Loading...
Loading...
Security and compliance, in the open.
FasoFresh moves food, payments, and personal data for customers, independent shops, and delivery workers across the two régions today, with the rest gated until couriers reach them — so we treat security and compliance as product features, not paperwork. This page summarizes our posture in plain language: which frameworks we align with (and exactly how far that alignment goes), the concrete safeguards implemented in the platform, the infrastructure it runs on, and the live pages where you can verify our claims yourself. It complements our Security Policy and Privacy Policy.
A SOC 2-aligned control matrix maps every AICPA TSP 100 trust-service criterion (CC1–CC9, Availability, Confidentiality, Processing Integrity, Privacy) to the platform feature that implements it, with live evidence flowing from our append-only audit log. A Type 2 report requires an independent CPA examination, which has not yet been engaged — the controls and evidence pipeline are built so that engagement is a walkthrough, not a rebuild.
Our information-security controls are aligned with ISO/IEC 27001:2022 Annex A — access control, cryptography, operations security, supplier relationships, and incident management all have implemented counterparts in the platform. We have not undergone certification by an accredited body and do not claim one.
FasoFresh is not a covered entity or business associate under HIPAA and holds no protected health information (PHI). We nonetheless voluntarily apply HIPAA Security Rule-grade administrative, technical, and physical safeguards to customer data — encryption in transit, role-based access, audit trails, and breach-response procedures.
No card number and no mobile-money PIN is ever entered into FasoFresh. The credential goes to the payment provider directly and we receive an opaque reference. We hold no cardholder data, so we make no PCI DSS claim of our own — the obligation sits with the provider, and delegating it is the point.
Products whose price the State fixes or caps — bread, butane, cement, rice, sugar, essential generics — are checked at listing time and again at order time against an administrable table carrying each rule's effective date, geographic scope and source arrêté. Commission is set to zero on fixed-price lines: taking a percentage of a price the seller may not raise is itself the offence.
VAT follows the selling store's regime, not a platform-wide rate. A store under CME or RSI invoices no VAT at all; only an RNI store does, at the standard rate or the reduced restaurant rate, with per-category exemptions. A flat rate would invent tax on most of the catalogue and on every store legally barred from collecting it.
Couriers are paid the greater of what their deliveries earned and a pay floor, computed across the whole pay period, with the top-up itemised on every statement. An hourly floor derived from the SMIG and a per-delivery floor apply as alternatives rather than a stack, and tips count towards neither.
Beyond the static matrices, a catalog of automated checks continuously probes the running platform — security-header configuration, password hashing, webhook signature verification, audit-log freshness, backup and disaster-recovery artefacts, and more — each mapped to SOC 2, ISO/IEC 27001, and HIPAA Security Rule control ids. The aggregate result is published here; this is continuous monitoring in the open, not a certification.
Automated checks passing
0 of 25
Last automated run: pending first automated run
Checks re-run continuously; the nightly compliance job records every run in our append-only audit log.
Example checks currently passing
Check results are being refreshed — see the status page for platform health in the meantime.
We publish aggregate counts and passing examples only — individual failure details stay internal so this page never doubles as a reconnaissance aid.
The platform runs on Vercel's managed edge network, with data stored in managed PostgreSQL accessed exclusively through a typed ORM (no hand-built SQL in request paths). Payment collection and payouts run through mobile-money operators via a single payment aggregator, so no payment credential is stored here. The complete list of subprocessors — who they are, what data each receives, and why — is published in our Privacy Policy, §3.1, and each is bound by a data-processing agreement.
Don't take our word for it — these pages are live:
Honesty is the point of this page, so to be explicit: “aligned” and “audit-ready” are not the same as “certified” or “attested”. FasoFresh has not yet engaged an independent CPA firm for a SOC 2 Type 2 examination, nor an accredited body for ISO/IEC 27001 — those engagements are the natural next step for an operator or enterprise buyer who requires a formal report, and the control matrix, evidence pipeline, and audit log documented above exist precisely to make that step fast. Where we do state compliance outright — regulated prices, per-store fiscal regime, per-vertical licensing, and courier pay floors — it is because each is binding today and actively enforced in code, and every legal figure behind them is dated, sourced and confidence-rated in our go-live checklist rather than asserted here.
Questions from procurement or security teams: security@fasofresh.bf.