A division of Jiranisoko Market Ltd
Jiranisoko Tech

Governance, compliance and service assurance

Contractual commitments, not aspirations.

Every engagement is governed by a written service framework. These terms are available for review before contract, and our security documentation is released to prospective clients under non-disclosure agreement on request.

Compliance register

Each standard we work to, with its current status. A standard we follow but have not certified is shown as aligned rather than certified, because the distinction is material to a vendor risk reviewer and misrepresenting it is a disqualifying event.

Standard Status Last reviewed Evidence
ISO/IEC 27001 Aligned — not certified Sep 2026 Available under NDA
PCI-DSS v4.0 Aligned — not certified Sep 2026 Available under NDA
SOC 2 Type II Certification in progress Sep 2026 Available under NDA
Kenya Data Protection Act 2019 Aligned — not certified Sep 2026 Available under NDA
GDPR Article 28 Aligned — not certified Sep 2026 Available under NDA
WCAG 2.2 AA Aligned — not certified Sep 2026 Available under NDA

Service level framework

Service level tiers, availability targets and response commitments
Tier Availability target P1 response P1 resolution target Coverage Service credits
Platinum 99.95% 15 minutes 4 hours 24 × 7 × 365 Yes
Gold 99.9% 1 hour 8 hours 24 × 5 plus on-call Yes
Silver 99.5% 4 hours 2 business days 09:00–18:00 EAT No
How these are agreed

The tiers describe the framework we contract within. The targets that bind us on your engagement are the ones written into its statement of work, set against the composite service levels of the infrastructure underneath it — we will not sign up to an availability figure the platform below us cannot support. Where a tier carries service credits, clause 6 of the terms of engagement sets out how they are claimed and capped.

Security

Controls

  • Role-based access with least privilege and quarterly access review
  • Mandatory peer code review before merge
  • Dependency, secret and container scanning enforced in CI, failing closed on critical findings
  • Annual third-party penetration testing with remediation tracked to closure
  • Published responsible disclosure channel
Data protection

Processing obligations

  • Data Processing Addendum meeting Kenya Data Protection Act 2019 and GDPR Article 28
  • Region-selectable data residency, agreed before any data is processed
  • Sub-processor register with change notification
  • Documented retention and deletion schedule per engagement
  • Breach notification within the periods the applicable law requires
The instruments themselves

These obligations are not a summary of intent. They are set out in our data processing addendum, which attaches to every engagement that involves personal data, and the sub-processor register it is honoured against. Both are published in full rather than sent on request.