AAHRED logoAAHRED home

Trust & security

Data governance and security

This page is maintained by AAHRED to answer the security and privacy questions donors, ministries and partners ask during due diligence. It describes controls we operate today — it is not an independent audit report or a certification.

Analyst reviewing access-control dashboards beside a secured server room

Principles

Ministry-owned data, least-privilege access, auditable decisions

Programme data is generated with and belongs to national institutions. Our architecture is designed so that ownership survives the end of any single grant, and so that every privileged action leaves a trace.

Least privilege

Access is granted by role, reviewed on change of duties and revoked on departure.

Data minimisation

We collect the smallest set of fields that makes the service work.

Defence in depth

Authorisation is enforced in the application and again in the database.

Screened uploads

Attachments are scanned and rejected before they reach durable storage.

Controls in force

What is actually enabled on this platform

Only controls currently operating are listed. Where a control is a self-declared alignment rather than an audited certification, that is stated.

ControlStateHow it works
Access controlRole-based, least privilegeAdministrative data is reachable only through authenticated, role-checked server functions; roles are held in a dedicated table separate from user profiles.
Row-level authorisationEnforced in the databaseEvery table carries row-level security policies; enquiry records are readable only by accounts holding the administrator role.
Attachment handlingPrivate storage, signed linksUploaded documents are stored in a private bucket and released only through short-lived signed URLs issued after a role check.
Malware screeningEnabled on uploadAttachments are screened for known signatures, macro-enabled office containers and executable markers before storage; unsafe files are rejected.
Spam and abuse protectionServer-verified challengeThe contact form uses a signed server-side challenge and a hidden honeypot field to block automated submissions.
Transport securityHTTPS everywhereAll traffic is served over TLS; the application issues no mixed-content requests.
Secret managementServer-side onlyService credentials are held as server environment secrets, are never shipped to the browser and are never written to logs.
Audit trailRetainedEnquiry records retain a reference number, submission timestamp, scan result and delivery state for accountability.

Data lifecycle

From collection to deletion

Stage 1

Collection

Minimum necessary fields, explicit purpose statements and documented consent for research data.

Stage 2

Transmission

Encrypted in transit; attachments screened before they reach durable storage.

Stage 3

Storage

Managed cloud storage with row-level authorisation and private buckets for documents.

Stage 4

Use

Access limited to named roles; research analysis uses de-identified extracts wherever identification is not required.

Stage 5

Sharing

Ministry data remains ministry-owned; onward sharing requires a documented agreement and purpose limitation.

Stage 6

Retention & deletion

Category-specific schedules with deletion on request where no statutory duty to retain applies.

Donor standards

Alignment reviewers ask about

Statements below describe AAHRED's own posture. Certification-style claims are made only where an external body has issued an opinion, which is noted explicitly.

Standard or frameworkPostureBasis
Uniform Guidance (2 CFR 200)Systems mappedCost allocation, procurement and sub-recipient monitoring documented for federal and bilateral awards.
IFRS-aligned reportingIn forceAccrual accounting with restricted and unrestricted fund segregation, externally audited annually.
GDPR (EU 2016/679)AlignedLawful-basis register, data-subject rights workflow and processor agreements maintained by the secretariat.
Kenya Data Protection Act 2019Registered controllerProcessing notified, retention schedule documented and transfers assessed before sharing.
CCPA / CPRAAlignedNo sale or cross-context sharing of personal information; rights requests handled through the privacy contact route.
ISO 27001 principlesReferenced frameworkControl design references the standard's domains. This is a self-declared alignment, not a certification.
IFC Performance Standards 1–8Applied in screeningEnvironmental and social risk screening for blended-finance and SME capital facilities.
OECD DAC aid effectivenessOperating modelCountry-systems delivery, ministry data ownership and joint results reporting.

Incident response

What happens if something goes wrong

  1. Detect

    Error monitoring, delivery logs and enquiry audit trails surface anomalies; staff are required to report suspected incidents immediately.

  2. Contain

    Affected credentials are rotated, the impacted access path is disabled and the scope of exposure is bounded before any remediation is attempted.

  3. Assess

    Data categories, individuals and jurisdictions in scope are identified, and notification duties assessed against applicable law.

