Trust & Security
Security
Last updated: 14 July 2026
Xobriq builds fraud detection and identity verification systems that customers trust with sensitive data — so our own infrastructure is held to the same standard we sell. This page summarizes the security practices described in more detail in our Privacy Policy and AI Ethics policy.
Infrastructure & Data Protection
Encryption in transit and at rest, role-based access control, least-privilege access, multi-factor authentication for administrative access, and network segmentation across our infrastructure. Our primary processing infrastructure is located in a Tier 3 data centre in Nairobi, Kenya, with sovereign-tier deployments available where designated customer data never leaves Kenya.
Monitoring & Testing
24/7 SIEM monitoring and continuous logging across production systems, regular third-party penetration testing, and secure development practices. Our models and detection systems are tested against adversarial attacks, presentation attacks, injection attacks, prompt manipulation, and evolving deepfake techniques — degraded or compromised models are retrained or rolled back.
Biometric & Sensitive Data Handling
Biometric data is processed only as strictly necessary for the verification, liveness, or fraud-prevention task requested. It is encrypted, access-restricted, deleted on the shortest schedule consistent with the customer's legal obligations, and never reused across customers or repurposed for training without explicit opt-in.
Incident Response & Breach Notification
In the event of a personal data breach posing a real risk of harm, Xobriq notifies the Office of the Data Protection Commissioner of Kenya (ODPC) within 72 hours, notifies affected data subjects where required, and notifies affected customers without undue delay.
Regulatory Compliance
Xobriq is registered with the Office of the Data Protection Commissioner of Kenya (ODPC) as a data controller and data processor, and processes personal data in accordance with the Kenya Data Protection Act, 2019 and, where applicable, the GDPR. See our Privacy Policy and AI Ethics policy for the full detail behind these practices.
Responsible Disclosure
If you've found a security vulnerability in our systems, we want to know about it. Report it to info@xobriq.com — we operate a responsible disclosure channel and will work with you to understand and address the issue.
Report it to info@xobriq.com — we take responsible disclosure seriously.
