Toplorgical Logo

Loading Experience

Home/Security

Security at
Toplorgical

Security is foundational to everything we build. We employ enterprise-grade security measures to protect your data, your institution, and your members.

TLS 1.3 Encrypted
AES-256 Storage
ISO 27001 Aligned
SOC 2 Type II Ready

Our Commitment

Multi-Layered Security Architecture

We implement a defence-in-depth strategy, combining technical controls, operational procedures, and continuous monitoring to protect your data at every layer.

Data Encryption

All data is encrypted in transit using TLS 1.2/1.3 and at rest using AES-256 encryption. Encryption keys are managed using industry-standard key management practices.

Access Control

Role-based access control (RBAC) enforced on the principle of least privilege. Multi-factor authentication (MFA) is required for all internal systems and administrative access.

Continuous Monitoring

24/7 security monitoring with real-time alerting. Our Security Operations Centre (SOC) actively monitors for threats, anomalous behaviour, and potential breaches.

Infrastructure Security

Hosted on enterprise-grade cloud infrastructure with regular vulnerability assessments, patch management, and network segmentation to isolate sensitive systems.

Application Security

Secure Software Development Lifecycle (SSDLC) with code reviews, static analysis, and penetration testing for all major releases. OWASP Top 10 compliance maintained.

Incident Response

A documented incident response plan with defined escalation paths, containment procedures, and communication protocols to handle security events rapidly and transparently.

Data Protection

How We Protect
Your Data

We treat data protection as a core business responsibility, not just a compliance checkbox. Our practices are aligned with global data protection regulations and financial industry standards.

Data Minimisation

We collect only the data that is strictly necessary for providing our services.

Purpose Limitation

Data is used only for the specific purposes for which it was collected.

Storage Limitation

Personal data is retained only for as long as necessary and then securely deleted.

Data Accuracy

We maintain processes to keep your data accurate and up to date.

Accountability

A dedicated Data Protection Officer oversees our data governance programme.

Compliance & Standards

NDPR Compliance

Nigeria Data Protection Regulation

Compliant

ISO/IEC 27001

Information Security Management

Aligned

PCI DSS

Payment Card Industry Data Security Standard

In Progress

SOC 2 Type II

Service Organisation Control

Planned

CBN Guidelines

Central Bank of Nigeria Fintech Regulations

Compliant

Security Testing

We conduct regular security assessments including penetration testing, vulnerability scanning, and code reviews to proactively identify and remediate security risks.

Quarterly external penetration tests

Monthly automated vulnerability scans

Continuous static code analysis

Annual third-party security audits

Vulnerability Disclosure

Responsible Disclosure Policy

We take the security of our systems seriously. If you believe you have found a security vulnerability in any of our products, we encourage you to report it to us responsibly.

How to Report a Vulnerability

01

Contact Us

Send a detailed report to security@toplorgical.com. Include a description of the vulnerability, steps to reproduce, and potential impact.

02

Acknowledgement

We will acknowledge your report within 48 hours and provide an estimated timeline for investigation.

03

Investigation

Our security team will investigate and work to reproduce the vulnerability. We may reach out for additional information.

04

Resolution

We will remediate the vulnerability and notify you when the fix has been deployed. We follow a coordinated disclosure process.

Out-of-Scope Activities

Social engineering attacks, physical security attacks, denial of service attacks, and any testing against our production systems without prior authorization are strictly prohibited. Please use only test accounts and environments for security testing.

Security Questions?

Our security team is here to help. Whether you have questions about our security practices, need to report a vulnerability, or want to discuss a partnership, don't hesitate to reach out.