  4. Notify

    Where a notifiable personal-data breach is confirmed, the competent authority and affected individuals are informed without undue delay.

  5. Remediate & learn

    Root cause is documented, controls are changed, and the Audit & Risk Committee reviews the incident at its next sitting.

Shared responsibility

Who is accountable for what

Platform layer

Hosting, managed database, storage and authentication services provide encrypted transport, managed patching and regional data residency for the infrastructure this site runs on.

AAHRED secretariat

We are accountable for the data we collect, the roles we grant, the retention schedules we apply, the agreements we sign with ministries and the training our staff complete.

Partners and customers

Ministries and partners remain the owners of their programme data and control onward use; users of this site are responsible for the accuracy of what they submit to us.

Reporting a vulnerability

Report suspected vulnerabilities or data-handling concerns through the secretariat contact form, marking the subject as a security report. Please include reproduction steps and avoid accessing or altering data that is not yours. We acknowledge reports with a reference number and do not pursue action against good-faith researchers.

Tripartite operating model

Think tank, implementation partner and governance/MEL advisory in one institution

Evidence generation translates into execution and delivery, which is in turn evaluated and governed — closing the loop between research, policy design, operations and accountability. Each arm is independently staffed and independently reported, so evaluation is never marked by the team that delivered the work.

  • Pillar 1

    Think Tank & Applied Research Arm

    Evidence generation, policy analytics and horizon scanning

    • Translational policy research turning epidemiological, macroeconomic and spatial data into legislative roadmaps and ministerial briefs.
    • Econometric and micro-simulation modelling: cost-benefit analysis, UHC fiscal space assessment and predictive shock modelling.
    • Policy harmonisation with AU Agenda 2063, the Abuja Declaration, the Maputo Plan of Action and Africa CDC frameworks.
    • Ethics, bioethics and data sovereignty protocols safeguarding indigenous health data, genomic assets and vulnerable population registries.
    Core outputs
    Ministerial briefs, costed policy options, national investment cases, peer-reviewed papers and open data dictionaries.
    Methods & instruments
    Micro-simulation, spatial econometrics, cost-benefit and fiscal-space modelling, horizon scanning and political-economy analysis.
    Delivery capacity
    42 researchers, economists and modellers across epidemiology, health financing, GIS and bioethics.
  • Pillar 2

    Implementation & Programme Delivery Arm

    Technical assistance, direct execution and capacity building

    • Direct programme rollout and pilot scalability across maternal-child health, cross-border surveillance, nutrition hubs and safety nets.
    • Embedded technical assistance seconding senior advisors, health economists and data architects into line ministries and RECs.
    • SOP development codifying clinical pathways, MISP emergency response and multi-agency coordination manuals.
    • Institutional capacity building for decentralised civil servants, local councils and community health networks.
    Core outputs
    Programme designs, SOP libraries, service-delivery pilots, supply and referral pathways, trained frontline cadres.
    Methods & instruments
    Embedded technical assistance, results-based grant execution, MISP emergency response, sub-award management and procurement support.
    Delivery capacity
    Field teams across 14 countries with surge deployment inside 72 hours for outbreak and displacement events.
  • Pillar 3

    MEL & Governance Advisory

    Accountability, systems strengthening and oversight

    • Third-party monitoring and independent verification of multilateral programmes in high-risk and cross-border corridors.
    • Impact evaluation using RCTs, difference-in-differences and mixed-method process evaluation to measure attribution and ROI.
    • Digital MEL infrastructure: mobile-first pipelines, geospatial dashboards and automated anomaly detection against data falsification.
    • Public financial management and governance audits covering procurement integrity and expenditure tracking.
    Core outputs
    Independent verification reports, impact evaluations, governance and PFM audits, live MEL dashboards.
    Methods & instruments
    RCTs, difference-in-differences, mixed-method process evaluation, third-party monitoring and anomaly detection analytics.
    Delivery capacity
    Evaluation unit operating to OECD-DAC criteria with a firewalled reporting line to the Board Audit Committee.

  1. 01

    Diagnose

    Burden, equity and fiscal-space diagnostics using national datasets, geospatial layers and community consultation.

  2. 02

    Design

    Costed intervention design with theory of change, indicator framework and explicit assumptions on attribution.

