Security at Qwiva
Built with security first
We follow industry best practices to ensure your data — and your customers' data — remains private, secure, and available.
Encryption in Transit and at Rest
All data transmitted to and from Qwiva is encrypted using TLS 1.2 or higher. Data stored on our servers uses AES-256 encryption at rest.
Secure Infrastructure
Qwiva is hosted on AWS with servers in certified, ISO 27001-compliant data centres. We use VPCs, security groups, and WAF rules to restrict access.
Access Controls
Role-based access control (RBAC) ensures staff can only see what they need. Multi-factor authentication (MFA) is available for all accounts and required for admin roles.
Regular Security Audits
We conduct internal security reviews quarterly and engage independent security researchers for annual penetration testing of our platform and APIs.
Compliance
Qwiva is designed to help Nigerian pharmacies comply with NAFDAC regulations and the Nigeria Data Protection Act (NDPA). Data is processed and stored in accordance with applicable law.
Backups & Disaster Recovery
Your data is backed up daily with 30-day retention. We maintain a tested disaster recovery plan with a recovery time objective (RTO) of under 4 hours.
Application Security
We build security into every step of our engineering process using industry-leading best practices:
- All system updates undergo rigorous manual and automated security reviews prior to deployment.
- Continuous vulnerability scanning and security testing are integrated directly into our development lifecycle.
- Strict data validation protocols protect the platform against malicious input and unauthorized data extraction.
- Comprehensive safeguards are implemented to block unverified scripts and ensure safe interactions.
- Continuous verification protocols ensure that all system requests and account changes are authentic and authorized.
- Advanced traffic monitoring and defense mechanisms protect our login systems from automated threats and abuse.
Data Isolation
Your pharmacy's data is kept completely separate and secure. We employ rigorous security controls to guarantee that your information is completely accessible only by you, and we continuously audit these protections as part of our routine security testing.
Employee Access
Qwiva employees follow a strict least-privilege policy. Access to production data is limited to engineers who require it for support and operational purposes, and only when explicitly authorised.
- All employees undergo background screening before joining.
- Access to customer data is logged and audited.
- MFA is mandatory for all internal systems.
- Access is revoked within 24 hours of an employee leaving the company.
Incident Response
In the event of a security incident affecting your data, we will notify you within 72 hours of becoming aware of it, in accordance with our obligations under the Nigeria Data Protection Act. Our notification will include:
- A description of the nature of the incident.
- The categories and approximate number of records concerned.
- The likely consequences of the incident.
- The measures we have taken or propose to take to address it.
Responsible Disclosure
We take security reports seriously. If you believe you have discovered a vulnerability in the Qwiva platform, please report it to us responsibly before disclosing it publicly.
Report a Vulnerability
Email our security team at:
security@qwiva.ioPlease include a detailed description of the vulnerability, steps to reproduce it, and any proof-of-concept code. We aim to acknowledge reports within 48 hours and will keep you informed throughout the investigation. We do not take legal action against researchers who act in good faith.
Contact
For general security questions or concerns: