ZenoXCare — marketing
Loading standards & compliance…
ZenoXCare operates on a pan-African baseline of internationally recognised security, privacy, clinical, and AI-governance standards — overlaid with data-protection regimes of every country we serve. Compliance is transparent, verifiable, and auditor-ready.

Live metrics from our compliance registries, updated weekly
ISO, AICPA, HL7, WHO, NIST, OWASP
Full jurisdiction registry + rollout waves
Third-party verified attestations
SOC 2, ISO 27001, Ghana DPC
Live status of all third-party certifications and audit evidence collection. Every certification is verifiable and audit-ready.
External CPA firm (engagement TBD)
External CPA firm (engagement TBD)
Accredited certification body (e.g., BSI, DNV, TÜV)
Accredited certification body (joint scope with 27001)
Data Protection Commission, Ghana
External CREST/OSCP-credentialed pentest firm (engagement TBD)
Self-assessed; QSA validation when card data scope expands
HITRUST-authorised external assessor
Every standard below links to its publisher's authoritative source. Our alignment status is reviewed quarterly and verified independently by the auditors who issue our certifications.
Foundational ISMS controls and third-party attestations governing how ZenoXCare protects systems, data, and customer trust.
ISO/IEC
International standard for an Information Security Management System (ISMS) — risk-based controls covering organisation, people, processes, and technology.
AICPA
Reporting framework on controls relevant to Security, Availability, Confidentiality, Processing Integrity, and Privacy of a service organisation.
AICPA
Reporting framework on controls relevant to user entities' Internal Control over Financial Reporting (ICFR).
Privacy-by-design controls extending the ISMS to personal data lifecycle management.
Verification standards for secure software development and runtime defence.
Operational continuity, disaster recovery, and incident-response disciplines.
Card and mobile-money compliance, settlement integrity, and payout safeguards.
Open standards for safely exchanging clinical information between systems.
Globally-recognised vocabularies for unambiguous clinical meaning.
Sector-specific operating standards for digital health systems and clinical workflows.
ISO
Health-sector application of ISO/IEC 27002 — security management in health using ISO/IEC 27002 controls.
World Health Organization
Standards-based, Machine-readable, Adaptive, Requirements-based, Testable — WHO's framework for digital adaptation kits in health systems.
Lifecycle controls for trustworthy, ethical, and human-supervised AI in healthcare.
ISO/IEC
AI Management System — requirements for establishing, implementing, maintaining and continually improving an AI management system within an organisation.
NIST (USA)
AI Risk Management Framework — voluntary guidance to incorporate trustworthiness considerations into the design, development, use, and evaluation of AI products, services, and systems.
World Health Organization
Ethics and governance of artificial intelligence for health — six principles ensuring AI works to the public benefit of all countries.
Standards held in reserve until any feature is classified as Software as a Medical Device.
Continental and regional instruments framing pan-African data, privacy, and digital-trade obligations.
African Union
African Union Convention on Cyber Security and Personal Data Protection — continental instrument harmonising data protection and cybersecurity.
African Union
Continental policy framework governing data, cross-border flows, and digital trade across African Union member states.
ECOWAS
ECOWAS Supplementary Act on Personal Data Protection — regional instrument governing data processing across West African member states.
National statutes that overlay the pan-African baseline as ZenoXCare enters each market.
Data Protection Commission, Ghana
Statutory data protection law in Ghana; controllers and processors must register with the Data Protection Commission.
Information Regulator, South Africa
Protection of Personal Information Act — South Africa's primary data protection statute; requires Information Officer registration.
Nigeria Data Protection Commission
Nigeria Data Protection Act, 2023 — established the Nigeria Data Protection Commission; recognises lawful bases including contract, legal obligation, and vital interests.
Per-topic surfaces that are themselves entity-first, AI-search ready, and built directly from the same registries that drive this hub.
AI Governance
Replayable traces, regression gates, prompt- and tool-injection defenses, on-device WebLLM, MCP / A2A surfaces.
Open
Conformity matrix
Live cross-mapping of every regulatory framework to its declared standards and the certifications that satisfy it.
Open
Live calendar
Forward-looking compliance events derived live from the certifications registry. Overdue items pinned at the top.
Open
Regression bar
Published budgets per intent, latest archived run, pass/fail per metric — surfaced from the repo's eval artifacts.
Open
Security findings
Severity → remediation SLA matrix, finding-status workflow, and live counts. CI gates breaches at build time.
Open
Auto-KYC v1
Ghana Card / NIA, passive liveness, sanctions screen, GhanaPostGPS, three-band decisioning with reviewer co-pilot.
Open
Audit roadmap
Every active, in-progress, and planned third-party attestation with renewal cadence and scope.
Open
Pan-African coverage
Per-country data-protection statute, regulator engagement, and rollout wave for every African Union member state.
Open
For every African country, we document the applicable data-protection statute, regulator engagement, and rollout wave.
Answers grounded in the published compliance registry. Runs in your browser via WebLLM when WebGPU is available; falls back to the registry FAQ otherwise — works fully offline once loaded.

Our compliance and security teams are ready to help. Get detailed audit documentation, compliance reports, or speak directly with our experts.
All documentation is verified and audit-ready