How we handle your money.
ZenvaPay is still being built. Everything on this page is a commitment we are building to, written down now so it can be held against what ships — not a description of a running system.

We cannot read your PIN
Your PIN and password are hashed separately. Nobody at ZenvaPay can recover either — and neither could anyone who took a copy of our database.
A stolen session is caught, not just expired
Sign-in tokens rotate on every use. If an old one reappears, that proves it was copied — so we revoke the whole session immediately.
Your BVN never reaches a log file
Our logs record only fields explicitly permitted. Identity numbers, card details, OTPs and PINs are not among them.
No one person can move your money
Manual credits, refunds and payouts each need one person to raise them and another to approve. Enforced in the database, not on a screen.
Every kobo is accounted for
Your balance is not a number we store — it is the sum of every entry on your account, reconciled nightly.
An unclear result is resolved, not assumed
If we cannot tell whether a purchase succeeded, we ask the provider until we know. We never guess in either direction.
Found something?
If you believe you have found a vulnerability, email hello@zenvapay.com with enough detail to reproduce it. We will confirm receipt and keep you updated as we investigate.