The evidence, not just the claim
Certifications, regulatory coverage and the documents your procurement team will ask for, listed so you can check rather than take our word for it.
- Last updated
- 12 June 2026
- Last updated
At a glance
What we can put in front of procurement
SOC 2 Type II
Annual independent audit. Report shared before signature, under NDA.
ISO 27001
Certificate and statement of applicability available on request.
Kenya DPA 2019
Compliant with the Data Protection Act, 2019, and registered with the ODPC.
GDPR
DPA with Standard Contractual Clauses on every plan.
WCAG 2.2 AA
Conformance statement published, including the gaps we are still closing.
Certifications
SOC 2 Type II, audited annually by an independent firm, with the current report available under NDA. ISO 27001 certified, with the certificate and statement of applicability available on request.
We provide both before contract signature rather than after, because a security review that happens after the decision is not a review.
Kenya Data Protection Act, 2019
TeamPulse conforms with the Kenya Data Protection Act, 2019 and its subsidiary regulations, and is registered with the Office of the Data Protection Commissioner as both a data controller and a data processor.
We process personal data on a lawful basis under section 30, honour data subject rights under Part V including access, correction, deletion and objection, and apply the data minimisation and purpose limitation principles in section 25 as product constraints rather than policy statements.
Cross-border transfers follow section 48, and Kenyan customers may elect in-country or regional data residency. Our Data Protection Officer is registered with the ODPC and reachable at privacy@teampulse.app, and we notify the Commissioner and affected data subjects within 72 hours of a reportable breach as section 43 requires.
GDPR and data protection
We act as processor for employee data and controller for account data. A Data Processing Agreement incorporating Standard Contractual Clauses is available on every plan.
Records of processing, a subprocessor list, and our transfer impact assessment are published or available on request.
Employment and payroll
Statutory profiles are maintained per jurisdiction for the countries we support payroll in, covering tax, social security and mandatory contributions.
Working time, leave entitlement and public holiday rules are maintained per country so your configuration stays current without you tracking legislation.
Public sector requirements
For government and parastatal tenants we support performance contracting against a national plan reference, accounting officer approval on stage gates, and the reporting formats oversight bodies expect.
Where a procurement requires on-premises or sovereign cloud deployment, that is available rather than an exception.
Accessibility
We target WCAG 2.2 AA. Our current conformance statement, including known gaps and the schedule to close them, is available on request.
Accessibility defects are triaged on the same severity scale as functional defects, not on a separate backlog.
Audit support
The platform keeps an immutable audit trail of who changed what, when and why, retained for as long as your policy requires.
Auditors can be granted scoped read-only access rather than being sent exports, which keeps the evidence in the system that produced it.
Questions your legal team needs answered?
We will send the DPA, subprocessor list and certifications without making you sign anything first.
