Trust Center
We believe trust is earned through transparency. This page details our security practices, compliance status, sub-processors, and policies — everything you need to evaluate Vayva's security posture.
Security at a Glance
256-bit
AES Encryption
Level 1
PCI-DSS (via Paystack)
High
Availability Architecture
Daily
Encrypted Backups
Security Controls
All stored data encrypted with AES-256-GCM. Database volumes, object storage, and backups are fully encrypted.
All communication between clients and our services uses TLS 1.3 with strong cipher suites. HSTS enforced.
Granular RBAC with least-privilege defaults. Multi-factor authentication required for all administrative access.
Production networks are segmented with strict firewall rules. No direct internet access to database tiers.
Real-time security monitoring with automated anomaly detection. SIEM integration for threat correlation.
Web Application Firewall with managed rule sets. Layer 3/4 DDoS mitigation via Cloudflare Magic Transit.
Daily encrypted backups with point-in-time recovery. Cross-region replication with 30-day retention.
Payment processing through PCI-DSS Level 1 compliant Paystack. Raw card data never touches our systems.
Compliance
We actively pursue compliance with major security and privacy frameworks. Our compliance program is continuously monitored and updated.
Nigeria Data Protection Regulation
EU General Data Protection Regulation
Service Organization Control 2
Information Security Management
Payment Card Industry Data Security Standard
Health Insurance Portability and Accountability Act
Sub-Processors
We maintain a list of all sub-processors that may handle your data. Each is vetted for security and compliance.
| Provider | Purpose | Location | Compliance |
|---|---|---|---|
| Paystack | Payment processing | Nigeria | PCI-DSS Level 1 |
| Amazon Web Services (AWS) | Cloud infrastructure & hosting | Global | SOC 2, ISO 27001 |
| Cloudflare | CDN, DDoS protection, WAF | Global | SOC 2, ISO 27001 |
| Google Cloud | AI/ML services | USA | SOC 2, ISO 27001 |
| SendGrid | Email delivery | USA | SOC 2 |
| Redis Cloud | Caching & session storage | Global | SOC 2 |
| Supabase (AWS) | Primary database | AWS (Global) | SOC 2, ISO 27001 |
Uptime
Uptime monitoring data will be published here after launch. Our target is 99.9% monthly uptime.
We are setting up comprehensive uptime monitoring and will publish historical data here once available. For real-time status updates, visit /system-status.
Policies
Our security practices are governed by published policies. Contact us for access to specific policy documents or to request a security assessment questionnaire.
Overall security program scope, objectives, and governance structure.
Authentication, authorization, MFA, and least-privilege principles.
Data categorization (public, internal, confidential, restricted) and handling rules.
Detection, escalation, containment, and communication procedures.
RPO/RTO targets, backup strategy, and disaster recovery procedures.
Third-party assessment, ongoing monitoring, and contractual requirements.
Code review, SAST/DAST, dependency scanning, and release gates.
Data subject rights, consent management, cross-border transfer rules.
Full policy documents available upon request or via your account's compliance dashboard.
For security concerns, vulnerability reports, or compliance questions, contact our Data Protection Officer or security team.
Join African merchants who trust Vayva with their business.