NexaPay NexaPay
Sign In Get Started
Back Security & Compliance
Enterprise-Grade Security

Your Payments, Protected at Every Layer

NexaPay is built on a foundation of bank-grade security standards. Every transaction, API call, and data point is protected using the most advanced security protocols available — so you and your customers can transact with complete confidence.

PCI DSS
PCI DSS
Level 1 Certified
SSL TLS
TLS 1.3
256-bit Encryption
3D Secure
3D Secure
v2.0 Ready
ISO 27001
ISO 27001
Information Security
GDPR Aligned
Data Privacy
99.9% Uptime
SLA Guaranteed
256-bit
AES Encryption at Rest
TLS 1.3
Encryption in Transit
< 60s
Incident Alert Response
99.9%
Guaranteed API Uptime
Certifications & Standards
PCI DSS

PCI DSS Level 1 Compliance

The gold standard in payment security

NexaPay is PCI DSS Level 1 compliant — the highest certification level defined by the Payment Card Industry Data Security Standard. This means every component of our payment infrastructure is independently audited annually by a Qualified Security Assessor (QSA).

Annual QSA Audit
Quarterly Network Scans
Penetration Testing
Cardholder Data Protection

Our compliance covers all 12 PCI DSS requirements including network security, access control, vulnerability management, monitoring, and information security policy. Merchants on NexaPay inherit our compliance posture — reducing your own PCI scope to a simplified SAQ-A or SAQ-A-EP self-assessment questionnaire.

ISO 27001

ISO 27001 — Information Security Management

Internationally recognised standard

Our information security management system (ISMS) is built to ISO 27001 standards. This covers the full lifecycle of information security — from risk assessment and asset management through to access control, incident management, and business continuity planning.

Risk Assessment Access Control Asset Management Incident Management Business Continuity Supplier Relationships
Encryption & Transport Security
TLS Encryption

TLS 1.3 Encryption in Transit

All data encrypted end-to-end

All communication between your application and NexaPay APIs is encrypted using TLS 1.3 — the latest and most secure version of the Transport Layer Security protocol. Older TLS versions (1.0, 1.1) and SSL are explicitly rejected at our API gateway.

  • 256-bit AES-GCM encryption for all API traffic and webhook payloads
  • Perfect Forward Secrecy (PFS) enabled on all endpoints via ECDHE key exchange
  • HSTS (HTTP Strict Transport Security) enforced with one-year max-age and preloading
  • Certificate pinning available for mobile SDK integrations
  • All data at rest encrypted using AES-256 with key management via Hardware Security Module (HSM)
  • Automatic certificate rotation — no manual intervention required by merchants

API Key Security & Access Control

Scoped, rotatable, and IP-restricted

NexaPay API keys use a two-tier model: a public key (safe for client-side) that identifies your account, and a secret key that must only be used server-side. Secret keys are never logged, never stored in plaintext, and are hashed with bcrypt in our systems.

  • Separate sandbox and production key pairs — sandbox keys cannot access live funds
  • Per-key permission scoping — restrict a key to collections only, disbursements only, or read-only reporting
  • IP allowlisting — restrict which server IPs may use a key (configurable in dashboard)
  • Instant key rotation with a 60-second grace window for zero-downtime deploys
  • Activity logs for every API call — searchable by IP, endpoint, timestamp, and response code

Never expose secret keys in client-side code. Always make NexaPay API calls from your server. If a key is compromised, rotate it immediately from your dashboard — old keys are revoked within 60 seconds.

Authentication & Fraud Prevention
3D Secure

3D Secure Authentication

Additional authentication layer for every payment

NexaPay supports 3D Secure 2.0 (3DS2) across all supported mobile money networks. This provides an additional authentication layer that confirms the identity of the payer before a transaction is authorised, dramatically reducing fraud and chargebacks.

3DS2 enables risk-based authentication — low-risk transactions flow seamlessly without user friction, while high-risk transactions trigger additional verification steps. This means fewer abandoned payments and stronger protection simultaneously.

Risk-Based Auth
PIN Verification
Fewer Chargebacks
No Added Friction

Fraud Detection & Prevention

Real-time threat intelligence

Our multi-layer fraud detection engine analyses every transaction in real time using machine learning models trained specifically on African mobile money patterns. Suspicious activity is flagged and reviewed within seconds — often before a fraudulent transaction can complete.

  • Velocity checks — detecting unusual transaction frequency per account, device, and IP
  • Device fingerprinting and geo-IP mismatch detection
  • Phone number reputation scoring across all four supported countries
  • SIM swap detection integration with MTN, Airtel, and EcoCash APIs
  • Merchant-configurable risk thresholds and auto-block rules via dashboard
  • Behavioural anomaly detection — flags deviations from a merchant's normal transaction patterns
  • 24/7 fraud operations team monitoring live transaction feeds
Data Residency & Privacy

Data Residency — Your Data Stays in Africa

In-country storage for all four markets

NexaPay processes and stores all transaction data within African data centres. We maintain separate data residency zones for Zambia, Zimbabwe, Botswana, and Namibia to comply with each country's data sovereignty requirements.

