ADMFm, Affordable Diagnostic and Medicines Facility for Malaria. Test, treat, track.

Command layer

Governance

Everything on this screen is read from the governance reference in the programme documents. Where a control is specified in those documents but cannot be exercised in a demonstration on synthetic data, the screen says the control is specified and not demonstrated here rather than implying it has been tested.

The programme owns the data, Sproxil processes it

This is the whole distinction, so it sits at the top of the screen rather than in a schedule.

Data owners

  • National Malaria Elimination Programme
  • Presidential Vaccine and Health Product Advisory Committee

The owners set the purpose the data may be used for, approve every indicator definition, and hold the record. Nothing in this portal is Sproxil's to publish, retain or reuse on its own authority.

Data processor

Sproxil

Sproxil captures, serialises, verifies and reconciles events on the owners' instruction. Processing role only, for the purposes the owners set.

Legal basis

Nigeria Data Protection Act 2023

The Act frames the owner and processor split above, and the client data boundary below.

What is held, and what is deliberately not held

The second list is the more important one. It is what the architecture refuses to record, at every level of the portal, including in exports.

Client data held

Pass: 3 fields
  • Synthetic client identifier
  • Age band
  • Sex

The synthetic client identifier links an encounter to its day 3 and day 10 follow-up and to nothing outside the ledger. It does not resolve to a person.

Client data not held

Fail: 4 excluded
  • Name
  • Address
  • Phone number
  • Any direct identifier

Survey delivery needs a mobile number; the analytical record does not receive it. Verification PINs are displayed masked wherever they appear.

Regulators with standing over the programme

Each regulates a different part of the chain: product, dispensing practice, and laboratory testing.

  • NAFDAC
  • Pharmacy Council of Nigeria
  • Medical Laboratory Science Council of Nigeria

Auditors

Both audit routes need the same thing from the system: a subsidy figure that decomposes to individual verified events.

  • Auditor-General of the Federation
  • World Bank donor audit teams

What follows a substantiated breach

The routes named in the programme documents, in the documents' own terms. The portal detects and evidences; it does not sanction.

  • Contract termination
  • Recovery of public funds
  • Blacklisting
  • EFCC or ICPC referral
  • NAFDAC licence suspension

What the system contributes to any of these is evidence: the custody chain for a pack, the price paid at the point of dispense, the verification event a payment rests on, and the audit trail of who recorded what and when. The decision to act sits with the owners, regulators and auditors above.

Access control and encryption, at the level the source documents support

Stated no further than the documents go. No key lengths, certifications, retention periods, ISO numbers or named access roles are asserted here, because the governance reference does not carry them.

Role based access

Specified, not demonstrated here

Access to the record is granted by role, on the owners' authority, and the processor holds no wider access than the processing purpose requires. The specific roles, their permissions and the approval route are set in the governance documents and are not reproduced here, because inventing a role list would misrepresent them.

This demonstration has no sign in, so no access control is exercised on these screens. Everything visible here is synthetic.

Encryption

Specified, not demonstrated here

The programme requires client and transaction data to be encrypted in transit and at rest under the Nigeria Data Protection Act 2023. The demonstration runs on a static synthetic dataset shipped with the portal, so there is no live store or transport to encrypt and no control to evidence on this screen.

What the demonstration can show is the data minimisation the control protects: the two lists above, and masked verification PINs throughout.

Governance is auditable because the record is one ledger

An owner, a regulator or an auditor asking a question of this programme is asking it of events.

Every figure in the portal resolves to the events beneath it, and every event carries the actor, timestamp and location that recorded it. That is what makes the ownership split above enforceable rather than declaratory: the owners can audit the processor's output down to one ₦300 test, without the record ever holding a client's name.