Security & Compliance
Built to be trusted by East African businesses.
Your data is encrypted, backed up daily, and never shared. We comply with Kenya's Data Protection Act, KRA eTIMS, and Safaricom's official M-Pesa API — so your business stays compliant automatically.
For those who need the technical detail — transactions, payroll, customers, and tax records are protected at every layer. Here is exactly how.
What we commit to you.
Business legitimacy
MAAMUL TECH COMPANY LIMITED is registered in Kenya. Our registration and tax details are available upon request. Certificates of incorporation and compliance can be provided to verified clients.
Data protection
We operate under Kenya's Data Protection Act 2019 and are registered with the ODPC. Your data is never sold or shared without your written consent. See our Privacy Policy for full details.
Cybersecurity controls
All data is encrypted with AES-256 at rest and TLS 1.3 in transit. We run daily geo-redundant backups with 30-day retention, role-based access controls, and a full immutable audit log.
Contracts & IP
Every engagement is covered by a signed service agreement. Your data and custom configurations remain your property. We hold no licence over your business data or intellectual property.
Delivery governance
All projects follow defined milestones with written sign-off at each stage. We use versioned releases and can provide demo or repository access before you go live.
Regional tax & trade
Maamul is eTIMS-approved and issues KRA-compliant invoices automatically. We support PAYE, NSSF, and SHA filings for Kenya, plus e-invoicing for Uganda (URA) and Tanzania (TRA).
Support & SLA
We guarantee 99.5% uptime. Support runs Monday–Saturday, 7am–9pm EAT, with critical-issue response within 4 hours. Full SLA terms are included in every service agreement.
References & verification
We can provide client references, audited accounts, and proof of regulatory compliance on request. Technical due diligence is welcome — demo access is available for all active modules.
"Maamul collects and processes personal data only for the purposes stated at collection, in accordance with the Kenya Data Protection Act 2019."
→ Read our Privacy Policy"Maamul maintains AES-256 encryption, daily backups, and role-based access controls across all customer environments."
→ Read our Security StatementRequest our Client Trust Pack
Compliance documents, client references, audited accounts, and SLA terms — ready for your procurement team.
How we protect your data.
Encryption
- TLS 1.3 for all data in transit
- AES-256 encryption at rest
- Database-level field encryption for sensitive records
- M-Pesa credentials stored encrypted, never in plaintext
Access controls
- Role-based access within your account (admin, manager, cashier)
- Single sign-on (SSO) available on Enterprise
- All staff actions logged with timestamp and user ID
- Internal Maamul access is role-gated and audit-logged
Uptime & reliability
- 99.5% monthly uptime SLA for core features
- Multi-zone infrastructure — no single point of failure
- Planned maintenance windows announced 24hrs in advance
- Real-time status at status.maamul.com
Backups
- Automated daily backups with 30-day retention
- Point-in-time recovery available on Enterprise
- Backups stored in geographically separate locations
- Recovery tested monthly
Compliance & certifications.
Kenya Data Protection Act 2019
We are registered with the Office of the Data Protection Commissioner (ODPC). Data processing agreements are in place with all sub-processors.
KRA eTIMS
Maamul generates eTIMS-compliant invoices for every sale. We are an approved eTIMS-integrated software provider.
KRA PAYE / NSSF / NHIF
Payroll calculations comply with current KRA, NSSF, and NHIF schedules. Tax filing integrations are updated when rates change.
Uganda Revenue Authority (URA)
eTIMS-equivalent electronic invoicing supported for Uganda-based businesses.
Tanzania Revenue Authority (TRA)
Electronic invoicing supported for Tanzania-based businesses.
Safaricom Daraja API
M-Pesa integration uses the official Safaricom Daraja 2.0 API. We are a certified Daraja integration partner.
Security questions?
Enterprise buyers can request our full security documentation, penetration test reports, and data processing agreements.