
Trust centre
Security, data residency and reporting routes
Access control, data residency, standards, availability commitments and the function that receives a report.
One control framework across the group
Group Security owns the control framework, the Compliance Department monitors it, Internal Audit tests it independently, and evidence is produced under contract.
Security
How the group protects what it operates
The measures below are set by Group Security, implemented by Group Operations and tested by Internal Audit.
- Access is granted by role and recordedProduction access is granted per role and per environment. Every privileged action is logged where it cannot be altered.
- Encryption in transit and at restTraffic is encrypted end to end. Data at rest is encrypted with group-managed or customer-managed keys.
- Independent review before releaseNo change reaches production without a review by someone who did not write it. Group Security reviews security changes.
- Environments are separatedDevelopment, test and production are separate estates with separate credentials. Production data is never copied into test.
- Recovery is testedBackups are restored on a defined schedule, and Group Operations documents each test with Group Security.
- Incident response with a named ownerEvery incident has one owner from detection to review, and Group Security tracks each corrective action to completion.
Data residency
Where the data stays
Customer data remains in the jurisdiction the customer chooses, and the Data Protection Office holds the record of processing and of transfers.
Group offices
Central Africa
Parousia Group
Kinshasa, Democratic Republic of the Congo
Group headquartersWest Africa
Parousia West Africa
Lagos, Nigeria
East Africa
Parousia East Africa
Nairobi, Kenya
Americas
Parousia America Inc.
New York, United States
Middle East
Parousia Middle East
Dubai, United Arab Emirates
Where a customer requires that data never leave a jurisdiction, that requirement is written into the contract by the Legal Department and implemented in the architecture of the service.
Standards
What is held, and what is only targeted
The Compliance Department maintains the register of applicable standards and the group’s status against each one.
Certificates held
The group does not hold a certificate issued against these standards; a certificate number and its issuing body are published on this page as soon as one is awarded.
Engineered to
- ISO/IEC 27001
- ISO/IEC 27701
- ISO/IEC 22301
- ISO 9001
- PCI DSS
- SOC 2
- NIST SP 800-53
- CIS Benchmarks
Availability
What the group commits to
Service objectives are agreed contract by contract, according to the criticality of the service concerned.
- Objectives are contractualGroup Operations agrees recovery time and recovery point objectives in writing with the customer before a service goes live.
- Maintenance is announcedPlanned maintenance is notified in advance and carried out within a window agreed with the customer.
- Incidents are reported to those affectedAn affected customer is told what is known at the time, and again when the review is complete.
Reporting
How to reach the group
Four routes, each with the function that receives the report and the policy that governs how it is handled.
- A security vulnerabilityReports are received by Group Security under the vulnerability disclosure policy, which provides for acknowledgement within three working days and for the group’s commitment not to pursue a researcher who follows it.
- A live incident on a service under contractCustomers under contract use the escalation path set out in their agreement, which reaches the Group Operations team responsible for the service. Where that path is not to hand, the group is reached at the contact address and the message is marked urgent.
- A data protection requestRights of access, rectification, erasure, portability and objection are handled by the Data Protection Office under the privacy policy, within the statutory period of the jurisdiction concerned.
- WrongdoingReports are received by the Legal Department, which operates the internal reporting channel under the speaking-up policy: confidentiality of identity, acknowledgement within seven days and feedback within three months.
The documents behind this page
Each commitment above is set out in full, with its regulatory basis, in the legal documents the Legal Department maintains.
- Privacy policyHow Parousia Group collects, uses and protects personal data, and how to exercise the rights attached to it.Read more
- Cookie policyWhat is stored on your device, for what purpose, and how to change that choice.Read more
- Terms and conditionsThe terms governing use of this website, and the law that applies to them.Read more
- Accessibility statementThe group’s commitment to WCAG 2.2 level AA, the measures taken on this site, and how to report a barrier.Read more
- Vulnerability disclosureHow to report a security flaw, what the group undertakes to do, and the protection afforded to researchers acting in good faith.Read more
- ComplianceThe group’s regulatory, security and ethical commitments, and the functions accountable for them in every market it operates in.In legal reviewRead more
- Anti-bribery and corruptionWhat the group prohibits without exception, and how that prohibition is enforced.In legal reviewRead more
- Speaking upHow to report wrongdoing, how the report is handled, and the protection the law affords the person who reports it.In legal reviewRead more
- Modern slavery and forced labourWhere the risk sits in the group’s supply chains, and the measures taken to address it.In legal reviewRead more
- Legal noticeWho publishes this site, under what identity, and where to address a formal notice.Read more
