Skip to main content
Trust & Security

Built so your data, and your decisions, stay yours.

Here's what's shipped today, honestly. We update this page when we ship more.

Audit logs on every decision

Every score, override, and reviewer action is logged with reasoning. Not just an outcome.

Webhook signature verification

Stripe and Clerk webhooks are cryptographically verified and deduplicated against replay.

Role-based access control

Organisation-scoped roles. Applicants, reviewers, and organisers separated by design.

Data residency

Application data at rest in Azure South Africa North. LLM inference currently routes to Azure OpenAI in the EU (Sweden Central), encrypted in transit; full in-region inference is on the roadmap.

Consent before collection

We collect only what the programme defines. Applicant consent required for AI features.

Honest about certifications

FairLens is a young company. We do not yet have SOC 2, ISO 27001, or any third-party security certification. We will publish each one as it is awarded. Not before.

Aligned to NDPR + POPIA

We design FairLens to align with the Nigeria Data Protection Regulation (NDPR) and South Africa's Protection of Personal Information Act (POPIA). Alignment, not certification. We will publish formal attestations only as they land.

Aligned to Kenya DPA + Ghana DPA

We also design to align with Kenya's Data Protection Act 2019 and Ghana's Data Protection Act 2012. Same framing: we name the statutes we hold ourselves to, and won't claim certifications we don't have.

Cross-border AI processing

LLM inference currently leaves the African region for Azure OpenAI in the EU (Sweden Central), encrypted in transit. This is documented in our Privacy Policy; full in-region inference is on the roadmap and we'll mark it shipped only when it ships.

Have a specific security review to run?