Security.
Last updated: 2 October 2026.
How we protect the information entrusted to our platforms.
Our approach
We handle information for healthcare, financial and business users. We treat protecting it as a legal duty as well as a business commitment. The Nigeria Data Protection Act 2023 requires appropriate technical and organisational measures to keep personal data secure.
Our approach is based on risk. We limit what we collect. We give people access only to what their role needs. We build security into our products, and we learn from incidents. No system is completely secure, and we cannot promise that any system is free from risk.
Data protection
We protect information in transit with encryption, and we restrict access to systems and data to the people who need it. This website is hosted with Hostinger. We require our service providers to protect personal data by contract, and we train our people to keep it confidential.
If a data breach is likely to harm people, we will notify the Nigeria Data Protection Commission within seventy two hours where the law requires. Where the risk to individuals is high, we will also tell them without undue delay.
Healthcare and financial data
Health and financial information is among the most sensitive we handle. Health information is sensitive personal data and is subject to duties of confidentiality.
Our products that handle this information are designed to limit access to those who need it and to follow the rules that apply to each product, working with licensed partner institutions where the law requires. Each product's privacy notice and terms give the detail.
Report a vulnerability
If you find a weakness in our website or platforms, please tell us before you share it with anyone else. Use our contact form and choose Security. Please describe the problem, where it is, and how to reproduce it, and give us a way to reach you.
To be covered by this policy, you must act in good faith and follow these rules.
- Do not access, change, copy or delete data that is not yours. If you reach personal data by accident, stop and tell us.
- Do not carry out denial of service attacks, phishing or social engineering, or attacks on our people, clients or partners.
- Do not use the weakness to keep access, to move to other systems, or for gain.
- Give us a reasonable time to fix the problem before you disclose it. We expect that to be no more than ninety days.
We will acknowledge your report within five working days and keep you informed until it is fixed. If you follow these rules, we will treat your testing as authorised and will not bring legal action against you for it. We cannot bind public authorities, which decide for themselves under laws such as the Cybercrimes Act. We do not currently pay rewards for reports.
Have a difficult system to build?
Tell us what needs to work better. We will help you understand the opportunity, define the product, and build the system.
Prefer to write? Use the forms on the Contact page.