Compliance register
Each standard we work to, with its current status. A standard we follow but have not
certified is shown as aligned rather than certified, because the distinction is material
to a vendor risk reviewer and misrepresenting it is a disqualifying event.
| Standard |
Status |
Last reviewed |
Evidence |
| ISO/IEC 27001 |
Aligned — not certified |
Sep 2026 |
Available under NDA
|
| PCI-DSS v4.0 |
Aligned — not certified |
Sep 2026 |
Available under NDA
|
| SOC 2 Type II |
Certification in progress |
Sep 2026 |
Available under NDA
|
| Kenya Data Protection Act 2019 |
Aligned — not certified |
Sep 2026 |
Available under NDA
|
| GDPR Article 28 |
Aligned — not certified |
Sep 2026 |
Available under NDA
|
| WCAG 2.2 AA |
Aligned — not certified |
Sep 2026 |
Available under NDA
|
Publication gate G-02 — outstanding
No claim in this register is currently set to Certified, because no certificate
has been evidenced. Promote a row only when the certificate is held, in date, and its
reference recorded against the record. The site will then display it as certified
automatically.