  3. 03

    Pilot

    Controlled implementation with embedded measurement to test feasibility, unit economics and delivery risk.

  4. 04

    Scale

    Government-owned scale-up with SOPs, workforce training, procurement pathways and digital reporting rails.

  5. 05

    Evaluate

    Independent evaluation, public financial audit and open publication of results — including null findings.

Engagement matrix

Multi-level institutional engagement

Who AAHRED works with at each level of governance, what it delivers there, the legal instruments used and the cadence of reporting back to partners.

Institutional clients, service offerings, engagement instruments and reporting cadence at each level of governance.
Governance levelCore institutional clientsKey service offeringsEngagement instrumentsReporting cadence
Continental & MultilateralAfrican Union, Africa CDC, UNECA, WHO AFRO, World Bank, Global FundStrategic framework development, regional public goods governance, cross-border treaty alignment and macro-level grant evaluation.Framework agreements, technical secretariats, joint working groupsMulti-year (3–5 yrs)
Regional Economic CommunitiesEAC, IGAD, ECOWAS, SADCSurveillance harmonisation, cross-border migration protocols and trade-related biosecurity standards.Protocol harmonisation compacts, corridor surveillance MOUsAnnual review cycles
National GovernmentsMinistries of Health, Finance, Gender/Social Protection and AgriculturePolicy formulation, UHC benefit package design, fiscal space analysis and embedded ministerial technical assistance.Embedded advisory placements, costed national plans, MoUsBudget-cycle aligned
Sub-National & Local GovernanceCounty and district health directorates, municipalities, local councilsDecentralised planning, budget execution tracking, frontline worker training and community engagement architecture.County work plans, community compacts, frontline training grantsQuarterly

  • Closing the policy-to-execution gap

    Unlike academic think tanks producing non-operational papers, or NGOs executing without rigorous evaluation, AAHRED unifies theoretical rigour with frontline delivery.

  • End-to-end programmatic lifecycle

    Empirical research → policy drafting → pilot implementation → nationwide scale-up → independent impact evaluation.

  • South-led contextualisation

    Endogenous African data models accounting for informal economies, pastoralist mobility and customary governance systems overlooked by external consultancies.

Evaluation standards
OECD-DAC criteria
Financial reporting
IFRS + 2 CFR 200
Data protection
GDPR / national DPAs
Safeguarding
PSEAH policy, independent channel

How does AAHRED avoid marking its own homework?
The MEL and Governance Advisory arm is staffed separately from delivery teams and reports directly to the Board Audit Committee. Where a programme exceeds USD 2 million in value, evaluation is contracted to an external firm under OECD-DAC criteria and published in full, including null and negative findings.
Who owns the data and intellectual property generated?
Primary data collected in-country is co-owned with the relevant national authority and stored under that country's data-protection regime. Anonymised, aggregated indicators are released as open data under CC-BY 4.0 with a published data dictionary; genomic and vulnerable-population registries are governed by a separate sovereignty protocol requiring ministerial consent for any secondary use.
How quickly can AAHRED mobilise for an emergency?
Surge teams deploy inside 72 hours for outbreak, flood and displacement events in the 14 countries of operation, using the Minimum Initial Service Package (MISP) and pre-positioned framework contracts for procurement and logistics.
What financial and procurement standards apply?
Accounts are prepared under IFRS and audited annually by an international firm. Grant administration follows 2 CFR 200 for US-sourced funds and EU PRAG-equivalent procedures for European funds. Sub-awards are subject to pre-award capacity assessment, quarterly financial verification and spot audits.
How are safeguarding and misconduct concerns handled?
A PSEAH policy applies to every staff member, consultant and sub-grantee. Reports can be made through an independent channel that bypasses line management, are triaged within 48 hours and investigated by an external panel where a conflict of interest exists.
Can governments contract AAHRED directly?
Yes. Engagements are structured as framework agreements, embedded advisory placements or results-based delivery contracts, aligned to the national budget cycle so that costed plans arrive before the medium-term expenditure framework is fixed.
How is value for money demonstrated?
Every investment case carries a benefit-cost ratio, cost per DALY averted and a fiscal-space assessment. Delivery is tracked against unit-cost benchmarks, and variance above 15 percent triggers a formal review by the Programme Committee.