This checklist documents the security practices that cyber liability insurance underwriters typically evaluate. It reflects the current state of Eniena Technologies Limited(trading as "Comutte") as of the date above.
1. Access Control
- ✓Multi-factor authentication (MFA) enforced for all admin and staff accounts via Supabase Auth.
- ✓Role-based access control (RBAC) with three roles: admin, staff, operator. Least-privilege principle applied.
- ✓Row-level security (RLS) policies on all database tables restricting access by role and ownership.
- ✓Service-role keys restricted to server-side code only, never exposed to clients.
- —Privileged access review performed quarterly (not yet scheduled).
2. Data Encryption
- ✓All data encrypted in transit via TLS (HTTPS enforced, no HTTP fallback).
- ✓Data at rest encrypted with AES-256 by Supabase (AWS infrastructure).
- ✓Card payment data handled by PCI DSS Level 1 compliant processor (Paystack). No card numbers stored.
- ✓Database credentials, API keys, and secrets stored in environment variables — never committed to version control.
- —Full encryption key rotation schedule documented (managed by Supabase, not directly controlled).
3. Vulnerability Management
- ✓Weekly OWASP ZAP automated vulnerability scans on production endpoints.
- ✓Dependency audit on every deployment (npm audit).
- ✓Initial penetration assessment completed July 2026 (OWASP ZAP automated assessment).
- —Annual third-party penetration test by external firm (not yet engaged).
- —Formal vulnerability disclosure program with SLA for response (planned).
4. Incident Response
- ✓Written incident response plan with 5 phases: Detection, Containment, Notification, Recovery, Post-Incident Review.
- ✓Incident logging system with 48-hour post-mortem scheduling.
- ✓Incident knowledge base with searchable root cause categories.
- ✓48-hour data breach notification commitment (to controllers and affected users).
- —Tabletop incident response exercise conducted annually (not yet conducted).
5. Business Continuity
- ✓Database automated daily backups with point-in-time recovery (managed by Supabase).
- ✓Application deployed on global edge network (Vercel) with automatic failover.
- ✓Payment processing failover: card (Paystack) and Mobile Money (manual MoMo) dual channels.
- —Documented disaster recovery plan with RTO/RPO targets (not yet formalised).
- —Annual business continuity test (not yet conducted).
6. Employee and Contractor Security
- ✓All production access gated behind authenticated accounts with role verification.
- ✓Staff role with limited permissions — no access to financial settings, operator management, or platform configuration.
- —Formal security awareness training program (not yet implemented).
- —Background checks for employees with access to PII (not yet formalised).
- —Signed acceptable use and confidentiality agreements (not yet standardised).
7. Third-Party Risk
- ✓Third-party sub-processors documented in Data Processing Agreement (Supabase, Vercel, Paystack, Meta, Anthropic).
- ✓Payment processor (Paystack) is PCI DSS Level 1 compliant.
- ✓Database provider (Supabase) runs on AWS with SOC 2 compliance.
- —Formal vendor security assessment questionnaire (not yet standardised).
- —Annual review of sub-processor security posture (not yet scheduled).
8. Regulatory Compliance
- ✓Privacy Policy published and accessible, compliant with Ghana Data Protection Act, 2012 (Act 843).
- ✓Data Processing Agreement template available for operators.
- ✓Data deletion process documented with 14-business-day SLA.
- ✓Data retention policy: 180 days, clearly communicated.
- —Registration with Ghana Data Protection Commission (to be completed).
9. Summary
| Category | In Place | Planned |
|---|
| Access Control | 4 | 1 |
| Data Encryption | 4 | 1 |
| Vulnerability Management | 3 | 2 |
| Incident Response | 4 | 1 |
| Business Continuity | 3 | 2 |
| Employee Security | 2 | 3 |
| Third-Party Risk | 3 | 2 |
| Regulatory Compliance | 4 | 1 |
| Total | 27 | 13 |
27 of 40 underwriter-expected controls are currently in place. 13 are planned or in progress. This checklist is updated as controls are implemented.
10. Contact
- Security Contact: support@bookcomutte.com
- Phone: 020 324 2649
- Address: 10 Aviation Road, Airport Residential Area, Accra, Ghana
See also our Security Page, Privacy Policy, and Data Processing Agreement.