- Photo capturedDone
- ID readDone
- Watchlist screeningChecking 3 lists
- The visitor waits at reception until screening finishes.
Security
Your visitors trust you with their details. We take that seriously.
Agoo holds names, phone numbers, photos and sometimes ID numbers. Every part of the platform is built to keep them private, correct and available, and to prove it to your auditors.

Controls
Protection at every layer.
Encryption
TLS for everything in transit. Databases, backups and files encrypted at rest with AES-256.
Tenant isolation
Every record belongs to one organisation, and isolation is enforced at the data layer, not only in the app.
Roles by site
Front desk, hosts, security and admins each see only what their role and site allow.
Sign-in
Single sign-on with Google, Microsoft or SAML, SCIM provisioning, and two-step verification, required for Owners and Admins and open to everyone.
Audit trail
Append-only, hash-chained records of every action, checked with Verify chain, kept for up to seven years.
Support access you control
Agoo staff never use your password. When we help, we see your organisation read-only, for a set time, and every Owner is told at once and can end it. Changes need an Owner’s approval. Emergency access, for what can’t wait, tells every Owner and Admin and is followed by a written report within 72 hours.
Account recovery that can’t be talked into
Lost a phone? A reset needs your inbox and a colleague who has checked it’s really you, or our own identity check and a 24-hour wait. A new Owner, when yours has gone, needs evidence and 72 hours’ notice that your Owner and Admins can stop.
Retention
Set how long to keep each kind of data. Deletion runs every hour and is logged.
Hosting
Application and database hosted in London, UK, with daily backups and edge delivery through Cloudflare.
Live status
status.agoo.ardent.africa checks every part of Agoo every minute from outside, and runs separately so it stays up even if Agoo doesn’t. It shows what’s happening now, planned maintenance and 90 days of history, and emails you updates if you subscribe.
Payments
Paid through Paystack’s own checkout. Card and mobile money details are handled by Paystack and never stored by Agoo; a saved card renews with Paystack’s token, kept encrypted and deleted when the card is removed. Every payment is checked with Paystack before anything changes, and test payments can never count as real ones.
Audit trail
Every action, recorded. Nothing rewritten.
Who approved which visitor, who exported what, who changed a setting: time, person and IP address, in an append-only log. Each entry carries the hash of the one before, so any change to history shows.
- Verify chain recalculates every link and checks each hourly checkpoint, kept separately from the trail
- Search by who, what, site and date, and export to CSV or Excel for your auditors
- Every export from Agoo is itself recorded: who, what, in which format and how many rows
- Nobody can edit or delete an entry, including Owners and Ardent staff
- Agoo support’s access is in it too: when it opened, what it looked at, and anything it changed
Screening
The right people in, quietly.
Watchlist checks run at check-in on names, phone numbers and ID numbers. A match holds the check-in and alerts security without a scene at the desk. Overrides need a reason, and every one is logged.
Data and privacy
Kept as long as you need it, and no longer.
Banks, hospitals and public bodies answer to auditors and regulators. In Agoo you decide how long each kind of data is kept, deletion happens on schedule with a record of every run, a legal hold stops it when you need to, and you can take everything with you at any time.

