Last Updated: May 22, 2026
Vayva Technologies Ltd Security Policy
Vayva Technologies Ltd (BN9089966), 19 Princess Bola Kazem, Shangisha, Lagos, Nigeria, is committed to protecting the confidentiality, integrity, and availability of all data processed through our B2B commerce platform. This Security Policy describes the technical and organizational measures we implement in compliance with the Nigeria Data Protection Act (NDPA) 2023, NDPR 2019, and industry best practices.
All personal and transactional data stored on Vayva servers is encrypted at rest using AES-256 (Advanced Encryption Standard with 256-bit keys), the strongest commercially available symmetric encryption algorithm. All data transmitted between your device and our servers is encrypted in transit using TLS 1.3 (Transport Layer Security), ensuring that data cannot be intercepted or read by unauthorized parties during transmission. Payment card data is encrypted end-to-end and processed through Paystack, a PCI-DSS Level 1 certified payment processor. We never store raw payment card details on our servers.
Vayva implements Role-Based Access Control (RBAC) to ensure that only authorized personnel can access specific data and systems. Access is granted on a least-privilege basis, meaning users receive only the minimum access necessary to perform their duties. All Vayva staff and merchant administrators are required to enable Multi-Factor Authentication (MFA) using time-based one-time passwords (TOTP) or hardware security keys. MFA adds a second layer of verification beyond passwords, significantly reducing the risk of unauthorized account access.
Our platform infrastructure is hosted on AWS data centers with physical security controls including 24/7 surveillance, biometric access, and environmental monitoring. Network security is provided by Cloudflare, offering DDoS protection, Web Application Firewall (WAF), bot management, and content delivery. All servers are hardened in accordance with CIS benchmarks and are subject to regular vulnerability scanning and penetration testing by independent third-party security firms at least annually.
Our software development lifecycle follows security-by-design principles. All code changes undergo peer review, automated security scanning (SAST/DAST), and dependency vulnerability checks before deployment. We maintain a bug bounty program and conduct regular third-party penetration tests. Security patches are applied within 24 hours for critical vulnerabilities and 7 days for high-severity issues.
Vayva maintains 24/7 security monitoring with automated threat detection and alerting. All system access and data operations are logged with tamper-evident audit trails retained for a minimum of two years. Our Incident Response Plan defines procedures for detecting, containing, eradicating, and recovering from security incidents. In the event of a data breach, we will notify affected merchants and the NDPC within 72 hours as required by the NDPR 2019.
All data is backed up continuously with encrypted backups stored in geographically separate locations. We conduct disaster recovery drills quarterly and maintain a Recovery Time Objective (RTO) of 4 hours and a Recovery Point Objective (RPO) of 1 hour.
All Vayva employees undergo background checks before employment. Security awareness training is mandatory upon hire and refreshed quarterly. All staff sign confidentiality and data protection agreements. Access to production systems is revoked immediately upon termination.
Merchants are responsible for: maintaining strong, unique passwords for their Vayva accounts; enabling MFA on all administrator accounts; keeping their devices and browsers updated; not sharing login credentials; and promptly reporting any suspected unauthorized access to privacy@vayva.ng. You acknowledge and agree that: (a) Vayva shall not be liable for security breaches caused by merchant's failure to implement these security measures; (b) merchants are solely responsible for the security of their account credentials; (c) any unauthorized access resulting from merchant negligence is the merchant's sole responsibility; and (d) Vayva reserves the right to suspend accounts that fail to maintain adequate security.
We welcome responsible disclosure of security vulnerabilities. If you discover a security issue, please report it to privacy@vayva.ng. We commit to acknowledging reports within 48 hours and will not take legal action against researchers who follow responsible disclosure practices.
While Vayva implements industry-leading security measures, no system is completely secure. You acknowledge and agree that: (a) Vayva does not guarantee that the Platform will be completely secure or immune from cyber attacks; (b) Vayva shall not be liable for security breaches caused by third-party providers, zero-day vulnerabilities, or sophisticated attacks beyond reasonable prevention; (c) merchants are responsible for securing their own devices and networks; (d) Vayva's security measures are provided "as-is" without warranty of complete protection; and (e) in the event of a security breach, Vayva's liability is limited to the measures described in this policy and applicable law.
To the maximum extent permitted by law, Vayva shall not be liable for: (a) security breaches caused by third parties outside our reasonable control; (b) unauthorized access resulting from merchant's failure to maintain security; (c) losses arising from cyber attacks, malware, or other security incidents; or (d) any indirect, incidental, or consequential damages from security incidents. Vayva's total liability for security incidents shall not exceed the amounts specified in the Terms of Service.
Security team: privacy@vayva.ng | DPO: privacy@vayva.ng | Phone: +234 913 700 0140.