Sign in
Security

How we handle your money.

ZenvaPay is still being built. Everything on this page is a commitment we are building to, written down now so it can be held against what ships — not a description of a running system.

Argon2id

We cannot read your PIN

Your PIN and password are hashed separately. Nobody at ZenvaPay can recover either — and neither could anyone who took a copy of our database.

Every use

A stolen session is caught, not just expired

Sign-in tokens rotate on every use. If an old one reappears, that proves it was copied — so we revoke the whole session immediately.

Allowlist

Your BVN never reaches a log file

Our logs record only fields explicitly permitted. Identity numbers, card details, OTPs and PINs are not among them.

Two people

No one person can move your money

Manual credits, refunds and payouts each need one person to raise them and another to approve. Enforced in the database, not on a screen.

Double-entry

Every kobo is accounted for

Your balance is not a number we store — it is the sum of every entry on your account, reconciled nightly.

Never guessed

An unclear result is resolved, not assumed

If we cannot tell whether a purchase succeeded, we ask the provider until we know. We never guess in either direction.

Found something?

If you believe you have found a vulnerability, email hello@zenvapay.com with enough detail to reproduce it. We will confirm receipt and keep you updated as we investigate.