Security & Trust
What we actually do to protect your wallet, numbers and API — and what we don't claim.
How Your Data Is Protected
No badges, no buzzwords — just the measures you can verify in the product.
Encrypted in Transit
Every page and API call is served over HTTPS/TLS. We call it what it is — encrypted in transit — not end-to-end encryption.
Secure Authentication
Passwords are stored as bcrypt hashes (12 rounds). Sessions use signed JWTs in httpOnly, Secure, SameSite cookies with 10-minute email OTPs.
Hosting & Payments
Payments are handled off-site by Paystack and Flutterwave. We never store your full card or bank details — the gateway does.
Data Minimization
We collect only what the dashboard actually uses — email, wallet, orders, SMS content, API logs and security logs — and nothing else.
What we don't claim: We don't display SOC 2, ISO 27001, PCI DSS Level 1, GDPR/CCPA “certified” badges, regular pen-tests or 24/7 SOC — the codebase doesn't provide them. If you need formal attestations for a regulated use case, contact us first.
No False Badges
We removed unverified certifications. Here's the honest status.
SOC 2 / ISO 27001
No audit has been published. We don't display these badges.
PCI DSS / GDPR / CCPA
We don't badge as “certified”. Payments are off-site; privacy is under Nigeria NDPA 2023.
What we do
HTTPS/TLS in transit, bcrypt, JWT cookies, OTP expiry, rate limits, RBAC. See Privacy Policy §19.
Security Practices
The actual controls you can verify in the dashboard and API — not marketing promises.
A note on VPN
Our manual and dashboard suggest using a VPN that matches the virtual number's country to improve deliverability. That tip is kept — it helps avoid blocks when a platform checks IP vs number country. It does not authorize breaking a platform's terms. Always confirm that the service you're verifying allows virtual numbers and VPN use.