/en/trust-transparency

Every credential, with the entity, the period and the scope it covers.

A person reads every message and replies.

Credentials

Every credential in this table is presented with five things: the entity or system it covers, the report period, the services in scope, and the geographic and personnel assumptions behind it. Documentation for Onshore Technology Services, Inc. is available under a non-disclosure agreement, within its stated scope. That is what your procurement reviewer can actually work with, and it is a higher bar than a logo.

CredentialEntity or system coveredReport periodServices in scopeGeographic & personnel assumptions
Parent documentation, under NDAOnshore Technology Services, Inc.As stated in the documentWithin its stated scopeU.S. facilities, U.S.-based personnel
Hosting platform certificationsThe platforms’ own, never oursPer the platform’s published reportInfrastructure layer onlyRegion selected per engagement

Answers, not gaps

QuestionThe answerWhen
Multi-factor authenticationAnswered per engagement, in writing, under NDAAt scoping, before access is granted
Business continuityAnswered per engagement, in writing, under NDAAt scoping, before access is granted
Service hoursStated per engagement. We do not publish a coverage level before the staffing that supports it existsAt scoping
Data processing agreementThe instrument depends on your regime. Tell us what yours requires and we will work to itAt scoping
Our own data-protection filingsWhere a market requires a declaration or authorization before processing, our position in that market is stated hereSequenced with the launch-data decision

Tiered by legal regime, not by geography

  • Where there is no localization requirement, the deployment region is chosen for performance and for your own preference. That is an engineering decision rather than a compliance one.
  • Where cross-border transfer is permitted with authorization, the transfer is lawful and the authorization is obtained — as a named task at scoping, with an owner and a date.
  • Where localization is required, we deploy locally, arranged as part of the engagement.
  • Where no data may leave your own infrastructure, the platform is deployed inside it — including the AI models, which run on your hardware rather than calling an external service.

A worked example. In Côte d’Ivoire the data-protection authority is ARTCI, and the deadline for entering a designated data-protection correspondent in the national registry was 31 January 2026, under the arrêté of 16 August 2024. Each WAEMU state runs its own regime and its own authority. The tiers above are how the decision gets made; yours is where it starts.

Whose cloud. The platform is deployed into your own cloud tenancy where you have one, so your data never leaves your control. Where you have none, it runs in ours, and we are then a processor — with every subprocessor disclosed and every applicable authorization obtained.

Who holds which control

The default split, so you can evaluate it before we meet rather than after. Every line can move for a given engagement; none of them moves silently.

ControlYoursOurs
Identity and accessYou own the directory and the joiner–mover–leaver process. Accounts are issued by you.We hold named, individual accounts under your policy. No shared credentials, ever.
Privileged accessYou approve every elevation and can revoke it without notice to us.We request elevation per task, with the reason recorded. We do not hold standing privilege.
Logging and audit trailLogs are generated in your tenancy and stay under your retention policy.Our activity is in your logs, attributable to a named person. We keep no separate record you cannot see.
Change controlYou approve what reaches production, against criteria agreed before the work.We do not deploy to production on our own authority.
SubcontractorsYou may refuse any subcontractor, and the refusal does not need a reason.Every subcontractor is declared before access, by name, with the scope they touch.
ExitYou keep the artefacts as they are produced — code, tests, criteria, the acceptance record.We return or destroy what we hold, at your instruction, and confirm which in writing.

This is a split of accountability, not a service level. It states who holds what, not how fast anyone answers — that is agreed per engagement and written into the contract.

Where the data actually sits

  • Default: your data does not leave your tenancy. We work inside it, against your identity provider, and what we produce is created there.
  • What crosses a boundary, when it does: the artefacts you asked for, sent the way you asked for them. Never a copy of a production dataset taken for convenience.
  • Where a workload cannot leave your infrastructure at all, the platform is deployed inside it — models included, running on your hardware.
  • Personal data reaching us is a decision you take deliberately at scoping, with the instrument your regime requires. It is not a by-product of how we work.

How pricing works

Scope first, then a fixed-scope proposal. No number is quoted before the scope exists, and no rate card is published.

Current operating model

Delivery runs today from established teams, primarily U.S.-based, and the African pathway is a plan with its status stated on this page.

Request our security response

Prepared for your engagement, under NDA.A person reads every message and replies.

Contact us

Two ways through. Both are answered by a person.

Emailinfo@onshoreafrica.comA written reply you can forward.WhatsApp+1 678 460 9510The fastest route. Write, or send a voice note.

HoursMonday to Friday, 10:00–18:00 GMT

A person reads every message and replies.

Read by Michael Kohio (Vice President, Solutions Delivery) and Shane Mayes (Founder, CEO & Chairman).

Track record
Onshore Outsourcing, founded 2005Over 20 years of enterprise delivery. Parent-company record.
Registrations
SAM · CAGE · UEIRegistrations your procurement team can verify on the public registers.