or external assurance.

Implemented

Security controls

Encryption, authenticated sessions, roles and access boundaries.

Documented

Privacy & data protection

Permitted processing, ownership, portability and protection context.

Documented

Safeguarding & consent

Ethical collection, consent records and escalation pathways.

Implemented

Auditability & evidence governance

Audit events, review states, evidence links and versions.

Configurable

Retention, deletion & exports

Controls are agreed and configured around the implementation scope.

Human approval required

Responsible AI

AI-assisted outputs remain review-controlled and evidence-linked.

Documented

Continuity & incident handling

Backup, recovery and incident processes are described below.

External review required

Procurement assurance

Questionnaires and supporting evidence are supplied without implying certification.

Security controls

Encryption in transit

All traffic between respondents, field devices, and our servers is encrypted over TLS/HTTPS. There is no unencrypted path into the platform.

Encryption at rest

Audio recordings and transcripts are stored in access-controlled object storage and a managed database, both encrypted at rest by our infrastructure provider.

Infrastructure

VoiceInsights Africa runs on Cloudflare's global edge network (Workers, D1, R2) — the same class of infrastructure used by major global platforms — with Twilio for telephony and messaging delivery.

Role-based access control

Every account has a defined role — organization admin, M&E officer, or system administrator — that scopes exactly what data they can see and act on.

Authentication

Passwords are hashed with PBKDF2 and never stored in plain text. Sessions use signed, time-limited tokens.

Fraud & anomaly detection

Automated checks flag near-duplicate responses and suspicious submission speed on every incoming answer, across every channel.

Legal Compliance

Designed for Tanzania's data-protection context and project-specific obligations.

Implementations are designed to support obligations under Tanzania's Personal Data Protection Act, No. 11 of 2022. Controller and processor roles, transfer safeguards and any required registrations or regulatory evidence must be confirmed for the applicable organization and project.

Accountability roles

Controller, processor and customer responsibilities are documented for the approved implementation scope.

Consent controls

Consent capture and review are configured for the approved collection workflow and applicable research protocol.

Data Minimization

We collect only what's necessary for your research purpose.

Transfer safeguards

Processing locations and cross-border safeguards are documented and agreed for the implementation scope.

Data ownership

Data rights and responsibilities are defined contractually.

Data ownership, permitted processing, retention and portability are governed by the applicable customer agreement and implementation scope.

Disaster Recovery & Business Continuity

Built on infrastructure designed not to lose your data.

Database Backups

Response data is stored on Cloudflare D1, which maintains automatic point-in-time recovery — your data isn't a single point of failure.

Audio Storage Durability

Voice recordings are stored on Cloudflare R2, built for eleven-nines (99.999999999%) durability with redundancy across multiple facilities.

Global Edge Infrastructure

The platform runs on Cloudflare's global network, not a single server — a regional outage in one location doesn't take the whole platform down.

Incident Response

Security-relevant events (logins, invites, permission changes) are logged to an audit trail your Org Admin can review at any time.

This describes the resilience built into our current infrastructure. A formal, independently-audited disaster recovery runbook with tested Recovery Time/Point Objectives (RTO/RPO) is on our roadmap as we take on larger enterprise and government contracts — ask us for the current status if this is a procurement requirement for your organization.

Methodology & Transparency

How we measure accuracy — and why we don't publish one flashy number.

Many platforms advertise a single headline accuracy percentage. We think that's misleading — accuracy varies by audio quality, background noise, dialect, and channel. Instead, here's exactly how VoiceInsights Africa computes the numbers your own dashboard shows:

Transcription Confidence

Computed directly from OpenAI Whisper's own per-segment log-probability output for every single voice response — not a marketing estimate. You see the real average for your own data in Model Performance.

Fraud Detection

Flags are based on measurable signals — response speed, duplicate phrasing, answer-length anomalies — each visible per-flag in Fraud Alerts, not a black-box score.

AI Analysis

Where enabled, AI-assisted themes and findings are grounded in governed project evidence and remain subject to configured review and human approval.

Project-specific operational evidence

Authorized Workspace users can review operational measures derived from their governed project data. Update frequency and available measures depend on the configured workflow.

We don't yet have enough aggregated production volume across enough clients to publish a statistically meaningful platform-wide benchmark — and we'd rather say that plainly than publish an inflated number. Check our live status page for current platform health.

Need a security questionnaire completed?

We're happy to complete vendor security assessments and NDAs for procurement processes.

Contact Us