Trust & Security
Security is built in, not bolted on.
We take the security of your data seriously. Every platform we build is designed with security as a first-class requirement , from architecture through deployment and beyond.
Our security practices
End-to-End Encryption
All data in transit is encrypted with TLS 1.3. Sensitive data at rest (case files, documents, payment data) is encrypted with AES-256.
Access Controls
Role-based access control (RBAC) is enforced across all platforms. Privileged access requires multi-factor authentication and is logged immutably.
Continuous Monitoring
Our security team monitors all systems 24/7 for anomalies, intrusion attempts, and policy violations using automated SIEM tooling.
Vulnerability Management
We run regular penetration tests, automated dependency scanning, and code review for security issues. Critical vulnerabilities are patched within 24 hours.
Security Training
All Avonia employees complete security awareness training on joining and annually thereafter. Engineering teams receive specialised secure coding training.
Incident Response
We maintain a documented incident response plan with defined SLAs. Affected users are notified within 72 hours of a confirmed breach that affects their data.
Compliance & certifications
Tanzania PDPA
Personal Data Protection Act compliance
Kenya DPA 2019
Kenya Data Protection Act compliance
South Africa POPIA
Protection of Personal Information Act
Nigeria NDPR
Nigeria Data Protection Regulation
GDPR (where applicable)
EU General Data Protection Regulation
PCI-DSS
Payment Card Industry Data Security Standard (via processors)
Infrastructure
Avonia's platforms are hosted on enterprise-grade cloud infrastructure with automatic failover, geographic redundancy, and daily encrypted backups. We use separate environments for production, staging, and development , with strict access controls between them.
Our Ngomera platform additionally uses edge AI processing for local on-device inference, ensuring that security events are detected and acted upon even when internet connectivity is unavailable.
Responsible disclosure
We welcome responsible disclosure of security vulnerabilities. If you discover a security issue in any Avonia platform, please report it to us privately before making it public. We commit to:
- Acknowledging your report within 48 hours
- Investigating and providing updates as we work on a fix
- Crediting you publicly (with your consent) once the issue is resolved
- Not taking legal action against good-faith security researchers
Contact our security team
For security inquiries that are not vulnerability reports (such as audit requests, compliance questions, or penetration test scheduling), contact us at security@avonia.co.tz.