Access control
Signed, expiring access tokens, rotating refresh tokens, role checks, disabled-account enforcement, and hashed API keys.
Africa Data Bank is SOC 2 compliant and regularly audited. This page explains the controls visible in the platform; qualified customers can request the supporting security documentation.
Security assurance program
Audit documents can contain confidential infrastructure and control details. Contact the security team to request the appropriate assurance material for procurement or vendor review.
Request documentationThese are implemented platform controls, not a substitute for the independent report.
Signed, expiring access tokens, rotating refresh tokens, role checks, disabled-account enforcement, and hashed API keys.
Security-sensitive changes record the actor, action, outcome, request ID, and timestamp in an append-only audit stream.
Every observation response identifies its publisher, retrieval path, data vintage, and lineage mode. Managed runs add verifiable run IDs and transformation hashes.
Health probes, durable service volumes, immutable historical data artifacts, and documented recovery procedures support continuity.
We can provide security documentation alongside data licensing and service terms.