The controls behind the platform.
Privacy software that doesn't take its own security seriously is a contradiction. Here is how we run ours — auditable, Lagos-built, and engineered for the NDPC era.
The enforcement gap is no longer theoretical.
NDPC numbers, public as of 2025. Roughly 30,000 organisations are required to file compliance audit returns and haven't. Trust is no longer a slide — it's an exhibit.
Where we are, and where we're going.
Information security management — Stage 1 readiness review complete.
Operational controls, monitored continuously by an independent auditor.
Operated by ASIRI Compliance Ltd — three years of NDPA programs run by hand.
Nine pillars of the security program.
AES-256 at rest, TLS 1.3 in transit. BYOK and HSM-backed keys on Enterprise.
SSO (SAML/OIDC), SCIM provisioning, hardware-key 2FA. Role-based plus ABAC, scoped to tenant.
Hash-chained audit log, signed evidence exports, auditor rooms — every action verifiable in one click.
AWS af-south-1 (Cape Town) by default. Lagos Local Zone available on Enterprise.
Public list, 30-day change notifications, contractual flow-down of NDPA obligations.
RPO 5 min · RTO 1 hour. Disaster-recovery exercises tested and documented quarterly.
Row-level security in Postgres, per-tenant encryption keys, hard schema boundaries.
24/7 detection, anomaly alerts, immutable logs shipped to a separate security tenant.
On-call engineers in Lagos. NDPC 72-hour breach clock wired into the runbook.
Security as a daily practice, not a poster.
Threat modelling on every module. Code review, dependency scanning and SAST gate every release.
Background checks, least-privilege by default, quarterly access reviews — including for founders.
Every sub-processor risk-assessed against NDPA Article 29 before onboarding.
The things procurement always asks.
AWS af-south-1 (Cape Town) by default, with a Lagos Local Zone option for Enterprise customers who need in-country residency.
Postgres row-level security plus per-tenant encryption keys. There is no shared admin path that can read across tenants without a signed, audited break-glass.
Our on-call rotation triggers the NDPC 72-hour clock automatically. We notify affected tenants, file the Article 40 report and ship a post-incident pack within 14 days.
Yes. Enterprise customers can run an annual independent test against a staging tenant. Reports are shared under NDA.
Found something? Tell us.
We run a coordinated disclosure program. Send PGP-signed reports to security@asiri.ng. We acknowledge inside 24 hours, triage inside 72, and credit researchers in our hall of thanks.