Sign up to receive our monthly newsletter.
Have a question? Contact us here.
Learn about job openings.
Go.Data is an open-source platform for outbreak response and contact tracing developed by WHO in collaboration with GOARN partners. It streamlines all aspects of outbreak response and is highly versatile with customizable configurations for different scenarios.

Owner
World Health Organization (WHO)
Type
backend, mobile, web
Licence
GPL-3.0
Last evaluated
30.09.2024
Origin country
Switzerland
contact
godata@who.intRelease date
01.04.2024
DPG since
30.09.2024
The following repositories were submitted by the solution and included in our evaluation. Any repositories, add-ons, features not included in here were not reviewed by us.
N/A
N/A
English
World Health Organization (WHO), World Bank, Given that Go.Data installers are available in the public domain and that countries, territories, and institutions have complete control over the applicati…
* This information is self-reported and updated annually




SDG 3 - Good Health and Well-being: SDG Target 3.3 | End the epidemics of AIDS, tuberculosis, malaria and neglected tropical diseases and combat hepatitis, water-borne diseases and other communicable diseases. Relevance: Go.Data addresses this target by providing real-time data and analytics to quickly identify, monitor, and control outbreaks of infectious diseases. This helps reduce their spread and impact. SDG Target 3.8 | Achieve universal health coverage, including financial risk protection, access to quality essential healthcare services and access to safe, effective, quality and affordable essential medicines and vaccines for all Relevance: The Go.Data tool can enhance health systems' ability to respond effectively to disease outbreaks, ensuring that healthcare services are not overwhelmed and that infected people can access essential healthcare services during outbreaks. SDG 6 - Clean Water and Sanitation: Target 6.1 | By 2030, achieve universal and equitable access to safe and affordable drinking water for all. Relevance: Go.Data can be used to control water-borne diseases, ensuring safe drinking water supplies. Early detection and response to water contamination-related outbreaks help maintain safe access to drinking water. SDG 8 - Decent Work and Economic Growth Target 8.8 | Protect labor rights and promote safe and secure working environments for all workers, including migrant workers, in particular women migrants, and those in precarious employment. Relevance: By effectively controlling outbreaks, Go.Data supports maintaining healthy working environments and preventing economic disruptions caused by widespread illness, thus contributing to economic stability and the protection of workers' health. SDG 11 - Sustainable Cities and Communities Target 11.5 | By 2030, significantly reduce the number of deaths and the number of people affected and substantially decrease the direct economic losses relative to the global gross domestic product caused by disasters, including water-related disasters, with a focus on protecting the poor and people in vulnerable situations. Relevance: Go.Data contributes to minimizing the impact of health emergencies on communities, particularly vulnerable populations. Rapid and effective outbreak response helps reduce health-related deaths, and economic losses and protects the most vulnerable. In conclusion, Go.Data is a powerful tool that contributes to multiple SDGs. Its capacity to improve the prompt detection, monitoring, and management of disease outbreaks contributes to building resilient health systems, promoting community safety, and enhancing overall well-being. By directly addressing health emergencies, this tool also contributes to broader objectives of sustainable development, such as ensuring economic stability, facilitating access to clean water, providing safe working environments, and strengthening data infrastructure.
Python, Javascript, MongoDB, Node Js, Angular
Go.Data works with MongoDB because of its extensive features and flexibility. However, it is possible to use a fully Open-source alternative such as FerretDB. Detailed instructions for migrating from MongoDB to FerretDB can be found at: https://github.com/WorldHealthOrganization/GoDataSource-Installers/blob/main/docs/configuring-ferret-db.md
Yes
Data Encryption, Principles for Digital Development, ICT4D, Use of a Design System, Security Best Practices, Authentication and Authorization
PII data is collected and stored but NOT distributed.
Go.Data has undergone multiple security audits with the assistance of WHO cybersecurity and a member state. These audits involved a combination of automated and manual tests, including ethical hacking. The following is a list of details related to the security of Go.Data: • Sensitive data like passwords are hashed. • Captcha can be optionally enabled on password-related screens. (Captcha feature is included in the Go.Data application and can be optionally activated to challenge the user at login, password reset email request, and the resetting of the password) • Two-factor authentication can be enabled on password-related screens. This proceeds via the dispatch of an email so a working SMTP server must be configured with Go.Data. • Brute force handling: This is used to disable reset passwords with question & answers for a time for a specific user after a defined number of incorrect password attempts. Account lockouts can last a specific duration as defined in the config.json file fragment below. • "bruteForce": { "resetPassword": { "enabled": false, "maxRetries": 10, "resetTime": 30, "resetTimeUnit": "minutes" • Authentication tokens: This property in the config.json file dictates the behavior regarding authentication tokens and whether these are invalidated by a restart of the Go.Data service. When set to false, a Go.Data server restart does not log out any active sessions and their tokens remain valid. When set to true, a restart of the Go.Data server destroys tokens so that users will need to log back in. "signoutUsersOnRestart": false, • All backups can be encrypted by specifying the encryption key in config.json file: "backUp": { "password": "key" (Without this encryption key backup restore will fail for backups encrypted with this key, therefore do not misplace it.) } • Communication between mobile apps and API can be encrypted as well: Users have the option to exchange encrypted information between the app and the API. This option is present on the hub configuration screen as the “Encrypted connection” switch. By default, the encrypted connection is turned on. This option can later be turned off from the hub configuration screen. Go.Data is considered sufficiently hardened for common cybersecurity attacks provided that the configurable features such as CORS, multi-factor authentication, and token timeouts are set correctly. The environment in which Go.Data is deployed must also be validated to ensure that there are no vulnerabilities.
