Security & Compliance
Your data is protected. Here’s exactly how.
LCT Africa is built for healthcare, an industry where data breaches are not just technical failures, but human ones. Every architecture decision reflects that.
How We Protect You
Eight layers of protection, built into the platform.
Security is not a feature we added on top. It is the foundation every module is built on.
Data Encryption
All stored data is encrypted with AES-256. All data in transit is protected by TLS 1.3. Biometric templates are stored as encrypted mathematical representations; the raw image is never retained after enrolment.
Kenya Data Protection Act Compliance
LCT Africa operates in full compliance with the Data Protection Act 2019. Member personal and health data is collected only with consent, used only for the purposes disclosed, and never sold or shared with third parties.
Role-Based Access Control
Every user operates within a defined role with the minimum permissions required for their function. Scheme administrators, providers, claims analysts, and members each have separate, scoped access. All role assignments are logged.
Audit Logs & Activity Tracking
Every action in the platform (claim approval, benefit change, member data edit) generates an immutable audit entry with timestamp, user ID, and action detail. Logs are available for regulatory review and dispute resolution.
Backup & Disaster Recovery
All data is replicated across geographically separated infrastructure. Recovery time objective (RTO) and recovery point objective (RPO) are tested quarterly. No single point of failure.
Data Residency
Member and scheme data is hosted within Kenya. LCT Africa does not transfer personal health data outside the country without explicit authorization from the data controller.
Biometric Data Protection
Fingerprint and facial recognition data is stored as encrypted templates, not raw images. Templates cannot be reverse-engineered into the original biometric. Access to biometric stores is restricted to authenticated system processes only.
Incident Response
LCT maintains a documented incident response process. In the event of a data breach, affected parties and the Office of the Data Protection Commissioner are notified within the timelines required by law.
Questions?
Questions about our security posture?
Our team can walk you through our data handling practices, answer compliance questions, or arrange a technical security review.
