Security & Trust

Built to pass your due diligence

Financial institutions cannot take security on faith. This page summarises how Korvena protects customer data; our full security documentation is available to prospective customers under NDA.

Encryption

Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Keys are managed, rotated and access-controlled separately from the data they protect.

Data isolation

Each institution’s data is logically isolated per tenant. No customer’s data is ever visible to, or commingled with, another’s.

Access control

Role-based access control with least-privilege defaults, enforced multi-factor authentication and SSO support. Access reviews are periodic and recorded.

Audit logging

Administrative and data-affecting actions are logged immutably — who, what, when — and made available to customer compliance teams.

Secure development

Code review on every change, dependency and vulnerability scanning, segregated environments, and no production data in development or testing.

Backup & continuity

Automated, encrypted backups with defined recovery objectives, restoration tests, and documented business-continuity procedures.

Incident response

A documented incident-response plan with defined severities, escalation paths and customer-notification commitments consistent with applicable law.

Privacy compliance

Personal data is handled in line with the Nigeria Data Protection Act, 2023 and our privacy notice: minimum necessary data, clear purpose, defined retention.

Due diligence

Security questionnaires, architecture reviews and our full policy set are available to prospective customers under NDA. Request access.

We describe our practices plainly and avoid badge-collecting language. Where formal certifications are achieved in future, they will be documented here with their scope and dates.