Security

Last updated 6 October 2026

Institution isolation

Every record belongs to one institution, and access is enforced by the database itself, not by the browser.

Two-step sign-in

Every account must use an authenticator app code. No data loads without it.

Tamper-evident evidence

Compliance scores are computed by the system. Audit packs are SHA-256 sealed, each chained to the previous one, and cannot be edited or deleted.

Data minimisation

No raw BVN, NIN or card numbers are stored.

Reporting a vulnerability

If you believe you have found a security issue, please contact admin@vaedilimited.com privately before disclosing it. Do not include passwords, authenticator codes or customer payment data.