Security
Your financial data, protected at every layer
Kontrol Ops reconciles money movement for businesses across Africa, so we treat your data as exactly what it is — sensitive financial records. Here's how we keep it isolated, encrypted, and accountable.
Account & access security
Sign-in is email and password, with optional two-factor authentication using an authenticator app (TOTP — Google Authenticator, 1Password, Authy, Microsoft Authenticator and similar). Enrolment, sign-in challenges, and resets are recorded in your organisation's audit log. Authenticator codes are never visible to us.
Data residency
Your data is stored in the European Union (eu-west-1) on managed PostgreSQL. We don't relocate it. For organisations with stricter residency needs, a dedicated-region deployment is available on request.
Tenant isolation
Every record is scoped to your organisation and isolated at the database layer with PostgreSQL row-level security — not just in application code. Within your organisation, role-based access (admin, finance, viewer) limits what each member can see and do.
Encryption
Data is encrypted in transit (TLS) and encrypted at rest. Server-only credentials are never exposed to the browser.
Error diagnostics
When we collect error diagnostics to keep the service reliable, personal and financial data — request bodies, account references, amounts, tokens — is scrubbed out before the report ever leaves our systems.
Audit trail
Security-relevant actions — two-factor events, resolutions, and configuration changes — are recorded in a per-organisation audit log that your admins can review and export for a security review.
Running a vendor security review?
We're happy to complete your questionnaire. Email info@kontrol-ops.com and we'll respond with the detail your team needs. This page describes the product's current capabilities — we'll always tell you plainly what is and isn't in place.