A period for each kind of data
Set in Console → Settings → Data & privacy, also for bookings, deliveries and attendance. Before a shorter period is saved, Agoo counts what it would delete and asks you to confirm.
| Kind of data | How it’s counted |
|---|---|
| Visits | From when the visit ended. A visitor goes with their last visit. |
| Visitor photos | From when the photo was taken. Often a short period. |
| ID images | From when the image was taken. 24 hours unless you choose otherwise. |
| ID numbers | From the visitor’s last visit. Stored masked and encrypted. |
| Answers to your questions | From when the visit ended, and each question can have its own, shorter period. |
| Messages sent | The address and text go; the record that a message was sent, and its cost, stays. |
| QR code scans | From the scan. 2 years unless you choose otherwise, and never an IP address. |
| Audit trail | Oldest entries first, so the chain still verifies. |
How far back each plan goes
How much visitor history each plan shows, and how long it keeps the audit trail. A move to a lower plan never deletes anything: older records are hidden, and come back when you move up.
| Plan | Visitor history | Audit trail |
|---|---|---|
| Free | 3 months shown | 7 days |
| Starter | 12 months | 90 days |
| Growth | 24 months | 1 year |
| Pro | Up to 5 years | 3 years |
| Enterprise | Custom, legal hold | Up to 7 years |
Scheduled deletion
Runs every hour on its own. Each run is recorded in the audit trail with how many records of each kind went, and listed in Data & privacy, so you can show auditors your rules work. Deleted data can’t be recovered, and backup copies expire within 30 more days.
Legal holds, on Enterprise
During an investigation, a dispute or a regulator’s request, place a hold on the whole organisation, a site, a person or a visitor. Scheduled deletion and erasure stop for what it covers until you lift it, and both are in the audit trail.
The full organisation export
Owners and Admins can take everything Agoo keeps for the organisation, on every plan: a ZIP with a CSV file for each kind of record and the files still kept. You’re emailed when it’s ready and download it in the Console within 7 days. Passwords, keys and full ID numbers never leave Agoo.
People and access
The right access for every person, and nothing more.
Everyone who signs in has a role, and sees only what that role and their sites allow. Each person looks after their own profile and chooses how alerts reach them.
Roles and sites
Owner, Admin, Site admin, Receptionist, Security lead, Guard, Host, Employee and Auditor, each seeing only what the role allows. On Growth and above, limit any role to its own sites.
Invitations by email
A sign-in link is a credential, so invitations go by email only, and links expire. Invite later, import people from a CSV file on Growth and above, or add people who receive visitors without signing in.
Two-step verification
Required for Owners and Admins, and open to everyone with an authenticator app. Changing a sign-in email is confirmed at both addresses.
Profiles with photos
People add a photo, the name they go by and their pronouns, within what you let them change. Photos are re-made without location or camera details.
Alerts their way
Each person chooses WhatsApp, SMS or email for each alert, and quiet hours. Security holds and roll call’s “Are you safe?” always come through.
Groups share only what you allow
An organisation joins a group only when its Owner accepts, and chooses what the group gets: totals only, read-only or admin. Group admins need two-step verification, everything they do is marked in your audit trail, and leaving ends their access at once.
Changes apply at once
Change a role or remove someone’s sign-in and it applies on their next click. Agoo emails them, and the change is in the audit trail.
Data protection
Built for Ghana’s Data Protection Act.
Under the Data Protection Act, 2012 (Act 843), your organisation controls the data and Agoo processes it for you. We sign a data processing agreement with every customer, help you answer access and deletion requests, and show visitors a privacy notice before they check in.
Sub-processors
The services that process data on our behalf, as of 5 October 2026. Some apply only when a feature is turned on or launched; the full sub-processor list says when, and what data each receives.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database hosting and backups | United Kingdom |
| Vercel | Hosting for the website and web apps | United Kingdom, with a global delivery network |
| Cloudflare | Network security, file storage and delivery | Global network; files stored in Western Europe |
| Fly.io | Application hosting | United Kingdom |
| PowerSync | Offline working for Agoo’s apps | European Union |
| Twilio SendGrid | Email delivery | United States |
| Hubtel | SMS delivery | Ghana |
| Meta | WhatsApp messages | Global (Meta’s data centres) |
| Apple, Google | Push notifications | Global |
| Paystack | Payments | Ghana, Nigeria |
| Anthropic | AI features, when enabled | United States |
Report a vulnerability
Found a weakness? Tell us first.
We welcome reports from security researchers and customers. Research in good faith that follows the rules here is welcome, and we won’t take legal action against it.
Email agoo@ardentafrica.com with “Security” in the subject. We acknowledge every report within 3 working days and keep you updated while we investigate and fix it. Our security.txt has the same details.
What to include
- What is affected: the page, app, API endpoint or package, and its version
- Steps to reproduce, and what an attacker could do
- How we can reach you, and whether you would like credit
Please don’t
- Access, change or delete other customers’ data: test only your own organisation, ideally in test mode
- Run denial-of-service, load or spam tests
- Share the issue publicly before we have had a reasonable time to fix it

Agoo!
Your visitors say Agoo. Let your front door say Amee.
Join the organisations getting early access. We will set up your site, bring your staff list across and train your front desk.