Content is NOT collected NOT stored and NOT distributed.
Yes
Go.Data adheres to the WHO policies and codes of conduct for Preventing and Responding to Sexual Exploitation, Abuse, and Harassment (https://www.who.int/initiatives/preventing-and-responding-to-sexual-exploitation-abuse-and-harassment). These policies and codes are also reflected in the application's code of conduct for members, contributors, and leaders within the Go.Data community (https://github.com/WorldHealthOrganization/godata/blob/master/CODE_OF_CONDUCT.md).
2025-09-30 17:30:51
Go.Data project team (Applicant) submitted application for Go.Data (12915)
2025-08-01 01:30:02
System created an autofill refresher application for Go.Data (12915)
2025-08-01 01:30:02
System created a refresher application for Go.Data (11613)
2024-10-03 17:28:43
Admin (Admin) edited 7. Privacy & Applicable Laws for Go.Data (11613)
2024-10-01 18:20:30
Admin (Admin) edited 7. Privacy & Applicable Laws for Go.Data (11613)
2024-09-30 12:46:22
Admin (Admin) edited 8. Open Standards & Best Practices for Go.Data (11613)
2024-09-30 12:45:23
Admin (Admin) edited 8. Open Standards & Best Practices for Go.Data (11613)
2024-09-30 12:42:55
Admin (Admin) edited 7. Privacy & Applicable Laws for Go.Data (11613)
2024-09-30 12:42:04
Admin (Admin) edited 7. Privacy & Applicable Laws for Go.Data (11613)
2024-09-30 12:40:13
Admin (Admin) edited 7. Privacy & Applicable Laws for Go.Data (11613)
2024-09-30 02:22:39
Ricardo Torres (L2 Reviewer) submitted their review of Go.Data (152) and found it to be a DPG
2024-09-30 02:22:36
System unmarked Go.Data (11613) as a nominee
2024-09-30 02:22:32
Ricardo Torres (L2 Reviewer) passed 4. Platform Independence for Go.Data (11613)
2024-09-30 02:18:54
Ricardo Torres (L2 Reviewer) pulled Go.Data (11613) under review
2024-09-18 13:00:21
Bolaji Ayodeji (L1 Reviewer) submitted their review of Go.Data (11613)
2024-09-18 12:58:52
Bolaji Ayodeji (L1 Reviewer) passed 4. Platform Independence for Go.Data (11613)
2024-09-18 11:57:48
Bolaji Ayodeji (L1 Reviewer) pulled Go.Data (11613) under review
2024-09-16 08:30:56
New tag (Clarifications) added to application
2024-09-16 08:30:56
Application clarifications submitted, Application move to L1 for review again
2024-08-19 12:57:59
Ricardo Torres (L2 Reviewer) requested clarifications for Go.Data (11613)
2024-08-19 12:57:58
System marked Go.Data (11613) as a nominee
2024-08-19 12:57:46
Ricardo Torres (L2 Reviewer) require clarification on 4. Platform Independence for Go.Data (11613)
2024-08-19 12:56:54
Ricardo Torres (L2 Reviewer) moved Go.Data (11613) to under review
2024-08-19 12:56:51
Ricardo Torres (L2 Reviewer) finished consultation on 4. Platform Independence for Go.Data (11613)
2024-08-14 07:22:23
Ivan Perdomo (Expert) submitted their inputs on 4. Platform Independence for Go.Data (11613) as “input”
2024-08-11 23:37:05
Ricardo Torres (L2 Reviewer) requested consultation on 4. Platform Independence for Go.Data (11613)
2024-08-11 23:36:53
Ricardo Torres (L2 Reviewer) moved Go.Data (11613) to under consultation
2024-08-11 23:36:49
Ricardo Torres (L2 Reviewer) passed Scale of Solution for Go.Data (11613)
2024-08-11 23:36:46
Ricardo Torres (L2 Reviewer) passed 9C. Protection from Harassment for Go.Data (11613)
2024-08-11 23:36:38
