Security
Last updated 6 October 2026
Institution isolation
Every record belongs to one institution, and access is enforced by the database itself, not by the browser.
Two-step sign-in
Every account must use an authenticator app code. No data loads without it.
Tamper-evident evidence
Compliance scores are computed by the system. Audit packs are SHA-256 sealed, each chained to the previous one, and cannot be edited or deleted.
Data minimisation
No raw BVN, NIN or card numbers are stored.
Reporting a vulnerability
If you believe you have found a security issue, please contact admin@vaedilimited.com privately before disclosing it. Do not include passwords, authenticator codes or customer payment data.