Trust
Security & privacy
Veligraph holds facility-level infrastructure data from official and public sources. It holds no patient data, ever.
What we store
- Health facility records: identity, location, capacity, staffing counts, services, licensing
- Facility contact details exactly as published in the official register
- No patient records, no clinical data, no personal health information
The service
- The portal is a static site served over TLS; there are no user accounts
- We use Google Analytics to understand aggregate usage of the portal; no personal or patient data is involved
- API keys are scoped per organisation and revocable
- Licensed deliveries come with a documented audit trail of source and transformation
Data protection
We operate to the principles of the data protection regimes in our coverage area, including Nigeria's NDPR and South Africa's POPIA. A data processing agreement is available to licensed customers. Facility staff named in an official register can request removal of their name from our copy; the register itself is the authority.
Reporting
Security concern or vulnerability: hello@veligraph.com. Data error: see corrections.