  • Data for Zambian merchants stored in Zambia-based infrastructure
  • Full compliance with Bank of Zambia, RBOZ, NBFIRA, and BoN data regulations
  • GDPR-aligned data handling for any EU-connected integrations
  • Zero data sharing with advertisers, aggregators, or third-party brokers
  • Right to deletion (RTBF) honoured within 72 hours of a valid request
  • Transaction data retained for a minimum of 7 years as required by financial regulations

Customer Data Handling

Minimal collection, maximum protection

NexaPay applies the principle of data minimisation — we collect only what is strictly necessary to process payments and prevent fraud. Customer PINs and wallet passwords are never seen or stored by NexaPay; these remain exclusively in the mobile network operator's secure infrastructure.

  • Phone numbers hashed at ingestion — never stored in plaintext
  • Transaction amounts, timestamps, and status codes stored for settlement and reporting only
  • No tracking of customer browsing behaviour, location, or device beyond fraud signals
  • All customer-facing data requests fulfilled within 30 days per applicable law
Testing & Infrastructure Security

Penetration Testing

Tested by external experts quarterly

NexaPay undergoes rigorous penetration testing by independent security firms every quarter. Our scope covers web application security, API security, network infrastructure, mobile SDK security, and social engineering resilience.

  • OWASP Top 10 vulnerability testing on every major release
  • API fuzzing and injection attack simulation (SQL, NoSQL, command injection)
  • Full network and infrastructure pen test quarterly by certified CREST/OSCP testers
  • All critical findings resolved within 24 hours; high findings within 7 days
  • Summary security reports available to enterprise merchants on request
  • Bug bounty programme — responsible disclosure rewarded for verified vulnerabilities

Infrastructure & Network Security

Defence-in-depth architecture

NexaPay infrastructure is deployed on dedicated cloud instances (not shared tenancy) with a layered defence architecture. No single point of failure exists in our payment processing path.

  • Web Application Firewall (WAF) with custom rule sets for payment API patterns
  • DDoS protection — automatic traffic scrubbing at the network edge (up to 1 Tbps)
  • Network segmentation — payment processing, data storage, and management planes are fully isolated
  • Zero-trust internal access — every service-to-service call requires mutual TLS authentication
  • Immutable infrastructure — servers are replaced not patched, eliminating configuration drift
  • Real-time intrusion detection (IDS/IPS) with automated quarantine of anomalous nodes

Uptime, SLA & Business Continuity

99.9% guaranteed — no exceptions

NexaPay's payment API maintains a 99.9% uptime SLA backed by multi-region redundancy. Real-time status and historical uptime data are published at status.nexapay.africa. Planned maintenance windows are announced at least 72 hours in advance via email and the status page.

99.9%
API uptime SLA
< 72h
Advance notice for maintenance
  • Multi-region active-active deployment — no single region failure takes the API offline
  • Automatic failover with sub-30-second recovery time objective (RTO)
  • Daily encrypted backups with point-in-time recovery up to 30 days
  • Annual disaster recovery drill — documented and results published to enterprise clients
  • Incident communications via email, webhook, and the public status page within 15 minutes of detection
Incident Response

Incident Response & Breach Notification

Structured, tested, and transparent

NexaPay maintains a formal Incident Response Plan (IRP) that is tested through tabletop exercises twice per year. In the event of a security incident affecting merchant or customer data, we follow a strict notification timeline.

  • Security incidents are triaged by our on-call security team within 60 seconds of detection
  • P1 (critical) incidents: affected merchants notified within 1 hour; public notice within 4 hours
  • Regulatory notification: submitted to relevant financial regulators within 24–72 hours as required by law
  • Post-incident report delivered to affected enterprise merchants within 5 business days
  • Root cause analysis and remediation steps documented and shared transparently

To report a security vulnerability or suspected breach, contact our security team directly at security@nexapay.africa. Responsible disclosure is rewarded — we investigate all reports within 24 hours.

Internal Access Controls & Employee Security

Zero-trust, role-based, audited

Access to production systems and merchant data is governed by strict role-based access control (RBAC). No single employee has unrestricted access to live payment data.

  • All production access requires multi-factor authentication (FIDO2/hardware key preferred)
  • Principle of least privilege enforced — staff access only what is required for their role
  • All internal access to merchant data is logged, immutable, and reviewed weekly
  • Background checks conducted for all employees with access to financial systems
  • Mandatory annual security awareness training for all staff
  • Immediate access revocation on employee departure — automated via HR system integration