Skip to main content
Security & compliance

Isolated, encrypted, backed up and monitored

How we run and protect the systems our clients depend on.

Rows of server cabinets in a data centre
Infrastructure, security and compliance

Isolated, encrypted, backed up and monitored.

Client systems run in isolated, containerised environments on monitored cloud servers, so one client's system never affects another's.

Isolation

Each client system runs in its own Docker environment on a separate private network, behind a hardened reverse proxy.

Encryption

Every system is served over HTTPS with automatically renewed SSL certificates.

Backups

Automated backups stored off-server, with restores tested regularly.

Monitoring

Round-the-clock uptime and resource monitoring with alerts to our operations team.

Updates

Security patches and version upgrades applied on a managed schedule, tested before rollout.

Access control

Least-privilege access, two-factor authentication and audit trails for administrative actions.

Data protection

Processes aligned with the Kenya Data Protection Act, 2019, with a designated data protection contact at dpo@safisystems.co.ke.

Responsible disclosure

Report security issues to security@safisystems.co.ke and abuse to abuse@safisystems.co.ke.

Report a security issue

Found a vulnerability in one of our systems? Email security@safisystems.co.ke. Abuse reports go to abuse@safisystems.co.ke, and data protection questions to dpo@safisystems.co.ke.

Need help with your own compliance?

We support ODPC registration, privacy policies, data audits, security audits and access control. Tell us where you are and we will recommend next steps.