Security & Trust

What we actually do to protect your wallet, numbers and API — and what we don't claim.

How Your Data Is Protected

No badges, no buzzwords — just the measures you can verify in the product.

Encrypted in Transit

Every page and API call is served over HTTPS/TLS. We call it what it is — encrypted in transit — not end-to-end encryption.

Secure Authentication

Passwords are stored as bcrypt hashes (12 rounds). Sessions use signed JWTs in httpOnly, Secure, SameSite cookies with 10-minute email OTPs.

Hosting & Payments

Payments are handled off-site by Paystack and Flutterwave. We never store your full card or bank details — the gateway does.

Data Minimization

We collect only what the dashboard actually uses — email, wallet, orders, SMS content, API logs and security logs — and nothing else.

What we don't claim: We don't display SOC 2, ISO 27001, PCI DSS Level 1, GDPR/CCPA “certified” badges, regular pen-tests or 24/7 SOC — the codebase doesn't provide them. If you need formal attestations for a regulated use case, contact us first.

No False Badges

We removed unverified certifications. Here's the honest status.

Not claimed

SOC 2 / ISO 27001

No audit has been published. We don't display these badges.

Not claimed

PCI DSS / GDPR / CCPA

We don't badge as “certified”. Payments are off-site; privacy is under Nigeria NDPA 2023.

Implemented

What we do

HTTPS/TLS in transit, bcrypt, JWT cookies, OTP expiry, rate limits, RBAC. See Privacy Policy §19.

Security Practices

The actual controls you can verify in the dashboard and API — not marketing promises.

Data Protection
HTTPS/TLS for data in transit (not end-to-end encryption)
bcrypt hashing for passwords; no plain-text storage
Time-limited OTPs (10-minute expiry) enforced server-side
Input validation with Zod and sanitisation where needed
No full card/bank storage — handled by payment gateways

A note on VPN

Our manual and dashboard suggest using a VPN that matches the virtual number's country to improve deliverability. That tip is kept — it helps avoid blocks when a platform checks IP vs number country. It does not authorize breaking a platform's terms. Always confirm that the service you're verifying allows virtual numbers and VPN use.