Skip to content

Security

Your visitors trust you with their details. We take that seriously.

Agoo holds names, phone numbers, photos and sometimes ID numbers. Every part of the platform is built to keep them private, correct and available, and to prove it to your auditors.

A man with a lanyard using a tablet between server racks

Controls

Protection at every layer.

  • Encryption

    TLS for everything in transit. Databases, backups and files encrypted at rest with AES-256.

  • Tenant isolation

    Every record belongs to one organisation, and isolation is enforced at the data layer, not only in the app.

  • Roles by site

    Front desk, hosts, security and admins each see only what their role and site allow.

  • Sign-in

    Single sign-on with Google, Microsoft or SAML, SCIM provisioning, and two-step verification, required for Owners and Admins and open to everyone.

  • Audit trail

    Append-only, hash-chained records of every action, checked with Verify chain, kept for up to seven years.

  • Support access you control

    Agoo staff never use your password. When we help, we see your organisation read-only, for a set time, and every Owner is told at once and can end it. Changes need an Owner’s approval. Emergency access, for what can’t wait, tells every Owner and Admin and is followed by a written report within 72 hours.

  • Account recovery that can’t be talked into

    Lost a phone? A reset needs your inbox and a colleague who has checked it’s really you, or our own identity check and a 24-hour wait. A new Owner, when yours has gone, needs evidence and 72 hours’ notice that your Owner and Admins can stop.

  • Retention

    Set how long to keep each kind of data. Deletion runs every hour and is logged.

  • Hosting

    Application and database hosted in London, UK, with daily backups and edge delivery through Cloudflare.

  • Live status

    status.agoo.ardent.africa checks every part of Agoo every minute from outside, and runs separately so it stays up even if Agoo doesn’t. It shows what’s happening now, planned maintenance and 90 days of history, and emails you updates if you subscribe.

  • Payments

    Paid through Paystack’s own checkout. Card and mobile money details are handled by Paystack and never stored by Agoo; a saved card renews with Paystack’s token, kept encrypted and deleted when the card is removed. Every payment is checked with Paystack before anything changes, and test payments can never count as real ones.

Audit trail

Every action, recorded. Nothing rewritten.

Who approved which visitor, who exported what, who changed a setting: time, person and IP address, in an append-only log. Each entry carries the hash of the one before, so any change to history shows.

  • Verify chain recalculates every link and checks each hourly checkpoint, kept separately from the trail
  • Search by who, what, site and date, and export to CSV or Excel for your auditors
  • Every export from Agoo is itself recorded: who, what, in which format and how many rows
  • Nobody can edit or delete an entry, including Owners and Ardent staff
  • Agoo support’s access is in it too: when it opened, what it looked at, and anything it changed

Screening

The right people in, quietly.

Watchlist checks run at check-in on names, phone numbers and ID numbers. A match holds the check-in and alerts security without a scene at the desk. Overrides need a reason, and every one is logged.

Data and privacy

Kept as long as you need it, and no longer.

Banks, hospitals and public bodies answer to auditors and regulators. In Agoo you decide how long each kind of data is kept, deletion happens on schedule with a record of every run, a legal hold stops it when you need to, and you can take everything with you at any time.

An engineer holding a tablet in a bright data centre

A period for each kind of data

Set in Console → Settings → Data & privacy, also for bookings, deliveries and attendance. Before a shorter period is saved, Agoo counts what it would delete and asks you to confirm.

Kind of dataHow it’s counted
VisitsFrom when the visit ended. A visitor goes with their last visit.
Visitor photosFrom when the photo was taken. Often a short period.
ID imagesFrom when the image was taken. 24 hours unless you choose otherwise.
ID numbersFrom the visitor’s last visit. Stored masked and encrypted.
Answers to your questionsFrom when the visit ended, and each question can have its own, shorter period.
Messages sentThe address and text go; the record that a message was sent, and its cost, stays.
QR code scansFrom the scan. 2 years unless you choose otherwise, and never an IP address.
Audit trailOldest entries first, so the chain still verifies.

How far back each plan goes

How much visitor history each plan shows, and how long it keeps the audit trail. A move to a lower plan never deletes anything: older records are hidden, and come back when you move up.

