Security at
Toplorgical
Security is foundational to everything we build. We employ enterprise-grade security measures to protect your data, your institution, and your members.
Our Commitment
Multi-Layered Security Architecture
We implement a defence-in-depth strategy, combining technical controls, operational procedures, and continuous monitoring to protect your data at every layer.
Data Encryption
All data is encrypted in transit using TLS 1.2/1.3 and at rest using AES-256 encryption. Encryption keys are managed using industry-standard key management practices.
Access Control
Role-based access control (RBAC) enforced on the principle of least privilege. Multi-factor authentication (MFA) is required for all internal systems and administrative access.
Continuous Monitoring
24/7 security monitoring with real-time alerting. Our Security Operations Centre (SOC) actively monitors for threats, anomalous behaviour, and potential breaches.
Infrastructure Security
Hosted on enterprise-grade cloud infrastructure with regular vulnerability assessments, patch management, and network segmentation to isolate sensitive systems.
Application Security
Secure Software Development Lifecycle (SSDLC) with code reviews, static analysis, and penetration testing for all major releases. OWASP Top 10 compliance maintained.
Incident Response
A documented incident response plan with defined escalation paths, containment procedures, and communication protocols to handle security events rapidly and transparently.
Data Protection
How We Protect
Your Data
We treat data protection as a core business responsibility, not just a compliance checkbox. Our practices are aligned with global data protection regulations and financial industry standards.
Data Minimisation
We collect only the data that is strictly necessary for providing our services.
Purpose Limitation
Data is used only for the specific purposes for which it was collected.
Storage Limitation
Personal data is retained only for as long as necessary and then securely deleted.
Data Accuracy
We maintain processes to keep your data accurate and up to date.
Accountability
A dedicated Data Protection Officer oversees our data governance programme.
Compliance & Standards
NDPR Compliance
Nigeria Data Protection Regulation
ISO/IEC 27001
Information Security Management
PCI DSS
Payment Card Industry Data Security Standard
SOC 2 Type II
Service Organisation Control
CBN Guidelines
Central Bank of Nigeria Fintech Regulations
Security Testing
We conduct regular security assessments including penetration testing, vulnerability scanning, and code reviews to proactively identify and remediate security risks.
Quarterly external penetration tests
Monthly automated vulnerability scans
Continuous static code analysis
Annual third-party security audits
Vulnerability Disclosure
Responsible Disclosure Policy
We take the security of our systems seriously. If you believe you have found a security vulnerability in any of our products, we encourage you to report it to us responsibly.
How to Report a Vulnerability
Contact Us
Send a detailed report to security@toplorgical.com. Include a description of the vulnerability, steps to reproduce, and potential impact.
Acknowledgement
We will acknowledge your report within 48 hours and provide an estimated timeline for investigation.
Investigation
Our security team will investigate and work to reproduce the vulnerability. We may reach out for additional information.
Resolution
We will remediate the vulnerability and notify you when the fix has been deployed. We follow a coordinated disclosure process.
Out-of-Scope Activities
Social engineering attacks, physical security attacks, denial of service attacks, and any testing against our production systems without prior authorization are strictly prohibited. Please use only test accounts and environments for security testing.
Security Questions?
Our security team is here to help. Whether you have questions about our security practices, need to report a vulnerability, or want to discuss a partnership, don't hesitate to reach out.