Skip to main content
ASIRI

Trust is engineered,
not asserted.

Asiri is the operating layer for privacy and trust work. We hold ourselves to the same evidentiary bar we ship to customers: controls in code, audit logs on by default, and residency options built for African teams.

Trust Center preview

Customer-facing proof starts here.

Asiri customer Trust Center screenshot showing compliance evidence and trust artifacts
Public trust content is backed by internal evidence owners, freshness checks, and published sub-processor records.

What customers can request

  • Security overview and architecture notes.
  • Sub-processor register and data-location summary.
  • Penetration-test summary when available under NDA.
  • Current assurance roadmap and certification boundaries.
Encryption

Strong cryptography, on by default.

TLS in transit

Public endpoints are designed around modern TLS and HSTS controls. Service-to-service authentication is reviewed in deeper architecture sessions.

Encrypted at rest

Tenant databases, object storage, and backups are scoped for KMS-backed encryption at rest, with implementation evidence shared in the security pack.

Enterprise key options

Enterprise deployments can be scoped for customer-managed key patterns and stricter tenant-specific encryption boundaries.

Residency

African primary residency with documented exceptions.

af-south-1 primary

The Asiri control plane and tenant databases run in AWS Cape Town (af-south-1) by default. Customer-requested exceptions and processor locations are documented in the security pack.

Regulatory Intelligence boundary

When Regulatory Intelligence calls a foundation model, sensitive identifiers are tokenised where applicable. Provider region and retention settings are documented in the security pack.

Enterprise deployments can be scoped for Lagos Local Zone, MainOne, or Rack Centre residency based on customer requirements.

Assurance register

Current posture, with evidence boundaries.

NDPA
Readiness

ASIRI maintains an NDPA audit-readiness file and uses ASIRI internally to evidence its privacy operations. External DPCO/auditor validation remains pending.

May 2026
ISO 27001 readiness
Readiness

ISMS control families are mapped for readiness review. ASIRI does not claim ISO/IEC 27001 certification until an accredited certification body issues a certificate.

May 2026
SOC 2 readiness
Readiness

Trust Services Criteria mapping is in preparation. ASIRI does not claim SOC 2 Type I or Type II until an independent CPA firm issues the applicable report.

May 2026
GDPR/cross-border posture
Documented safeguards

Transfer posture is documented with safeguards, sub-processor review, and transfer-impact notes; customer counsel or auditor review remains pending where applicable.

May 2026
PCI DSS boundary
Boundary documented

ASIRI does not store, process, or transmit raw cardholder data in the application environment unless a future PCI scope assessment says otherwise.

May 2026
AI governance
Readiness

Regulatory Intelligence outputs are source-linked, reviewable, and subject to human approval; they do not replace legal advice, DPCO review, auditor review, regulator decisions, or customer counsel.

May 2026
View Trust Assurance Pack

The pack is evidence-backed readiness material for buyer, counsel, auditor, DPCO, and QSA review. It is not a certificate or external compliance outcome.

Access control

Least privilege, always.

Row-level security

Postgres RLS patterns isolate tenants at the database layer, so tenancy is enforced below the application boundary.

RBAC + MFA + SCIM

Granular role-based access control, mandatory MFA for privileged roles, and SCIM 2.0 user provisioning on the Enterprise tier.

Compliance

Posture you can audit.

  • SOC 2 Type II readiness — third-party audit roadmap in progress.
  • NDPA readiness and DPCO operating workflows for Nigerian teams.
  • ASIRI uses ASIRI internally to operate and evidence its NDPA program.
  • Current posture: NDPA audit-readiness file maintained; external DPCO/auditor validation pending.
  • Independent penetration-test summaries shared when available under NDA.
  • Third-party penetration testing is part of the assurance roadmap; summaries are shared when available.
  • Full audit log on every tenant — designed for export, immutability, and retention.
  • Coordinated vulnerability disclosure published at /policy/vulnerability-disclosure.
  • Sub-processor inventory published and version-controlled.
Claim boundaries

What we will not overstate.

Asiri readiness badges are not SOC 2, ISO 27001, or DPCO certificates.
Third-party attestations are only displayed when issued by the relevant independent auditor or certification body.
Regulatory Intelligence workflows use tokenisation and zero-retention configuration where available; cross-region processing is documented in the security pack.
The public Security Pack is a posture summary; detailed architecture evidence, penetration-test summaries, and customer-specific records stay request-gated or NDA-scoped.