Trust

Enterprise voice infrastructure built for regulated organisations.

Signals operates within an ISO/IEC 27001:2022-certified information security management system, with core production voice data hosted in Nigerian data centres. Telecommunications services are delivered under an NCC licence. Relevant security, data-protection and regulatory evidence is made available during enterprise vendor due diligence.

Core production data

Call recordingsNigeria — no cross-border replication
Call detail recordsNigeria
KYC dataNigeria
API logsNigeria
Primary backupsNigeria
Disaster-recovery copiesNigeria — geographically separated
Monitoring and supportNigeria
ISO/IEC 27001:2022-certified ISMSNDPC registration · 2025 Data Protection AuditTelecommunications delivered under an NCC licenceCore voice data hosted in Nigeria99.99% platform SLA

A. Assurance at a glance

What we can evidence today.

ISO/IEC 27001:2022

Signals operates within an information security management system certified to ISO/IEC 27001:2022 for Software Development and Information Technology Services.

Data protection audit

Evidence of the completed 2025 Data Protection Audit is available during enterprise vendor due diligence.

NDPC registration

Evidence of registration with the NDPC as a Data Controller/Processor of Major Importance is available during enterprise vendor due diligence.

NCC licence

Telecommunications services are delivered under an NCC licence.

Local hosting

Core production voice data is hosted in Nigerian data centres.

Capacity and availability

Current platform capacity is five million calls per day, backed by a 99.99% platform SLA for enterprise agreements.

B. Information security

Controls that run the platform.

Certified ISMS

An information security management system certified to ISO/IEC 27001:2022 governs the platform.

Encryption

Data is encrypted in transit and at rest.

Multi-factor authentication

MFA is available for account access.

Role-based access control

RBAC is available so access matches the responsibility of each user.

Audit logs

Audit logs record account and platform activity.

Penetration testing

Annual penetration testing is performed against the platform.

C. Data location

Where your voice data is stored.

Core production voice data is hosted in Nigerian data centres. Call recordings are 100% Nigeria-hosted with no cross-border replication, and call detail records, KYC data and API logs are hosted in Nigeria.

Transactional email and website analytics may use external providers. Where cross-border processing applies, it is governed by safeguards consistent with NDPA transfer requirements.

Data Protection and Residency →

Local data map

Call recordingsNigeria — no cross-border replication
Call detail recordsNigeria
KYC dataNigeria
API logsNigeria
Primary backupsNigeria
Disaster-recovery copiesNigeria — geographically separated
Monitoring and supportNigeria

D. Resilience

Built to keep production voice running.

Local primary and DR

Primary infrastructure and geographically separated disaster-recovery copies are hosted in Nigeria.

Tested failover

Failover between sites is tested rather than assumed.

Documented RTO and RPO

Recovery time and recovery point objectives are documented and confirmed contractually.

Backups

Primary backups are held in Nigeria alongside the disaster-recovery copies.

Availability

Enterprise agreements carry a 99.99% platform SLA.

Capacity

Current platform capacity is five million calls per day. This is provisioned capacity, not current traffic.

Reliability and Business Continuity →

Operational security

Operational Security and Incident Management

This is the governance layer for detecting, controlling, escalating, reviewing and learning from operational and security incidents.

  • Continuous monitoring
  • Defined incident-management procedure
  • Access-controlled incident response
  • Escalation and communication
  • Post-incident review
  • Business continuity and disaster recovery
  • Annual testing

Operating model →

Regulatory context

The obligations our regulated customers carry.

Under the Nigerian regime, accountability for an outsourced function stays with the regulated institution. Signals does not take on your regulatory obligations. Signals is accountable to you, contractually, for the evidence, controls, service levels and cooperation you need in order to discharge them.

CBN Risk-Based Cybersecurity Framework

The Central Bank of Nigeria's risk-based cybersecurity framework and guidelines set expectations for third-party and vendor risk management, security provisions in vendor contracts, and the escalation of cyber incidents. Signals is engaged as a service provider under those expectations, not as a supervised institution.

CBN Guidelines on Shared Services Arrangements

Arrangements in which a bank relies on an external provider are expected to rest on documented due diligence, board-approved risk assessment and defined service arrangements. Signals supplies the evidence and contractual terms that support that assessment.

CBN Consumer Protection Regulations

Complaint handling, evidence of customer interactions and record-keeping remain the bank's responsibility. Signals provides call records, authorised recording access and completed-call data so that evidence can be produced from the bank's own systems.

Nigeria Data Protection Act 2023 and NDPC GAID 2025

Where Signals processes personal data on your instruction, it does so as a data processor under a data processing agreement, with defined security obligations, notification of personal-data breaches to you as controller, and transfer conditions where any cross-border processing applies.

Data localisation for payment data

The Central Bank of Nigeria has directed that payment transaction data generated in Nigeria be stored and managed locally. Core production voice data on Signals — recordings, call detail records, KYC data, API logs, primary backups and disaster-recovery copies — is already hosted in Nigerian data centres.

What Signals accepts contractually as an outsourced provider.

  • Defined service levels, including a contract-backed 99.99% platform SLA and agreed escalation paths.
  • Incident notification to you, on defined terms, so that your own regulatory reporting can be made within your timelines.
  • Customer audit rights, and cooperation with inspections and information requests made by your regulator.
  • Disclosure of the service providers and subprocessors used in delivering the service.
  • Business continuity and disaster-recovery evidence, including tested failover and documented RTO and RPO.
  • A data processing agreement, with defined roles, security obligations and breach-notification terms.
  • Data location commitments for core production voice data, including recordings held in Nigeria without cross-border replication.
  • A documented exit and transition plan, covering export of recordings and call data and the return or deletion of data.

What Signals does not claim.

  • Signals is not licensed, approved, certified or supervised by the Central Bank of Nigeria.
  • Signals does not assume your regulatory obligations and does not make regulatory notifications on your behalf.
  • Signals does not provide legal or regulatory advice, and nothing here is a substitute for your own compliance assessment.
  • Regulatory positions are confirmed in the enterprise agreement, the data processing agreement and your integration review, not by this page.

Banks and Financial Institutions →

E. Enterprise assurance documents

What we supply to your evaluation team.

  • ISO/IEC 27001:2022 certification evidence.
  • Data-protection evidence, including NDPC registration and the 2025 Data Protection Audit.
  • Data processing agreement.
  • Completed security questionnaire.
  • Penetration-testing information.
  • Architecture and data-flow summary.
  • Business continuity and disaster-recovery summary.
  • Enterprise Operations, SLA and escalation overview.
  • Service-provider and subprocessor schedule.
  • Regulatory alignment summary for Nigerian regulated institutions, covering CBN cybersecurity, shared-services and consumer-protection expectations and NDPA/NDPC obligations.
  • Outsourcing clause schedule, covering service levels, incident notification, audit and inspection rights, subcontracting disclosure, and exit and transition.

F. Customer responsibilities

What remains with you.

  • Ensure every call placed through Signals serves a lawful purpose.
  • Obtain and maintain the consent and notices your regulator requires for recorded calls.
  • Protect account credentials, API keys and SIP credentials, and apply MFA and role-based access to your users.
  • Operate within the Signals acceptable use policy, including the prohibitions on caller-ID spoofing, harassment, fraudulent collections, unsolicited bulk voice advertising and international revenue-share fraud.

Next step

Send the evidence to your security team.

We supply the enterprise assurance pack directly to evaluating organisations, and our engineers will walk your architecture, security and risk teams through the call path.