Technology Privacy

The security and privacy engineering behind the Yinetai Privacy Toolkit. Last updated: 2 July 2026.

A compliance platform has to hold itself to the standard it helps its customers meet. This statement describes the technical and organisational measures we apply to the Yinetai Privacy Toolkit. It supplements our Privacy Policy.

1. Data protection by design

  • Every workspace is scoped to its own organisation. Access checks run on every request, so one organisation can never read another's records.
  • Regulator roles (DPCO and NDPC) see only the audit cases and filings explicitly submitted or assigned to them through the platform's handoff workflow.
  • We collect the minimum account data needed to operate the service and default to the least-permissive settings.

2. Encryption and credentials

  • All traffic between your browser and our servers is encrypted with TLS.
  • Passwords are stored only as salted one-way hashes; we cannot read them and never send them by email.
  • Uploaded evidence files are fingerprinted (SHA-256) so tampering is detectable in audit packages.

3. Auditability

  • Privileged and compliance-relevant actions — record changes, submissions, decisions, exports, deletions — are written to an append-style audit trail.
  • Deleting a compliance record archives it rather than destroying it, so regulatory history stays reconstructable; archives can be restored by your organisation.
  • Audit cases are versioned, and every handoff between DP, DPCO, and NDPC is logged with who, when, and why.

4. Cookies and tracking

The platform uses a session cookie that is strictly necessary for sign-in, plus a CSRF token that protects forms against forgery. Our marketing site asks for consent before setting any preference, analytics, or marketing cookies, and works fully if you accept only the necessary ones. We do not use third-party advertising trackers inside the platform.

5. Hosting and sub-processors

Production infrastructure is operated under data-processing agreements with our hosting and payment providers. A current list of sub-processors is available on request from support@yinetai.com. Where any processing happens outside Nigeria, it is done under the transfer safeguards described in our Privacy Policy.

6. Resilience and incident response

  • Databases are backed up on a schedule, and restores are tested.
  • We maintain an incident-response procedure aligned with the NDPA's breach-notification requirements: assess, contain, notify the NDPC and affected customers within the statutory window where a notifiable breach occurs, and remediate.
  • Security reports are welcome at support@yinetai.com — please do not test against production systems without authorisation (see our Acceptable Use Policy).

7. Your organisation's responsibilities

Security is shared. Your organisation controls who gets workspace accounts, what roles they hold, and what data is uploaded. We recommend enabling only named accounts, reviewing user lists quarterly, and using the platform's departments and roles to apply least privilege.

Want a deeper technical briefing for a due-diligence review? Contact support@yinetai.com.