Ricardo Torres (L2 Reviewer) passed 9B. Inappropriate & Illegal Content for Go.Data (11613)
2024-08-11 23:36:31
Ricardo Torres (L2 Reviewer) passed 9A. Data Privacy & Security for Go.Data (11613)
2024-08-11 23:36:26
Ricardo Torres (L2 Reviewer) passed 8. Open Standards & Best Practices for Go.Data (11613)
2024-08-11 23:36:22
Ricardo Torres (L2 Reviewer) passed 7. Privacy & Applicable Laws for Go.Data (11613)
2024-08-11 23:35:57
Ricardo Torres (L2 Reviewer) edited 6. Non-PII Data Extraction for Go.Data (11613)
2024-08-11 23:34:42
Ricardo Torres (L2 Reviewer) passed 6. Non-PII Data Extraction for Go.Data (11613)
2024-08-11 23:34:19
Ricardo Torres (L2 Reviewer) passed 5. Documentation for Go.Data (11613)
2024-08-11 23:33:55
Ricardo Torres (L2 Reviewer) edited 5. Documentation for Go.Data (11613)
2024-08-11 23:33:41
Ricardo Torres (L2 Reviewer) edited 5. Documentation for Go.Data (11613)
2024-08-11 23:33:01
Ricardo Torres (L2 Reviewer) passed 3. Clear Ownership for Go.Data (11613)
2024-08-11 23:33:00
Ricardo Torres (L2 Reviewer) edited 3. Clear Ownership for Go.Data (11613)
2024-08-11 23:32:45
Ricardo Torres (L2 Reviewer) passed 2. Open Licensing for Go.Data (11613)
2024-08-11 23:32:43
Ricardo Torres (L2 Reviewer) edited 2. Open Licensing for Go.Data (11613)
2024-08-11 23:31:44
Ricardo Torres (L2 Reviewer) passed 1. SDG Relevance for Go.Data (11613)
2024-08-11 23:31:42
Ricardo Torres (L2 Reviewer) edited 1. SDG Relevance for Go.Data (11613)
2024-08-11 23:28:53
Ricardo Torres (L2 Reviewer) passed General Information for Go.Data (11613)
2024-08-11 23:28:35
Ricardo Torres (L2 Reviewer) pulled Go.Data (11613) under review
2024-07-21 16:03:44
L1 Reviewer (L1 Reviewer) submitted their review of Go.Data (11613)
2024-07-21 16:03:21
L1 Reviewer (L1 Reviewer) passed Scale of Solution for Go.Data (11613)
2024-07-21 16:03:15
L1 Reviewer (L1 Reviewer) passed 9C. Protection from Harassment for Go.Data (11613)
2024-07-21 16:03:01
L1 Reviewer (L1 Reviewer) passed 9B. Inappropriate & Illegal Content for Go.Data (11613)
2024-07-21 16:01:27
L1 Reviewer (L1 Reviewer) passed 9A. Data Privacy & Security for Go.Data (11613)
2024-07-21 15:59:26
L1 Reviewer (L1 Reviewer) passed 8. Open Standards & Best Practices for Go.Data (11613)
2024-07-21 15:59:15
L1 Reviewer (L1 Reviewer) passed 7. Privacy & Applicable Laws for Go.Data (11613)
2024-07-21 15:58:58
L1 Reviewer (L1 Reviewer) passed 6. Non-PII Data Extraction for Go.Data (11613)
2024-07-21 15:58:36
L1 Reviewer (L1 Reviewer) passed 5. Documentation for Go.Data (11613)
2024-07-21 15:58:31
L1 Reviewer (L1 Reviewer) failed 4. Platform Independence for Go.Data (11613)
2024-07-21 15:47:04
L1 Reviewer (L1 Reviewer) passed 4. Platform Independence for Go.Data (11613)
2024-07-21 15:35:27
L1 Reviewer (L1 Reviewer) passed 3. Clear Ownership for Go.Data (11613)
2024-07-21 15:35:12
L1 Reviewer (L1 Reviewer) failed 2. Open Licensing for Go.Data (11613)
2024-07-21 15:27:33
L1 Reviewer (L1 Reviewer) passed 1. SDG Relevance for Go.Data (11613)
2024-07-21 15:27:24
L1 Reviewer (L1 Reviewer) edited a note on 1. SDG Relevance for Go.Data (11613)
2024-07-21 15:21:46
L1 Reviewer (L1 Reviewer) passed General Information for Go.Data (11613)
2024-07-21 13:15:02
L1 Reviewer (L1 Reviewer) pulled Go.Data (11613) under review
2024-07-15 08:31:12
Go.Data project team (Applicant) submitted application for Go.Data (11613)
