image

imageSecurity Guidelines

Effective Date: 11th November 2023Last Updated: 1st October, 2025

These Security Guidelines outline the measures, responsibilities, and best practices that protect all users, developers, and partners across Netapps Technologies Limited, including Netapps Marketplace Limited, Netapps Aggregators Limited, Netapps Microfinance Bank Limited, and Netapps Africloud Limited (collectively referred to as “Netapps Products & Services”). Security is a shared responsibility.

  • image

    You (users, developers, and partners) must take steps to safeguard your accounts and data.

  • image

    We (Netapps) are committed to securing our platforms, systems, and infrastructure with industry-leading standards.

1. User Security Guidelines

1.1 Account & Profile Security

Guidelines to protect user accounts and profiles.Guidelines to protect user accounts and profiles.Guidelines to protect user accounts and profiles.Guidelines to protect user accounts and profiles.

  • imageYour username must match your registered email or phone number. Usernames cannot be modified without contacting Netapps Support.
  • imageKeep your password confidential. If compromised, reset it immediately using the in-app feature.
  • imageTwo-Factor Authentication (2FA) is strongly recommended. Options include “Always remember” or “On Each Login.”

1.2 Password & PIN Management

  • imageUse strong, unique passwords (avoid names, dates, or reused credentials).
  • imageChange your password at least every 90 days.
  • imageNever disclose your password, PIN, or OTP — not even to Netapps staff.
  • imageAlways keep your PIN private and distinct from your password.

1.3 Session & Transaction Control

  • imageSessions automatically expire after 1 hour of inactivity to minimize risk.
  • imageCertain KYC-level accounts may customize session timeouts.
  • imageAll sensitive transactions require re-entry of your PIN.

1.4 Recognizing Phishing & Fraud

  • imageNetapps will never request your password, card details, or PIN via SMS, email, or phone.
  • imageVerify URLs before logging in: look for https:// and the padlock symbol.
  • imageBeware of fake domains (e.g., “netAPps” or “Net-Apps”) and poorly worded websites.
  • imageDo not click links from unverified SMS, WhatsApp, or social media messages.

2. Developer & Partner Security Guidelines

2.1 API & Integration Security

  • imageKeep your API keys, SDK credentials, and tokens confidential. Do not hard-code them into public repositories.
  • imageRotate API keys regularly and immediately revoke compromised keys.
  • imageUse the sandbox environment for testing — never use live credentials in development.

2.2 Access Control

  • imageRestrict access to API keys and credentials to authorized team members only.
  • imageApply the principle of least privilege when assigning user roles and access.

2.3 Data Handling & Compliance

  • imageEnsure that personal data collected via Netapps APIs is stored, processed, and transmitted in compliance with NDPR, GDPR, and other applicable data protection laws.
  • imageDo not retain or share sensitive user data beyond the purpose of integration.

2.4 Reporting & Support

  • imageReport suspected API misuse, fraud, or security vulnerabilities to security@netapps.ng.
  • imagePartners who fail to comply with integration security standards may face suspension of services.

3. Netapps Commitments to Security

3.1 Encryption & Data Security

  • imageAll sensitive data is encrypted in transit (TLS/SSL) and at rest (AES-256).
  • imageRegular penetration tests and vulnerability scans are performed on all systems.

3.2 Compliance & Certification

  • imagePCI DSS Level 1 Certified — audited by an independent PCI Qualified Security Assessor (QSA).
  • imageLicensed Payment System Service Provider (PSSP) by the Central Bank of Nigeria (CBN).
  • imageAdherence to NDPR (Nigeria Data Protection Regulation), GDPR, and global best practices.
  • imageCertified to ISO/IEC 27001:2022 for Information Security Management Systems (ISMS).

3.3 Monitoring & Fraud Prevention

  • imageContinuous monitoring of transactions to detect suspicious activities.
  • imageMulti-layered fraud prevention including velocity checks, anomaly detection, and AI-based risk scoring.

3.4 Incident Response & User Protection

  • imageIn the event of a suspected security breach, Netapps will immediately investigate and contain the threat.
  • imageNotify affected users and regulators as required by law.
  • imageProvide guidance on steps to secure accounts.

3.5 Transparency & Trust

  • imageNetapps regularly updates these Security Guidelines in line with evolving cyber threats.
  • imageUsers, developers, and partners will be notified of significant changes.

Contact & Reporting

If you suspect fraud, phishing, or unauthorized access, contact:

security@netapps.ng | +234-915-121-6060

Loading footer data...