Trust & Safety

Security at Qwiva

Bank-grade security and uncompromising privacy for Nigerian pharmacies.

Built with security first

We follow industry best practices to ensure your data — and your customers' data — remains private, secure, and available.

🔒

Encryption in Transit and at Rest

All data transmitted to and from Qwiva is encrypted using TLS 1.2 or higher. Data stored on our servers uses AES-256 encryption at rest.

🏗️

Secure Infrastructure

Qwiva is hosted on AWS with servers in certified, ISO 27001-compliant data centres. We use VPCs, security groups, and WAF rules to restrict access.

🔑

Access Controls

Role-based access control (RBAC) ensures staff can only see what they need. Multi-factor authentication (MFA) is available for all accounts and required for admin roles.

🛡️

Regular Security Audits

We conduct internal security reviews quarterly and engage independent security researchers for annual penetration testing of our platform and APIs.

📋

Compliance

Qwiva is designed to help Nigerian pharmacies comply with NAFDAC regulations and the Nigeria Data Protection Act (NDPA). Data is processed and stored in accordance with applicable law.

🔄

Backups & Disaster Recovery

Your data is backed up daily with 30-day retention. We maintain a tested disaster recovery plan with a recovery time objective (RTO) of under 4 hours.

Application Security

We build security into every step of our engineering process using industry-leading best practices:

  • All system updates undergo rigorous manual and automated security reviews prior to deployment.
  • Continuous vulnerability scanning and security testing are integrated directly into our development lifecycle.
  • Strict data validation protocols protect the platform against malicious input and unauthorized data extraction.
  • Comprehensive safeguards are implemented to block unverified scripts and ensure safe interactions.
  • Continuous verification protocols ensure that all system requests and account changes are authentic and authorized.
  • Advanced traffic monitoring and defense mechanisms protect our login systems from automated threats and abuse.

Data Isolation

Your pharmacy's data is kept completely separate and secure. We employ rigorous security controls to guarantee that your information is completely accessible only by you, and we continuously audit these protections as part of our routine security testing.

Employee Access

Qwiva employees follow a strict least-privilege policy. Access to production data is limited to engineers who require it for support and operational purposes, and only when explicitly authorised.

  • All employees undergo background screening before joining.
  • Access to customer data is logged and audited.
  • MFA is mandatory for all internal systems.
  • Access is revoked within 24 hours of an employee leaving the company.

Incident Response

In the event of a security incident affecting your data, we will notify you within 72 hours of becoming aware of it, in accordance with our obligations under the Nigeria Data Protection Act. Our notification will include:

  • A description of the nature of the incident.
  • The categories and approximate number of records concerned.
  • The likely consequences of the incident.
  • The measures we have taken or propose to take to address it.

Responsible Disclosure

We take security reports seriously. If you believe you have discovered a vulnerability in the Qwiva platform, please report it to us responsibly before disclosing it publicly.

Report a Vulnerability

Email our security team at:

security@qwiva.io

Please include a detailed description of the vulnerability, steps to reproduce it, and any proof-of-concept code. We aim to acknowledge reports within 48 hours and will keep you informed throughout the investigation. We do not take legal action against researchers who act in good faith.

Contact

For general security questions or concerns:

Qwiva Technologies Ltd

Lagos, Nigeria

Security: security@qwiva.io

Support: support@qwiva.io