Built so your data, and your decisions, stay yours.
Audit logs on every decision
Every score, override, and reviewer action is logged with reasoning. Not just an outcome.
Webhook signature verification
Stripe and Clerk webhooks are cryptographically verified and deduplicated against replay.
Role-based access control
Organisation-scoped roles. Applicants, reviewers, and organisers separated by design.
Data residency
Application data at rest in Azure South Africa North. LLM inference currently routes to Azure OpenAI in the EU (Sweden Central), encrypted in transit; full in-region inference is on the roadmap.
Consent before collection
We collect only what the programme defines. Applicant consent required for AI features.
Honest about certifications
FairLens is a young company. We do not yet have SOC 2, ISO 27001, or any third-party security certification. We will publish each one as it is awarded. Not before.
Aligned to NDPR + POPIA
We design FairLens to align with the Nigeria Data Protection Regulation (NDPR) and South Africa's Protection of Personal Information Act (POPIA). Alignment, not certification. We will publish formal attestations only as they land.
Aligned to Kenya DPA + Ghana DPA
We also design to align with Kenya's Data Protection Act 2019 and Ghana's Data Protection Act 2012. Same framing: we name the statutes we hold ourselves to, and won't claim certifications we don't have.
Cross-border AI processing
LLM inference currently leaves the African region for Azure OpenAI in the EU (Sweden Central), encrypted in transit. This is documented in our Privacy Policy; full in-region inference is on the roadmap and we'll mark it shipped only when it ships.
Have a specific security review to run?