TRUST & SECURITY

Security & Data Protection

Our approach: We use multiple layers of technical and operational safeguards designed to protect group, member and transaction data against unauthorized access, alteration and misuse.

Access is based on role and responsibility

Users do not automatically receive unrestricted access to a group's information. Permissions are applied according to role and authorised actions, while sensitive workflows can require independent approval before completion.

Controls used across the platform

✓ Secure authentication and PIN handling
✓ Role-based access control and permission restrictions
✓ Server-side validation and protected API endpoints
✓ Secure sessions, expiry and phone verification
✓ OTP where required by a workflow
✓ Transaction references and payment reconciliation
✓ Approval workflows for sensitive actions
✓ Audit trails and activity logging
✓ Database access restrictions
✓ Encrypted HTTPS connections
✓ Backup procedures
✓ Monitoring for suspicious activity and unauthorized access attempts

Payments and financial records

Payment flows use references and recorded statuses so transactions can be reconciled. Where a process involves approval, refund, settlement, withdrawal or disbursement, the system keeps workflow references and audit history rather than relying on an untracked manual action.

Feature-phone participation

SMS participation uses the member's registered mobile number and validates group membership and action eligibility before accepting a command. SMS governance votes are written to the same voting records used by web and mobile users, preserving one source of truth.

Security is an ongoing process

No responsible online service should claim that a platform is impossible to compromise. Security depends on technology, configuration, monitoring, operational controls and responsible user behaviour. Vozua Chama uses layered controls designed to reduce risk and protect authorised access.

User responsibilities

Back to Vozua Chama