Skip to main content

Proposal · Communications Authority of Kenya

Digital Trust and Inclusion Infrastructure for Kenya

Five proposed collaboration modules covering the regulatory sandbox, electronic certification services, licence verification, universal access programmes and community network operations.

This is a proposal, not a partnership

This page sets out collaboration modules that Bitdax Technologies Limited proposes for discussion with the Communications Authority of Kenya. It does not represent an endorsement, appointment, licence, accreditation or partnership.

No agreement exists between Bitdax and the Communications Authority. Every demonstration on this page uses synthetic records created solely to illustrate how a workflow would operate. No record shown here relates to any real licensee, and no credential shown carries legal effect.

E-CSP accreditation · Application in preparationSandbox admission · Application in preparation

Collaboration

Five proposed modules

Each module can be considered independently. Modules 1 and 3 are the fastest to demonstrate value and carry the least risk.

01

CA Regulatory Sandbox pilot

Test digital trust and verification services under supervision, with defined limits and a clear exit.

A time-boxed pilot with a capped number of participants, agreed consumer protection controls and reporting to the Authority throughout. The sandbox lets both parties observe how digital credential verification behaves in Kenyan conditions before any wider release.

Intended outcomes

  • Evidence on verification accuracy and failure modes
  • Consumer protection controls tested in the field
  • A documented basis for a full accreditation decision
02

E-CSP and digital trust infrastructure

Accredited certification services supporting signatures, timestamps and credential issuance.

Bitdax proposes to operate as an accredited Electronic Certification Service Provider, offering certificate issuance and lifecycle management, digital signing, trusted timestamps and verification. Private keys would be held in hardware security modules; certificate keys would never sit in application configuration.

Intended outcomes

  • Certificate request, issuance, renewal, suspension and revocation
  • HSM-backed key custody
  • Published certificate practice statement
03

Digital licence and credential verification

Anyone can confirm a licence is real, current and unrevoked, in one scan.

Licences issued or recognised by the Authority become digitally verifiable credentials carrying a QR code. A member of the public, a bank or a procuring entity scans it and receives a definitive status — instead of accepting a photocopied PDF. Every verification is logged, giving the Authority visibility of where its licences are being checked.

Intended outcomes

  • Reduced licence forgery and impersonation
  • Verification available to the public at no cost
  • Audit visibility of verification activity
04

Universal Service Fund digital access platform

Programme funds tracked from allocation to delivery, with evidence at every step.

A platform for administering universal access programmes: define eligibility, verify beneficiaries, allocate entitlements, record usage at the point of delivery, and produce settlement instructions supported by evidence. Financial settlement routes through an institution authorised by the Central Bank of Kenya.

Intended outcomes

  • Beneficiary verification before allocation
  • Usage evidence tied to each entitlement
  • Cost per beneficiary reporting from real records
05

Community network operating platform

Operational tooling so small and community operators can run compliantly and report accurately.

Subscriber management, vouchers, authentication, usage accounting and settlement for community networks and small ISPs. Standardised reporting reduces the compliance burden on small operators while improving the quality of data reaching the Authority.

Intended outcomes

  • Lower operating cost for small licensees
  • Consistent, comparable operator reporting
  • Clearer picture of underserved area coverage

Module 01 in detail

Regulatory sandbox submission outline

The information the Authority would expect in a sandbox application, prepared in advance.

The innovation

Publicly verifiable digital credentials for licences, certificates and signed documents, combining accredited PKI with a tamper-evident proof registry.

Consumer benefit

A person, employer, bank or procuring entity can confirm in seconds whether a document is genuine, without contacting the issuer and without paying a fee.

Why sandbox testing is needed

Verification behaviour under Kenyan network conditions, low-end device performance, and public comprehension of verification results all need to be observed with real users before wider release. A sandbox allows this under supervision with defined limits.

Test scenarios

  1. 1Academic credential issued by a participating institution and verified by an employer
  2. 2Professional practising certificate verified by a member of the public
  3. 3Regulatory licence verified by a procuring entity
  4. 4Signed document verified after alteration, to confirm tampering is detected
  5. 5Revoked credential verified, to confirm revocation propagates correctly

Target outcomes measured

  • Verification success rate and median response time
  • False positive and false negative rate on tamper detection
  • Proportion of users who correctly interpret the result shown
  • Volume and nature of concerns reported through the platform

Consumer protection controls

  • No fee charged to any verifier during the pilot
  • Only the minimum fields needed to confirm authenticity are displayed
  • A clear route to report a suspected fraudulent credential
  • Participants informed in writing that the pilot is a sandbox activity
  • Issuers may revoke any credential immediately

Risk controls

  • Capped participant numbers and capped credential volume
  • No financial value attached to any credential in the pilot
  • Personal documents are never written to a public ledger — hashes only
  • Data held in Kenya, consistent with the Data Protection Act 2019
  • Incident register with defined notification thresholds

Exit strategy

  • On success: apply for full accreditation with pilot evidence attached
  • On partial success: extend with a revised scope agreed with the Authority
  • On failure: notify participants, revoke pilot credentials, publish findings
  • In all cases: issuers retain their records and no participant is left without recourse

Module 03 demonstration

Licence verification, end to end

Step through how a licence becomes a verifiable digital credential, and what a member of the public sees when they scan it.

Demonstration environment. This demonstration shows synthetic records created for demonstration. No credential shown here is valid, and no regulated service is being performed.

Choose a demonstration licence

Demonstration record

Flow

Step 1 of 8

Licence record

A licence held by the Authority is imported, or issued directly through the platform.

Licence ID
DEMO-LIC-0001
Holder
Sample Community Network Limited
Licence type
Network Facilities Provider (Tier 3)
Issued
4 January 2026
Expires
3 January 2027

Every record in this demonstration is synthetic. No record relates to any real licensee, and no licence shown here has legal effect. This demonstration does not imply any endorsement, appointment or partnership.

Reference

Licence verification flow

  1. Licence record imported or issued

    A licence held by the Authority is imported, or issued directly through the platform.

  2. Organisation verified

    The licence holder's identity as an organisation is confirmed.

  3. Digital credential generated

    A signed credential is created and bound to the verified organisation.

  4. QR issued

    A QR code resolving to a public verification result is attached to the licence.

  5. Public verifier scans

    Any member of the public scans the code — no account, no fee.

  6. Status displayed

    Valid, expired, suspended, revoked, or verification unavailable.

  7. Verification logged

    The check is recorded, giving the Authority visibility of verification activity.

  8. Audit record generated

    An immutable audit event is written for the issuer's records.

Reference

E-CSP certificate lifecycle

  1. Requested

    A subscriber requests a certificate through an accredited process.

  2. Identity checked

    Identity, and organisation authority where applicable, are verified.

  3. Approved and issued

    The certificate is issued against an HSM-held key.

  4. Active

    The certificate is usable for signing and is publicly checkable.

  5. Renewed

    Renewal before expiry maintains continuity.

  6. Suspended or reinstated

    Temporary suspension is reversible where the cause is resolved.

  7. Revoked

    Permanent withdrawal, reflected immediately in verification.

  8. Expired

    Natural end of validity, with the record retained for audit.

We would welcome a technical briefing.

Bitdax is prepared to walk through the architecture, the key custody model, the data protection design and the sandbox controls with the Authority's technical and legal teams. Nothing on this page requires a commitment from the Authority.

Demonstration recordAll records on this page are synthetic. See our regulatory status.