Security controls
Encryption, authenticated sessions, roles and access boundaries.
Review the implemented, configurable and externally reviewable controls that support privacy, safeguarding, accountable access and governed evidence.
Status language distinguishes current implementation from controls that depend on configuration, documentation or external assurance.
Encryption, authenticated sessions, roles and access boundaries.
Permitted processing, ownership, portability and protection context.
Ethical collection, consent records and escalation pathways.
Audit events, review states, evidence links and versions.
Controls are agreed and configured around the implementation scope.
AI-assisted outputs remain review-controlled and evidence-linked.
Backup, recovery and incident processes are described below.
Questionnaires and supporting evidence are supplied without implying certification.
All traffic between respondents, field devices, and our servers is encrypted over TLS/HTTPS. There is no unencrypted path into the platform.
Audio recordings and transcripts are stored in access-controlled object storage and a managed database, both encrypted at rest by our infrastructure provider.
VoiceInsights Africa runs on Cloudflare's global edge network (Workers, D1, R2) — the same class of infrastructure used by major global platforms — with Twilio for telephony and messaging delivery.
Every account has a defined role — organization admin, M&E officer, or system administrator — that scopes exactly what data they can see and act on.
Passwords are hashed with PBKDF2 and never stored in plain text. Sessions use signed, time-limited tokens.
Automated checks flag near-duplicate responses and suspicious submission speed on every incoming answer, across every channel.
Implementations are designed to support obligations under Tanzania's Personal Data Protection Act, No. 11 of 2022. Controller and processor roles, transfer safeguards and any required registrations or regulatory evidence must be confirmed for the applicable organization and project.
Controller, processor and customer responsibilities are documented for the approved implementation scope.
Consent capture and review are configured for the approved collection workflow and applicable research protocol.
We collect only what's necessary for your research purpose.
Processing locations and cross-border safeguards are documented and agreed for the implementation scope.
Data ownership, permitted processing, retention and portability are governed by the applicable customer agreement and implementation scope.
Response data is stored on Cloudflare D1, which maintains automatic point-in-time recovery — your data isn't a single point of failure.
Voice recordings are stored on Cloudflare R2, built for eleven-nines (99.999999999%) durability with redundancy across multiple facilities.
The platform runs on Cloudflare's global network, not a single server — a regional outage in one location doesn't take the whole platform down.
Security-relevant events (logins, invites, permission changes) are logged to an audit trail your Org Admin can review at any time.
This describes the resilience built into our current infrastructure. A formal, independently-audited disaster recovery runbook with tested Recovery Time/Point Objectives (RTO/RPO) is on our roadmap as we take on larger enterprise and government contracts — ask us for the current status if this is a procurement requirement for your organization.
Many platforms advertise a single headline accuracy percentage. We think that's misleading — accuracy varies by audio quality, background noise, dialect, and channel. Instead, here's exactly how VoiceInsights Africa computes the numbers your own dashboard shows:
Computed directly from OpenAI Whisper's own per-segment log-probability output for every single voice response — not a marketing estimate. You see the real average for your own data in Model Performance.
Flags are based on measurable signals — response speed, duplicate phrasing, answer-length anomalies — each visible per-flag in Fraud Alerts, not a black-box score.
Where enabled, AI-assisted themes and findings are grounded in governed project evidence and remain subject to configured review and human approval.
Authorized Workspace users can review operational measures derived from their governed project data. Update frequency and available measures depend on the configured workflow.
We don't yet have enough aggregated production volume across enough clients to publish a statistically meaningful platform-wide benchmark — and we'd rather say that plainly than publish an inflated number. Check our live status page for current platform health.
We're happy to complete vendor security assessments and NDAs for procurement processes.
Contact Us