+254 722 117 850 Support Login
Why Sozuri Trust & Security
Why Sozuri · Trust & Security

The infrastructure your CFO already trusts.

Sozuri is licensed by the Communications Authority of Kenya, aligned with ODPC data-protection requirements, and built around per-project isolation so dev never sees prod and prod never sees the wrong account. The same posture we'd want as a customer.

CAK-licensed ODPC-aligned Audit-grade logs
CAK License · Active
Application Service Provider
Per-project isolation
api-key · webhook URL · balance
Audit log · this minute
14,802 events logged · 0 dropped
Millionsof messages a day, on the platform
99.999%API success rate
100%audit-trail coverage
Per-projectisolated auth + balances
The four pillars

Security that starts at the carrier, ends at the audit log

Each pillar is independent; together they form the defence-in-depth posture our customers stake their reputations on.

Carrier-licensed

Sozuri operates under a Communications Authority of Kenya licence as a Content & Application Service Provider, with direct peering to every Kenyan carrier.

Per-project isolation

Every project has its own Bearer token, webhook URL, credit balance and sender ID assignment. Dev never touches prod; prod never sees another client.

ODPC-aligned data

Customer data is collected and stored on the principles set out in Kenya's Data Protection Act. Consent and retention practices are exportable for inspection.

Audit-grade logs

Every message, every webhook, every OTP send is logged with timestamp, sender, recipient and delivery state. Inspector-ready, exportable to PDF.

In practice

Three real-world questions, answered honestly

"How do you isolate one customer's data from another's?"

Every Sozuri project is its own tenant. The API key is scoped to a single project; the dashboard view is scoped to the user's role in that project; the database queries are partition-keyed on project ID at the row level. Cross-tenant reads are physically impossible — not just policy-impossible.

Project A · key · balance · sender
Project B · key · balance · sender
Project C · key · balance · sender
isolated at the row level

"What happens to my data if I leave Sozuri?"

Your project data, contacts, message history and audit logs are exportable from the dashboard at any time. On cancellation, you choose a retention window and we honour it — full deletion or hand-off to your nominated successor. No locked-in formats.

SOZURI Data export · ready
Export package project-galaxion.zip
4.2 GB · CSV + JSON

"How do you prevent screenshot fraud at the till?"

Every Sozuri payment confirmation SMS contains a numeric OTP that's also sent to your cashier or operator. Until both phones show the same code, the goods don't leave the till. The cleanest, simplest fraud control in Kenyan retail — built in.

M-PESA OTP-stamped receipt
Confirmed KSh 2,400 to GALAXION · OTP 8392
Cashier phone Receipt visible · OTP 8392 matches
Where we stand

Compliance posture — honest, current

Communications Authority of Kenya licence
Content & Application Service Provider, active
Active
ODPC data-protection alignment
Kenya Data Protection Act principles applied; export & deletion supported
Aligned
GDPR-aligned practices
Where customers serve EU residents; data residency on request
Aligned
ISO 27001 certification
Engagement in progress; controls already mapped & audited internally
In progress
PCI DSS
Not applicable — Sozuri does not store card data; payments rail is M-Pesa Daraja
N/A by design
Your move

Inspect us. Audit us. Ask hard questions.

Security questionnaires welcomed. Walk-throughs of our isolation model on request. We're proud of how we built this — we'd rather have you see it than guess at it.

Chat on WhatsApp
Your first SMS in the time it takes to brew coffee. Start building in minutes