Trust Center

Security & compliance your regulator can sign off on.

Aminata.ai is engineered for banks, Saccos, mobile money operators and regulated enterprises. This page is our public commitment on how we protect your data, your customers and your licence to operate.

Platform status
All systems operational
99.95%
30-day uptime
<150ms
Global edge TTFB
0
Open Sev-1 incidents
24/7
On-call coverage
aminata.ai web Operational
VoxID API Operational
FraudShield gateway Operational
Cloudflare edge (WAF/DDoS) Protecting
Security pillars

Defence in depth, by design.

Every layer — edge, application, data and human — is hardened and independently auditable.

Encryption everywhere

TLS 1.2+ in transit, AES-256 at rest, KMS-managed keys, and an encrypted voiceprint vault for VoxID.

Identity & access

SSO, MFA, SCIM provisioning, role-based access control, OAuth 2.0, signed API tokens, least-privilege everywhere.

Audit & governance

Tamper-evident logs with hash-chain integrity. Every analyst decision is signed, time-stamped and exportable to your regulator.

Data controls

Configurable data residency, data minimisation by default, customer-controlled retention, and right-to-erasure workflows.

Application security

Continuous dependency scanning, secure-SDLC, code reviews, secret scanning, and third-party penetration testing.

Human in the loop

Sensitive actions require analyst approval. Supervisor dashboards, four-eyes controls and escalation policies enforce governance.

Edge & DDoS protection

Hardened at the perimeter.

Aminata.ai sits behind Cloudflare's global anycast network. Bad traffic is dropped before it ever reaches our origin.

Global anycast + WAF

330+ PoPs absorb volumetric attacks. Managed WAF rulesets block OWASP Top 10, zero-day CVEs and credential-stuffing patterns.

Bot management

Suspicious automation is challenged with a managed challenge while verified bots (Googlebot, monitoring) and real humans pass through untouched.

Real-time alerting

DDoS, WAF spike and origin-health alerts page our on-call team within seconds — no need to enable "Under Attack" mode for normal operations.

Compliance

Aligned to the frameworks your regulator already trusts.

ISO/IEC 27001
Aligned controls
SOC 2 Type II
Aligned controls
GDPR & Kenya DPA 2019
DPIA support
PCI DSS scope
Tokenised handling
CBK Risk Mgmt
Guideline aligned
FATF AML/CFT
Typologies built-in

Independent certifications are issued and renewed on a rolling basis. Request the current SOC 2 / ISO report and DPIA template from your account team.

Built for regulated institutions

The same platform — tuned to your supervisory regime.

Banks

Aligned to CBK Risk Management Guidelines, KYC/AML, sanctions screening and the BCBS 239 data-quality principles.

Saccos & MFIs

Built for SASRA reporting cadence, member-data protection and tiered approval matrices for fraud and disbursement events.

Regulated enterprises

Telcos, mobile money providers and insurers get full evidence packs, signed audit trails and regulator-ready exports.

Incident response

A defined playbook, every time.

Whenever something abnormal happens — DDoS surge, suspicious sign-in pattern, dependency CVE — this is how we react.

  1. T+0Detect

    Automated monitors, WAF events and customer reports open an incident.

  2. T+15mTriage

    Severity assigned (Sev-1 to Sev-4). On-call engineer + security lead engaged.

  3. T+60mContain

    Mitigation rolled out at the edge (Cloudflare), in app, or at the data layer.

  4. T+24hNotify

    Customers notified per contract. Regulator notification when materiality thresholds are met.

  5. T+5dPost-mortem

    Blameless RCA shared with affected customers; preventive actions tracked to closure.

Subprocessors

The vendors that help us serve you.

A current list, kept up to date. Material changes are communicated in advance.

VendorPurposeRegion
CloudflareDDoS protection, WAF, CDN, DNSGlobal anycast
Supabase / PostgresApplication database & authEU / configurable
OpenAI / Anthropic via gatewayLLM inference (no training)EU/US
Resend / MailgunTransactional email deliveryEU/US
Responsible disclosure

See something? Tell us — we'll fix it.

We welcome reports from security researchers. Please email security@aminata.ai with reproducible steps. We commit to acknowledge within one business day, work in good faith on a fix, and credit you on this page once resolved.