Zynterra

Products


We invest in our own products because building for ourselves keeps our standards honest. Both are trust infrastructure: one protects transactions, the other protects APIs.

Escrow platform · In development

Zorva. Pay safe.
Sell bold.

Zorva is a trust layer for Nigerian commerce. Create a secure escrow link in under two minutes and share it on WhatsApp. The buyer's money is held by Zorva until both sides agree, then released instantly to the seller's bank account.

The link holds the money.
Neither buyer nor seller can touch funds until the agreed terms are met. No more "send first" standoffs.
Built for how Nigeria trades.
Works over WhatsApp and Instagram, funded by card, transfer, or USSD. No app download for the other party.
Fair when things go wrong.
Human-mediated disputes, auto-release timers so buyers cannot ghost sellers, and instant NIP payouts on confirmation.
Get in touch
Zorva seller dashboard showing an active funded escrow transaction, wallet balance and trust score

The problem

Two strangers, no recourse.

Most commerce in Nigeria happens between people who have never met: a buyer and a seller connected through an Instagram post or a WhatsApp forward. Someone has to move first, and if it goes wrong, there is no bank to call and no chargeback to file. Zorva is the neutral third party that lets either side move first safely.

How it works

  1. Create the link

    Seller sets the price and terms and gets a link. Under two minutes, no app install.

  2. Share it

    Sent over WhatsApp, Instagram DM, or anywhere else the deal is already happening.

  3. Buyer funds it

    By card, bank transfer, or USSD. Money moves into Zorva, not into the seller's account yet.

  4. Zorva holds it

    Neither side can touch the funds until the terms both agreed to are met.

  5. Goods are delivered

    The seller ships or hands over what was promised.

  6. Buyer confirms, seller is paid

    Confirmation releases the funds instantly to the seller's bank account by NIP transfer.

Who it's for

  • Instagram and WhatsApp vendors
  • Freelancers taking a deposit before starting work
  • Peer-to-peer device and gadget sales
  • Small B2B orders between businesses that haven't worked together before

When things go wrong

Either side can raise a dispute, and a human mediator steps in rather than an algorithm. Auto-release timers mean a buyer cannot simply go quiet to avoid paying once goods have shipped. The money stays visibly held until a resolution is reached, not silently gone to either side.

API security platform · In development

Ship APIs with confidence.

AuditGate sits in front of your API as a transparent proxy and inspects every request in real time, catching vulnerabilities before they reach production. Connect your repo and findings name the exact file and line to fix, not just the endpoint.

Talk to us about AuditGate
AuditGate project overview for a production API, showing health score trend, severity counts and the connected repository
Passive monitoring, zero code changesPoint your traffic at the AuditGate proxy and you're live. Under 5ms of overhead, and analysis never blocks a response.
Findings that name the file and lineWith your GitHub or GitLab repo connected, "unauthenticated endpoint" becomes "add the auth guard on line 24 of payments.controller.ts."
Compliance built in, not bolted on100+ rules covering the OWASP Top 10 plus Nigerian regulatory checks: BVN, NIN, and card-data exposure flagged as critical, instantly.
One-click PDF audit reportsClient-ready reports generated in under a minute, built for consultants and teams that answer to someone.

< 0ms

p99 proxy overhead

Design target

< 0s

traffic event to finding

Design target

0+

rules, OWASP Top 10 plus Nigerian checks

Design target

The differentiator

Most scanners only see traffic. AuditGate reads the code too.

Teams shipping fast with AI-assisted tools introduce vulnerabilities faster than a human can review them. A traffic-only scanner can tell you a request looks dangerous. It cannot tell you why, or where to fix it. AuditGate can, because it indexes the codebase behind the endpoint, not just the request going past it.

How it works

  1. Traffic arrives

    Requests to your API pass the proxy with no code changes on your side.

  2. Checked in real time

    Every request is evaluated against the rule set without adding meaningful latency.

  3. Finding surfaced

    If something's wrong, it shows up immediately, described in plain English.

  4. Fixed with confidence

    With your repo connected, the finding points at the exact file and line to change.

Three ways to connect

Deepest

GitHub or GitLab connection

Findings point to the exact file and line. This is what makes a finding actionable instead of just alarming.

Medium

OpenAPI specification

No repo access needed. Findings are scoped to the documented surface of your API.

Always available

Traffic inference

Works from proxy traffic alone, with no code access at all. The floor, not the ceiling.

Privacy boundary

AuditGate stores the index built from your code. It never stores the source code itself. Files are analysed in a temporary workspace and discarded once the index is built.

Nigerian compliance, first class

Rules built for CBN and NDPC requirements, not bolted on after the fact. BVN, NIN, and card PAN exposure are detected and flagged critical by default.

Why we build our own products

Building for ourselves keeps our standards honest.

We feel our own mistakes before a client ever does. Zorva and AuditGate run on the same stack, the same review discipline, and the same on-call reality we bring to client work. If a shortcut is not good enough for our own product, it is not good enough for yours.