Skip to content

Security

Controls, security and audit

What your auditors and the regulator expect, enforced in the software rather than by policy.

Roles and permissions

A permission matrix per role covering view, create, edit, delete, approvals, settings and reports, managed on screen by your administrator.

Maker-checker

Loans, journals, expenses, transfer batches, field batches, account openings and large deposits all require approval by an officer other than the one who raised them, on the web and in the API.

Audit log

Every login and every posting is recorded against the named staff member. Backdated postings are logged as a distinct event.

Reversals, never deletions

Corrections are new balanced entries that reference the original and appear in a reversal history.

Closed periods

Once a period is closed, no user and no setting can post into it.

Posting-date rules

Postings can never be future-dated. Administrators may open a controlled window of past dates for catch-up posting; outside it, only today is allowed.

Posting integrity

Every customer posting has a general ledger counter-leg. Account rows are locked during posting and retried submissions are recognised, so nothing can double-post or overdraw.

Passwords and sessions

Forced change of the initial password within 7 days, expiry every 90 days, and instant revocation of app access when a staff member is deactivated.

Data isolation

Each institution has its own database. Staff of one institution cannot reach another's data, and your database can be exported or restored independently.

Encryption and backups

All traffic is encrypted. Provider keys are stored encrypted per institution. Backups run daily to a separate location with point-in-time restore on request.

Regulatory readiness

  • Know Your Customer. BVN and NIN verification with match scoring and a retained history per customer.
  • Credit checks. Credit bureau summary and score inside the loan workflow, kept on the loan file.
  • Monthly returns. The statements and ledgers supply the figures for returns to the CBN and NDIC. A return-file export pack is on the roadmap.
  • Audit. A read-only auditor role, the full audit log, reversal history and any ledger for any period.

Security FAQ

How are backups handled?

Automatically, daily, to a separate location. Restores are performed by us on request.

Is there maker-checker?

Yes. Loans, journals, expenses, transfer batches, field batches, account openings and large deposits all require approval by an officer other than the one who raised them, on the web and in the mobile app.

Can a teller post into last month?

Only if the administrator has opened a backdating window covering that date, and never into a closed period. Nothing can ever be future-dated.

Ask us the hard questions

Bring your auditor or IT lead to the demo. We will show the controls live, not on a slide.

Prefer WhatsApp? Chat with us