Effective 28 July 2026
Security
How Afialytics approaches security for a multi-tenant analytics platform—tenancy-aware by design, with shared responsibility between us and your organization.
1. Overview
Afialytics is built so organizations can analyze warehouse data with clear boundaries between tenants, workspaces, and people. Security is a shared duty: we secure the platform; you secure accounts, roles, and the data you choose to connect.
This page summarizes our posture. It is not a penetration-test report, certification claim, or invitation to probe the Service. Testing against production without written authorization is prohibited.
2. Design principles
- Tenancy isolation — organization and workspace boundaries are enforced in application authorization and data access paths;
- Least privilege — roles and capabilities limit what members can see and change;
- Defense in depth — authentication, authorization, encryption in transit, and monitoring work together;
- Customer control — you decide connectors, table access, model publish, and dashboard sharing;
- Privacy by design — personal data handling aligns with our Privacy Policy, Data Use Policy, and the Nigeria Data Protection Act, 2023.
3. Identity and access
Users authenticate with credentials managed through our identity stack. Organization owners provision members and assign workspace access. Capability checks gate sensitive product areas.
You should require strong passwords, rotate credentials for provisioned accounts, remove access promptly when people leave, and treat invite and recovery flows as sensitive.
4. Protecting data
In transit
Traffic to the Service is protected with modern TLS. Connections to your warehouses use the secure channels supported by each connector.
At rest and in processing
Platform databases and storage rely on provider-managed encryption at rest. Query results and catalogs are stored for your tenant to operate live analytics and are subject to retention rules in the Data Use Policy.
Customer warehouses
Your source systems remain under your control. We access them using credentials or roles you configure, for the operations you authorize (test, catalog refresh, query). Prefer least-privilege database roles.
5. Application and platform controls
- Authorization checks on sensitive routes and APIs;
- Workspace-scoped access to models, reports, and dashboards;
- Optional dashboard-level visibility and chart/tab restrictions;
- Audit-oriented membership and provisioning workflows for organization owners;
- Rate limiting and abuse controls on selected public and authenticated endpoints;
- Segregation of platform operator tools from customer tenants.
6. AI feature security
Oma and related agents operate in your authenticated session and workspace context. Prompts and Outputs are treated as Customer Data for that tenant. We configure model providers as subprocessors with contractual restrictions on use.
Do not place production secrets in prompts. Review automated suggestions before applying changes to models or boards.
8. Vendors and subprocessors
We rely on cloud and SaaS providers for hosting, email, and AI inference. We assess material vendors for security and privacy practices and bind them contractually where they process personal data or Customer Data. Contact [email protected] for a current subprocessor summary under NDA or customer agreement where applicable.
9. Vulnerability reports
If you believe you have found a security vulnerability in the Service, email [email protected] with enough detail for us to reproduce the issue. Please do not access other customers’ data, destroy data, or publicly disclose the issue before we have had a reasonable chance to respond.
We appreciate responsible disclosure and will make good-faith efforts to acknowledge valid reports.
10. Incident response
We maintain processes to detect, triage, contain, and remediate security incidents. Where a personal data breach affecting Customer Data occurs, we will notify designated customer contacts without undue delay and share information reasonably needed for your regulatory obligations under Nigerian law and your policies.
11. Compliance roadmap
We align product and operations with the NDPA and good industry practice for SaaS analytics. Formal certifications (for example independent audit reports) may be pursued as the company grows; this page will be updated when attestations are available. Until then, do not treat marketing language as a substitute for a signed security schedule in your contract.
12. Contact
Security: [email protected]. Privacy: [email protected]. Legal: [email protected].