Security

Data Security

Last updated: July 27, 2026

Your fleet data is the backbone of your operations. We treat its security with the same seriousness you would. This page describes the technical and organisational measures Tanka uses today — no certifications or uptime guarantees we do not hold.

Infrastructure

Cloud Hosting

Tanka is hosted on reputable cloud infrastructure with provider-managed redundancy and monitoring. We do not claim a specific uptime percentage or SLA we cannot stand behind.

Network Security

Traffic is served over HTTPS with HSTS. We use provider firewalling and network controls, and separate customer environments logically.

Database Isolation

A multi-tenant architecture with logical data isolation. Each customer's data is stored in isolated schemas to prevent cross-tenant access.

Backups

Regular encrypted backups with point-in-time recovery. Backups are encrypted and stored separately from the primary database.

Encryption

In Transit

All data transmitted between your devices and our servers is encrypted using TLS. We enforce HTTPS on all endpoints with HSTS headers.

At Rest

Stored data, including database records, file uploads, and backups, is encrypted at rest using AES-256. Encryption keys are managed by our cloud key-management service.

Key Management

Encryption keys are managed separately from encrypted data and are never exposed in application logs or error reports.

Access Controls

  • Role-Based Access Control (RBAC): Users within your organisation are assigned roles with specific permissions. Administrators control who can view, edit, or export data across modules.
  • Authentication: Secure password hashing, session management with automatic timeout, and single sign-on (SSO) where required.
  • Audit Logging: Access to sensitive data is logged with timestamp, user identity, and action performed, and is available to account administrators.
  • Internal Access: Tanka staff access to customer data is limited to authorised support and engineering personnel on a least-privilege, need-to-know basis.

Application Security

  • Secure Development: We follow OWASP secure-development guidance. Code changes go through review before deployment.
  • Dependency Management: We monitor third-party dependencies for known vulnerabilities and patch them.
  • Input Validation: User input is validated and sanitised to guard against SQL injection, cross-site scripting (XSS), and similar attacks.
  • API Security: API endpoints require authentication and enforce rate limiting.

Incident Response

We maintain a documented incident-response approach covering detection, containment, recovery, and post-incident review. In the event of a confirmed data breach:

  • Affected customers are notified without undue delay.
  • We provide a report covering scope, likely cause, and remediation.
  • Applicable regulatory authorities are notified as required by law.

Compliance

Kenya Data Protection Act

We design our data handling to align with the Kenya Data Protection Act (2019), including consent management and cross-border transfer safeguards.

Security Good Practice

Our practices are informed by established information-security good practice. We do not currently hold SOC 2 or ISO 27001 certification and do not claim one.

Regulatory Readiness

The platform is designed to support your compliance with NTSA and EPRA requirements through built-in audit trails and document management.

Data Processing Agreements

We can provide a Data Processing Agreement (DPA) that specifies data-handling obligations, sub-processors, and security commitments.

Business Continuity

We maintain documented recovery procedures covering infrastructure failover and data recovery, and we test them periodically. We will share our current recovery targets on request during a procurement review rather than publish figures we have not committed to.

Security Inquiries

If you have questions about our security practices, need to report a vulnerability, or require a more detailed assessment for your procurement process, contact us:

Tanka Technologies Inc.

Security Team: security@tanka.africa

Responsible Disclosure: security@tanka.africa with subject line “Vulnerability Report”

Need a detailed security review?

During evaluation we can walk your team through our security posture and share additional detail under NDA where appropriate.

Book a Security Briefing →