Skip to content
XuremiXuremi
Security & data

Your data stays yours.

How we approach security, written plainly. If you need specific answers for a procurement or regulator questionnaire, ask us and we will respond in writing.

01

Where your data lives

For a private AI deployment, the model and the data it reads run on infrastructure you control, whether that is your own servers or a private cloud account. We design it so your records are not sent to a third-party AI service.

02

Who can see what

Our own back office uses role-based access: people are given only the level they need, and every change is written to an activity log. In a deployment for you, we agree the roles and permissions with you during design.

03

Credentials and keys

Third-party API keys and mailbox passwords are stored sealed, and only the last few characters are ever shown back in a browser.

04

Payments

We operate live M-Pesa Daraja integrations. Payment callbacks are verified with a signature and timestamp before they are accepted, so a forged or replayed message is refused.

05

Your control

You own the environment, the logs and the shutdown switch. If a deployment is no longer wanted, access is removed and data is returned or deleted as agreed.

06

Reporting a concern

If you think you have found a security problem, email info@xuremi.co.ke with the details. We read every report and will reply.

Need a security questionnaire answered?

Send it to us with the deployment you have in mind. We respond with specifics for that project rather than a generic statement.

Security & data | Xuremi