PlanVisitor historyAudit trail
Free3 months shown7 days
Starter12 months90 days
Growth24 months1 year
ProUp to 5 years3 years
EnterpriseCustom, legal holdUp to 7 years
  • Scheduled deletion

    Runs every hour on its own. Each run is recorded in the audit trail with how many records of each kind went, and listed in Data & privacy, so you can show auditors your rules work. Deleted data can’t be recovered, and backup copies expire within 30 more days.

  • Legal holds, on Enterprise

    During an investigation, a dispute or a regulator’s request, place a hold on the whole organisation, a site, a person or a visitor. Scheduled deletion and erasure stop for what it covers until you lift it, and both are in the audit trail.

  • The full organisation export

    Owners and Admins can take everything Agoo keeps for the organisation, on every plan: a ZIP with a CSV file for each kind of record and the files still kept. You’re emailed when it’s ready and download it in the Console within 7 days. Passwords, keys and full ID numbers never leave Agoo.

People and access

The right access for every person, and nothing more.

Everyone who signs in has a role, and sees only what that role and their sites allow. Each person looks after their own profile and chooses how alerts reach them.

  • Roles and sites

    Owner, Admin, Site admin, Receptionist, Security lead, Guard, Host, Employee and Auditor, each seeing only what the role allows. On Growth and above, limit any role to its own sites.

  • Invitations by email

    A sign-in link is a credential, so invitations go by email only, and links expire. Invite later, import people from a CSV file on Growth and above, or add people who receive visitors without signing in.

  • Two-step verification

    Required for Owners and Admins, and open to everyone with an authenticator app. Changing a sign-in email is confirmed at both addresses.

  • Profiles with photos

    People add a photo, the name they go by and their pronouns, within what you let them change. Photos are re-made without location or camera details.

  • Alerts their way

    Each person chooses WhatsApp, SMS or email for each alert, and quiet hours. Security holds and roll call’s “Are you safe?” always come through.

  • Groups share only what you allow

    An organisation joins a group only when its Owner accepts, and chooses what the group gets: totals only, read-only or admin. Group admins need two-step verification, everything they do is marked in your audit trail, and leaving ends their access at once.

  • Changes apply at once

    Change a role or remove someone’s sign-in and it applies on their next click. Agoo emails them, and the change is in the audit trail.

Data protection

Built for Ghana’s Data Protection Act.

Under the Data Protection Act, 2012 (Act 843), your organisation controls the data and Agoo processes it for you. We sign a data processing agreement with every customer, help you answer access and deletion requests, and show visitors a privacy notice before they check in.

Mate Masie, what I hear, I keep: your details stay with us.

Sub-processors

The services that process data on our behalf, as of 5 October 2026. Some apply only when a feature is turned on or launched; the full sub-processor list says when, and what data each receives.

ProviderPurpose
SupabaseDatabase hosting and backups
VercelHosting for the website and web apps
CloudflareNetwork security, file storage and delivery
Fly.ioApplication hosting
PowerSyncOffline working for Agoo’s apps
Twilio SendGridEmail delivery
HubtelSMS delivery
MetaWhatsApp messages
Apple, GooglePush notifications
PaystackPayments
AnthropicAI features, when enabled

Report a vulnerability

Found a weakness? Tell us first.

We welcome reports from security researchers and customers. Research in good faith that follows the rules here is welcome, and we won’t take legal action against it.

Email agoo@ardentafrica.com with “Security” in the subject. We acknowledge every report within 3 working days and keep you updated while we investigate and fix it. Our security.txt has the same details.

What to include

  • What is affected: the page, app, API endpoint or package, and its version
  • Steps to reproduce, and what an attacker could do
  • How we can reach you, and whether you would like credit

Please don’t

  • Access, change or delete other customers’ data: test only your own organisation, ideally in test mode
  • Run denial-of-service, load or spam tests
  • Share the issue publicly before we have had a reasonable time to fix it
Two colleagues talking by a water dispenser in a warmly lit office after hours

Agoo!

Your visitors say Agoo. Let your front door say Amee.

Join the organisations getting early access. We will set up your site, bring your staff list across and train your front desk.