Security & Trust
Your organisational knowledge is sensitive. We treat it that way. Below is how Ichè protects the data you entrust to the platform.
- Uptime target
- 99.9%
- Response latency target
- < 500 ms
- Critical incident response
- < 4 hours
Monthly availability objective for the application and database.
Typical page and query response time under normal load.
Time to first human response for severity-1 issues.
These are our published targets, not a live status feed. Verified uptime and latency reports for a specific period are available on request during a security review.
Sovereign environment isolation
Every organisation is provisioned as its own sovereign environment with dedicated data, users and configuration. These boundaries ensure that each organisation operates in complete isolation from every other customer, with no visibility or access across organisations.
Each organisation operates as a separate boundary. No data, users, or configuration crosses between organisations.
Encryption
All data is encrypted in transit using TLS and at rest using industry-standard encryption managed by our cloud infrastructure provider. Passwords and credentials are handled through secure, managed authentication flows.
Access control
Access is role-based and invitation-only. Whether you run a single company or a group of subsidiaries, permissions are enforced at the database layer using Row-Level Security (RLS), so users only see the data they are explicitly allowed to see.
Audit logging & accountability
Key actions are written to an immutable audit trail, including record changes, invitations, and administrative events. Records are archived rather than hard-deleted, so your organisational history remains intact.
Backups & resilience
Database backups are managed automatically by our infrastructure provider. The platform is built on a managed, high-availability database service with built-in replication and point-in-time recovery capabilities.
Infrastructure security
The application runs on a managed, secure cloud platform with hardened networking, isolated customer data, and automated security patching. Server-side logic never exposes privileged credentials to the browser.
Authentication & identity
Users sign in with secure email and password credentials. Administrators control invitations, roles, and account suspension. Password resets are handled through signed, time-limited links.
Compliance posture
Ichè is designed with data-protection principles in mind (strict access controls, audit trails, soft-delete archive, and export-friendly record structures) to help customers meet obligations under the EU GDPR and Nigeria's NDPR. See the data protection section below for details.
Incident response
Security issues are tracked, prioritised, and remediated promptly. We monitor for vulnerabilities and apply patches as they become available. Enterprise customers are given a dedicated contact channel for security concerns.
How access scoping works
Ichè provisions every organisation as a sovereign environment. Each one is its own isolated boundary, so data from one customer never appears in another. Within that boundary, permissions are enforced in the database, not just hidden in the interface. Every record belongs to exactly one organisation. Each person is granted a role against the whole organisation or a specific subsidiary. For single-entity organisations, the same model applies with only the organisation-level scope; there are no subsidiary permissions to manage. A request that falls outside the granted scope returns nothing at all.
Organisation / Group Administrator
Whole organisation and any subsidiariesFor a single company, this role administers the entire organisation. For a group, it sees consolidated data and can administer every subsidiary, including members, roles, and settings.
Board Member / Executive viewer
Organisation-level, read-onlySees governance, strategy, and board-level material plus dashboards. Cannot edit operational records. For single entities, this is the same organisation-level view without subsidiary separation.
Subsidiary Administrator
One assigned subsidiaryFull control of their own organisation's records and members. Cannot see other subsidiaries or group-only material.
Contributor
One assigned subsidiaryCan create and edit records within their organisation, but cannot manage members, roles, or organisation settings.
Viewer
One assigned subsidiaryRead-only access to their organisation's records. No create, edit, or archive rights.
Suspended account
No accessAccess is revoked immediately at the data layer. A suspended member cannot read or change anything, even with an existing session.
Role changes take effect immediately, are written to the audit trail, and cannot be self-granted; administrators cannot change or remove their own access.
Data protection & privacy
Ichè is designed to help customers meet their obligations under the EU General Data Protection Regulation (GDPR) and the Nigeria Data Protection Regulation (NDPR) issued by NITDA. We are working toward formal certifications; in the meantime the platform provides the controls below, and your organisation remains the data controller for the information you store.
GDPR readiness
- Purpose-bound access: role-based scoping enforced at the database layer supports the principles of data minimisation and purpose limitation.
- Data subject rights: export-friendly record structures and full audit trails support access, rectification, and portability requests.
- Erasure & retention: records are archived rather than hard-deleted by default, with permanent deletion available to administrators where retention rules require it.
- Accountability: an immutable audit trail records who changed what and when, supporting your record-of-processing obligations.
- Encryption in transit and at rest, plus sovereign per-organisation isolation, provide appropriate technical and organisational measures.
NDPR readiness (Nigeria)
- Lawful processing support: consent-oriented invitation flows and explicit role grants give a clear, auditable basis for processing personal data.
- Data subject rights: Nigerian data subjects' rights to access, correct, and withdraw are supported through exportable records and administrator-managed erasure.
- Breach awareness: security monitoring, audit logging, and defined incident response help you meet NDPR notification expectations.
- Local relevance: built by a Nigeria-focused team, with controls suited to organisations regulated by NITDA's data protection framework.
- Data localisation options and a Data Protection Compliance discussion are available for enterprise customers on request.
These capabilities support your compliance programme but do not by themselves make any organisation compliant. Formal certification under GDPR- or NDPR-aligned audit frameworks is on our roadmap; contact us for our current compliance posture document.
Questions or security review?
If you are evaluating Ichè for your organisation and need a security questionnaire, compliance discussion, or architecture review, contact us. We can provide a detailed security posture document and walk through controls directly.

