Trust Center
Security, data residency, compliance, and subprocessors for AfriScore.
AfriScore builds credit intelligence infrastructure for financial institutions in emerging African markets. Because we handle borrower data, mobile money transaction histories, and credit decisions, trust is not optional. It is the product.
This Trust Center documents how we protect that trust — operationally, technically, and legally.
Who this is for
- Financial institutions evaluating AfriScore before a pilot
- Compliance and legal teams reviewing our data handling
- Security reviewers conducting technical due diligence
- Partners auditing our subprocessors and controls
What you will find here
Security
Encryption, access controls, infrastructure, and monitoring.
Data Residency
Where data lives, and how on-premise deployment works.
Compliance
OHADA, CEMAC, and GDPR-inspired data protection alignment.
Subprocessors
Every third party that may process data on our behalf.
DPA
Our Data Processing Agreement template.
Incident Response
How we detect, respond to, and communicate security incidents.
Vulnerability Disclosure
How to report a security issue to AfriScore.
Contact
Direct channel to our security team.
Our principles
Honesty over marketing. Where a control is in place, we document it. Where it is not yet in place, we say so explicitly and describe the roadmap.
Data minimization by design. We collect the minimum data required to produce a credit decision. Nothing is retained beyond the operational need.
Sovereignty for institutions. AfriScore can be deployed entirely inside your own infrastructure. No borrower data has to leave your environment.
Current status
AfriScore is an early-stage company. The trust controls documented here reflect our current operational reality, not aspirational targets.
Implemented
- Encryption in transit (TLS 1.3) and at rest
- Least-privilege access controls
- On-premise deployment option
- Formal subprocessor list (Vercel, Cloudflare, Formspree)
In progress
- SOC 2 Type II readiness (targeted after first paying CEMAC contract)
Planned
- Third-party penetration testing (scheduled with first institutional customer)
Reporting a security concern
If you believe you have identified a security issue, please contact us at security@afriscore.africa.
We respond to all reports within 72 hours.