Security
Controls, security and audit
What your auditors and the regulator expect, enforced in the software rather than by policy.
Roles and permissions
A permission matrix per role covering view, create, edit, delete, approvals, settings and reports, managed on screen by your administrator.
Maker-checker
Loans, journals, expenses, transfer batches, field batches, account openings and large deposits all require approval by an officer other than the one who raised them, on the web and in the API.
Audit log
Every login and every posting is recorded against the named staff member. Backdated postings are logged as a distinct event.
Reversals, never deletions
Corrections are new balanced entries that reference the original and appear in a reversal history.
Closed periods
Once a period is closed, no user and no setting can post into it.
Posting-date rules
Postings can never be future-dated. Administrators may open a controlled window of past dates for catch-up posting; outside it, only today is allowed.
Posting integrity
Every customer posting has a general ledger counter-leg. Account rows are locked during posting and retried submissions are recognised, so nothing can double-post or overdraw.
Passwords and sessions
Forced change of the initial password within 7 days, expiry every 90 days, and instant revocation of app access when a staff member is deactivated.
Data isolation
Each institution has its own database. Staff of one institution cannot reach another's data, and your database can be exported or restored independently.
Encryption and backups
All traffic is encrypted. Provider keys are stored encrypted per institution. Backups run daily to a separate location with point-in-time restore on request.
Regulatory readiness
- Know Your Customer. BVN and NIN verification with match scoring and a retained history per customer.
- Credit checks. Credit bureau summary and score inside the loan workflow, kept on the loan file.
- Monthly returns. The statements and ledgers supply the figures for returns to the CBN and NDIC. A return-file export pack is on the roadmap.
- Audit. A read-only auditor role, the full audit log, reversal history and any ledger for any period.
Security FAQ
How are backups handled?
Automatically, daily, to a separate location. Restores are performed by us on request.
Is there maker-checker?
Yes. Loans, journals, expenses, transfer batches, field batches, account openings and large deposits all require approval by an officer other than the one who raised them, on the web and in the mobile app.
Can a teller post into last month?
Only if the administrator has opened a backdating window covering that date, and never into a closed period. Nothing can ever be future-dated.
Ask us the hard questions
Bring your auditor or IT lead to the demo. We will show the controls live, not on a slide.
Prefer WhatsApp? Chat with us