Security & privacy
Compliance records are sensitive: they contain licence numbers, tax filings, staff training records and contracts. This page explains, plainly, how that data is protected inside HakikiComply Tanzania.
SSL secured in transit
Every request between your browser and HakikiComply is encrypted with TLS. There is no unencrypted path to your data.
Encrypted document storage
Uploaded licences, certificates and contracts are held in a private bucket scoped to your organization. Files are never publicly addressable — viewing or downloading issues a short-lived signed link generated on the server.
Role-based access control
Owner, admin, compliance manager, employee and viewer roles are enforced in the database itself, not only in the interface. Viewers cannot create or edit records even if they call the API directly.
Append-only audit logs
Sign-ins, uploads, document views, downloads, deletions and role changes are written to a log that ordinary users cannot edit or delete.
Daily backups
The managed database behind HakikiComply is backed up daily by the hosting platform so records can be restored after an accident.
Consent-based AI analysis
A document is only sent for AI extraction when you explicitly opt in during upload. Otherwise it is simply stored and tracked.
Where your data lives
Documents and records are stored on managed cloud infrastructure. Each row in the database is protected by row-level security tied to your account, so one organization can never read another organization's records.
What we do not claim
We do not currently hold SOC 2, ISO 27001 or any other third-party certification, and we will not imply otherwise. The controls described above are what we actually operate.
Reporting a vulnerability
If you believe you have found a security issue, contact us through the form on the home page and we will respond as quickly as we can.
See also our privacy policy and terms of service.
