Zynterra

Security & data protection

We build an API security product and an escrow platform. Security isn't a slide in our deck, it's the discipline both products depend on, and the same discipline applies to every project we take on.

Client data & credentials

What happens to your access.

  • Least privilege by default. We ask for access to what the work requires, not the whole account
  • Secrets never go into source control, in our code or in what we deliver to you
  • Access is removed when a project or retainer ends, not left dangling
  • Credentials are shared through a password manager, never over email or chat

Default in everything we ship

What's in every delivery.

  • TLS everywhere, no exceptions for internal traffic
  • Passwords hashed with a modern algorithm, never stored in plain text
  • Parameterised queries by default. String-built SQL doesn't ship
  • Dependencies audited on a schedule, not only when a CVE makes the news
  • Auth tokens scoped, short-lived, and rotated, not a single key that opens everything

NDPR & NDPC

Designed for it, not bolted on.

Nigeria's data protection framework isn't treated as a form to fill in after launch. It shapes how we design the data model in the first place.

  • 01Data minimisation: collect what a feature needs, nothing kept “just in case”
  • 02A real path to erasure. Deleting a user's data means deleting it, not soft-flagging a row
  • 03Breach notification obligations designed for up front, not figured out after an incident

Payments & CBN considerations

Regulated data stays regulated.

Anything touching payments gets the same rule we hold AuditGate to: BVN, NIN, and card data must never be logged in plain text. These fields are masked before they reach a log line or a queue message, not filtered out after the fact.

Report a vulnerability

Found something? Tell us directly.

If you've found a security issue in anything we've built, including Zorva or AuditGate, email [email protected] with what you found and how to reproduce it. We reply within one business day.

This page describes our practices as of 2026 and is not legal advice. If data protection compliance is a formal requirement for your project, consult qualified counsel.