Security

Built by people who shipped to banks. Secured like it.

WeServ runs a documented security programme: written policies, named ownership, and a quarterly review with an evidence trail. This page states what we actually do.

Our controls

Six things we operate, not just write down

Access control

Least-privilege, named accounts only, with multi-factor authentication required on every system that supports it. All access lives in a register reviewed quarterly; offboarding revokes access within one working day.

Encryption

TLS on every endpoint, platform storage encryption at rest, and application-level encryption of sensitive fields where a design calls for it. Secrets live in environment configuration, never in code.

Secure development

Private repositories, dependency hygiene, synthetic data in tests and seeds, and no personal data in logs. Security-relevant behaviour is covered by automated tests before release.

Data protection

We work to the Nigeria Data Protection Act 2023 and UK GDPR, act under data processing agreements when handling client data, and keep data only as long as our published retention schedule allows.

Backups and recovery

Backups are encrypted and held on a rolling window of 90 days or less, and the restore path is verified as part of the quarterly review, because a backup that has never been restored is a guess.

Incident response

Contain, assess, notify, remediate, post-mortem. Clients are told without undue delay about anything touching their systems, and personal data breaches are notified to the regulator within 72 hours.

What we build in

Every client app ships compliance-ready

Software we build carries a standard set of data protection features from day one, not as a retrofit: recorded consent at signup, a privacy notice, audit logging on sensitive actions, role-based access control, encryption in transit and at rest, and a working data-deletion path. For Nigerian products this maps directly onto NDPA obligations, which means our clients start compliant instead of starting over.

We also run NDPA gap assessments on existing products: a structured review against the Act, a prioritised remediation plan, and the evidence pack your compliance organisation needs for NDPC filings.

Found a vulnerability? Tell us.

Report security concerns through our contact form. We acknowledge reports within one working day, and good-faith research is always welcome, never threatened.

Report a security issue