Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.




Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.

CSAI FoundationChaptersEventsBlog
AI is changing fast. Behavioral security helps you keep up. Join Darktrace’s September 22 broadcast to see how →

CSA STAR Registry

Security, Trust, Assurance, and Risk Registry

Listings for AWRA OpsHub

Listings for AWRA OpsHub

AWRA OpsHub is a cloud business operations platform. It runs inventory, procurement, assets, sales and point of sale, HR and payroll, projects, helpdesk and accounting in one connected system, with multi-currency and per-country tax support. Customers reach it through a browser application and an Android app that captures work online/offline and syncs when a connection returns.

The company is based in Nairobi, Kenya, and the service is operated by the team that builds it.

Service model. Software as a Service, delivered from a shared hosted application.

Security posture. Time-based one-time-password multi-factor authentication for the main application and the supplier portal, enforceable as an organisation-wide policy. AES-256 field-level encryption. TLS 1.2 and 1.3 only, HSTS with subdomains, and a content security policy.

Scope. A CSA STAR Level 1 self-assessment covering the AWRA OpsHub service. No independent third-party audit or attestation has been performed.

AWRA OpsHub

AWRA OpsHub is a cloud business operations platform. It runs inventory, procurement, assets, sales and point of sale, HR and payroll, projects, helpdesk a...

Listed Since: 2026-09-12

CAIQ
Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).