Encryption
TLS 1.2+ in transit. AES-256 at rest, including backups. PII columns separately encrypted at the application layer.
WA-B handles real cedis through real merchants every day. Here's exactly how we keep that money and your customers' data safe.
TLS 1.2+ in transit. AES-256 at rest, including backups. PII columns separately encrypted at the application layer.
Every payment callback from Hubtel and Paystack is HMAC-verified with constant-time comparison. No spoofed payments, ever.
API keys are stored as SHA-256 hashes. Even our database admins cannot read them in plaintext.
Every query is row-level-security scoped to the merchant's tenant ID. Zero cross-tenant data exposure by construction.
Webhook processor uses idempotency keys; duplicate events are detected and dropped. Replay windows enforced on signed payloads.
Owner / Manager / Cashier roles. Every action (login, payment, refund, settings change) is logged with actor, IP, and timestamp.
Credentials are kept in server-side environment configuration on access-controlled infrastructure — never committed to code or exposed to the browser. API keys are stored only as SHA-256 hashes.
2FA available for all merchant accounts. SSO (Google, Microsoft) on Market plan. WA-B staff use SSO + hardware keys.
Encrypted point-in-time backups every 5 minutes. Quarterly restore drills. 30-day retention.
We are early-stage and don't pretend otherwise. We've built our controls to map to industry frameworks and are actively pursuing formal certification.
We run a bug bounty for security researchers. Disclose responsibly and we will respond fast, fix faster, and pay fairly.
First response within 24h · No legal action against good-faith researchers