Encryption
TLS 1.2+ in transit. AES-256 at rest, including backups. PII columns separately encrypted at the application layer.
Collections settle through a Bank of Ghana licensed PSP. We never hold your float.
Customer records are stored in Accra and Frankfurt, encrypted at rest with AES-256.
Export or delete your customer list any time. We don't sell or share it. Ever.
Refunds, price edits and payouts are written to an audit log you can export.
TLS 1.2+ in transit. AES-256 at rest, including backups. PII columns separately encrypted at the application layer.
Every payment callback from Hubtel and Paystack is HMAC-verified with constant-time comparison. No spoofed payments, ever.
API keys are stored as SHA-256 hashes. Even our database admins cannot read them in plaintext.
Every query is row-level-security scoped to the merchant's tenant ID. Zero cross-tenant data exposure by construction.
Webhook processor uses idempotency keys; duplicate events are detected and dropped. Replay windows enforced on signed payloads.
Owner / Manager / Cashier roles. Every action (login, payment, refund, settings change) is logged with actor, IP, and timestamp.
Credentials are kept in server-side environment configuration on access-controlled infrastructure. Never committed to code or exposed to the browser. API keys are stored only as SHA-256 hashes.
2FA available for all merchant accounts. SSO (Google, Microsoft) on Market plan. WA-B staff use SSO + hardware keys.
Encrypted point-in-time backups every 5 minutes. Quarterly restore drills. 30-day retention.
We are early-stage and don't pretend otherwise. We've built our controls to map to industry frameworks and are actively pursuing formal certification.
We run a bug bounty for security researchers. Disclose responsibly and we will respond fast, fix faster, and pay fairly.