Skip to main content
LCT Africa

Security & Compliance

Your data is protected. Here’s exactly how.

LCT Africa is built for healthcare, an industry where data breaches are not just technical failures, but human ones. Every architecture decision reflects that.

Ask our team a security question
Kenya Data Protection Act 2019
AES-256 Encryption at Rest
TLS 1.3 in Transit
Role-Based Access Control

How We Protect You

Eight layers of protection, built into the platform.

Security is not a feature we added on top. It is the foundation every module is built on.

Data Encryption

All stored data is encrypted with AES-256. All data in transit is protected by TLS 1.3. Biometric templates are stored as encrypted mathematical representations; the raw image is never retained after enrolment.

Kenya Data Protection Act Compliance

LCT Africa operates in full compliance with the Data Protection Act 2019. Member personal and health data is collected only with consent, used only for the purposes disclosed, and never sold or shared with third parties.

Role-Based Access Control

Every user operates within a defined role with the minimum permissions required for their function. Scheme administrators, providers, claims analysts, and members each have separate, scoped access. All role assignments are logged.

Audit Logs & Activity Tracking

Every action in the platform (claim approval, benefit change, member data edit) generates an immutable audit entry with timestamp, user ID, and action detail. Logs are available for regulatory review and dispute resolution.

Backup & Disaster Recovery

All data is replicated across geographically separated infrastructure. Recovery time objective (RTO) and recovery point objective (RPO) are tested quarterly. No single point of failure.

Data Residency

Member and scheme data is hosted within Kenya. LCT Africa does not transfer personal health data outside the country without explicit authorization from the data controller.

Biometric Data Protection

Fingerprint and facial recognition data is stored as encrypted templates, not raw images. Templates cannot be reverse-engineered into the original biometric. Access to biometric stores is restricted to authenticated system processes only.

Incident Response

LCT maintains a documented incident response process. In the event of a data breach, affected parties and the Office of the Data Protection Commissioner are notified within the timelines required by law.

Questions?

Questions about our security posture?

Our team can walk you through our data handling practices, answer compliance questions, or arrange a technical security review.

Currently onboarding new schemes

Ready to see LCT in action?

Book a 30-minute demo. We'll walk you through the modules that matter most for your organisation, and answer the hard questions.

No commitment required · Typical demo is 30 minutes

Not sure where to start?