Security & Compliance
Operational data is sensitive data. We treat it that way.
Encryption
End-to-end encryption for all data in transit and at rest.
Authentication
Multi-factor authentication with role-based access control, so what a user can see and do matches their actual role.
Audit Logs
A complete, append-only audit trail of every action and decision — the log itself can't be edited or deleted, even by an administrator.
Data Isolation
Each organisation's data is isolated and encrypted separately — one customer's data is never visible to another's.
Secure APIs
OAuth 2.0 and managed API key issuance for every internal and external integration.
High Availability
Redundant infrastructure with automatic failover, so a single component going down doesn't take the platform with it.
Compliance
Nigeria Data Protection Act (NDPA)
As a platform operating on Nigerian data, NDPA alignment is the primary compliance framework we design against — not an afterthought borrowed from a US or EU checklist.
Broader Compliance Roadmap
GDPR, CCPA, and other international frameworks sit on our roadmap as the platform expands beyond Nigeria — we name this as a roadmap, not a certification we already hold.
Independent Review
Third-party security assessments and penetration testing are part of our ongoing security practice as the platform matures.
Have a security questionnaire to run through?
We're happy to walk your security or compliance team through the platform directly.