Your data stays yours.
How we approach security, written plainly. If you need specific answers for a procurement or regulator questionnaire, ask us and we will respond in writing.
01
Where your data lives
For a private AI deployment, the model and the data it reads run on infrastructure you control, whether that is your own servers or a private cloud account. We design it so your records are not sent to a third-party AI service.
02
Who can see what
Our own back office uses role-based access: people are given only the level they need, and every change is written to an activity log. In a deployment for you, we agree the roles and permissions with you during design.
03
Credentials and keys
Third-party API keys and mailbox passwords are stored sealed, and only the last few characters are ever shown back in a browser.
04
Payments
We operate live M-Pesa Daraja integrations. Payment callbacks are verified with a signature and timestamp before they are accepted, so a forged or replayed message is refused.
05
Your control
You own the environment, the logs and the shutdown switch. If a deployment is no longer wanted, access is removed and data is returned or deleted as agreed.
06
Reporting a concern
If you think you have found a security problem, email info@xuremi.co.ke with the details. We read every report and will reply.
Need a security questionnaire answered?
Send it to us with the deployment you have in mind. We respond with specifics for that project rather than a generic statement.