Security and privacy
Security and privacy by design.
The platform treats visitor identity, contact details, and health responses as sensitive operational data. Access is limited, actions are logged, and geographic intelligence is shown in aggregate.

HealthRadar is designed to support public-health monitoring while minimizing unnecessary exposure of personal and location data.
Read the Privacy policy for the full data-protection detail.
- 01
Role-based access control
Staff see the surfaces that match their role. Administrators, surveillance officers, and doctors work from different views of the same programme.
- 02
Least-privilege architecture
Permissions are scoped to the work at hand. System administration is isolated from operational staff access.
- 03
Field-level encryption
Names, passport and national ID numbers, email addresses, dates of birth, and contact numbers are encrypted at rest with AES-256-GCM. One-way hashes support lookup without exposing the underlying value.
- 04
Data protection
Sensitive fields are encrypted and data moves over protected connections. Retention follows the monitoring window and applicable public-health record-keeping rules.
- 05
Audit trails
Access and material actions are recorded so programmes can review who saw what, and when, during an incident or inspection.
- 06
Secure communication
Check-ins are delivered through configured WhatsApp and SMS channels. Delivery status is operational metadata, not a public feed.
- 07
Privacy-preserving heatmaps
Maps show aggregated counts at LGA or community level. They are not a tracker of individual visitors.
- 08
Operational access controls
Sessions are short-lived, staff authentication is required for the command platform, and public pages never expose operational records.
Sensitive fields are encrypted before they are stored, access is role-scoped and audit-logged, and maps aggregate to local government area and community level.