Honest status
Namibia Health is in a development / pilot phase. We are not currently certified under HIPAA, ISO 27001, or formally verified under POPIA. The safeguards below are the ones actually in place today.
Encryption in transit
All data sent between your device and our servers is encrypted using TLS (HTTPS). This prevents interception of your information while it travels over the network.
Where data is stored
Data is stored in a managed cloud database provided by our hosting platform (Base44). The database is access-controlled and authenticated. Backups are managed by the hosting provider. We do not store data on local devices beyond what is needed for offline caching on your own device.
Access control
Each user account can only access its own records. Sensitive modules — HIV care, mental health, GBV support — are subject to the same account isolation. Platform administrators can access records only for support and maintenance purposes, and access is logged.
Access logging
The platform records an audit log when data is viewed, edited, exported, or deleted. Users can review this log from their Privacy settings.
Sensitive modules
- HIV status & care: stored under your account, visible only to you and providers you explicitly refer to.
- GBV reports: can be submitted anonymously; identifying details are kept only if you choose to provide them.
- Mental health records: session notes are visible to you and the assigned counselor only.
What is not yet in place
The following are planned but not yet implemented or certified:
- Formal third-party security audit or penetration test.
- HIPAA / ISO 27001 / POPIA certification.
- End-to-end encryption of stored field-level sensitive data.
- Formal data processing agreements with all third-party providers.
For these reasons, please do not submit real, sensitive medical data until the platform is verified. See our Privacy Policy for full details.
Reporting a security issue
If you believe you have found a security vulnerability, please report it responsibly to [Add security contact email]. Please do not publicly disclose it before we have had a chance to respond.