Data Security
The technical and organisational measures we implement to protect your personal data.
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction:
Technical Measures
- Encryption in transit: All data transmitted between your device and our servers is encrypted using HTTPS/TLS.
- Password security: Passwords are never stored in plain text. They are cryptographically hashed using industry-standard, one-way hashing algorithms.
- No storage of full card data: We never store the full card number (PAN) or CVV for your virtual cards. These remain solely with our PCI-DSS-compliant card issuer, Payscribe. We keep only a masked number (last 4 digits), which is all that is ever displayed to you. Card details you link through Paystack are similarly never stored in full.
- Signed document URLs: KYC documents are stored privately and accessible only through short-lived, signed URLs.
- JWT authentication: We use stateless, token-based authentication (JSON Web Tokens), which reduces the risk of session hijacking.
- Rate limiting: All API endpoints are rate-limited to prevent brute-force attacks and abuse.
- Regular monitoring: We conduct ongoing security monitoring to detect and respond to potential threats.
Organisational Measures
- Access to personal data is restricted to authorised personnel on a need-to-know basis.
- Third-party processors are contractually required to maintain equivalent security standards.
- We regularly review and update our security practices.
Encryption at Rest
Personal data stored in our databases is encrypted at rest using industry-standard encryption. Highly sensitive identifiers, including your BVN and other identity numbers, receive an additional layer of field-level (application-layer) encryption, so they are stored in encrypted form and are never held in plain text.
Breach Notification
In the event of a personal data breach, we will notify the Nigeria Data Protection Commission within 72 hours and notify affected users without undue delay where the breach is likely to result in a high risk to your rights and freedoms.
While we take extensive measures to protect your data, no method of electronic transmission or storage is 100% secure. If you become aware of any security breach or unauthorised use of your account, please contact us immediately at privacy@subsecute.com.