Skip to main content
Trust & security

Built for procurement reviewers, not just product managers

NDPR/NDPA aligned. Primary data self-hosted on hardware we own — no hyperscaler — with TLS 1.3 in transit. Audit log on every privileged action. Below is the answer to every question a Lagos fintech buyer will ask before signing.

Last reviewed 28 August 2026 · Annual review cycle · [email protected]

NDPR + NDPA 2023 aligned

We process Nigerian personal data under the Nigeria Data Protection Regulation and the Nigeria Data Protection Act 2023. Data Protection Officer correspondence: [email protected].

Real Nigerians, not panels or proxies

Tests are run by real people on real Nigerian phones and networks — no emulators, no VPNs, no synthetic personas. Payout bank details are stored because Nigerian transfers require the real account number; only the last 4 digits ever appear in the product, they are never shared with clients or data buyers, and a separate HMAC-SHA256 hash (server-side pepper) is used for duplicate detection.

Encrypted in transit, self-hosted on our own hardware

TLS 1.3 enforced on every endpoint with HSTS (Strict-Transport-Security: max-age=63072000); Cloudflare terminates TLS at its edge and proxies to our origin server. Primary data — accounts, payout-account hash, payout data, session recordings — is stored on hardware the company owns and controls: not AWS, not Google Cloud, not Azure, not any hyperscaler. Application secrets are held on that same infrastructure, not in any third-party hosting dashboard.

Audit trail on every state change

Every payout, demo review, and admin action writes a row to audit_log with actor, action, entity, and structured metadata. Queryable for incident forensics.

Controls

The day-to-day controls our auditor would care about

Identity & access

  • Email one-time code (OTP) via our self-hosted authentication stack — passwordless by design, no password to leak.
  • Service-to-service auth via short-lived JWTs scoped per role (tester / client / admin).
  • Postgres row-level security policies on every multi-tenant table.
  • Admin actions gated by a separate role flag, not just a user setting.
  • Panel integrity: every tester is bank-account verified, and since 28 August 2026 every new tester also attaches a work or education proof (CV, student ID or certificate) reviewed by a person before specialist work unlocks.

Data handling

  • Payout bank-account number: we do store it. Paying a Nigerian bank account requires the real number at transfer time, so the payout destination is held in our own database as bank code + account number. Only the last 4 digits are ever shown in the product, and the number is never shared with clients or AI-data buyers. A separate HMAC-SHA256(value, pepper) hash is kept for duplicate-account detection.
  • Session-recording video files: stored on local disk on our own server and served only through authenticated, ownership-checked streaming proxies — never a public URL.
  • Backups: nightly encrypted database snapshots (pg_dump) with ~14-day retention, plus — since 28 August 2026 — a nightly AES-256-encrypted off-site copy of the database and the consented data corpus, with the encryption key held offline and a restore drill performed and verified the day the leg shipped.
  • A Data Protection Impact Assessment and a Record of Processing Activities are maintained (last updated 28 August 2026) and a Data Protection Officer is designated. Procurement reviewers can request both under NDA at [email protected].

Incident response

  • Notify affected users within 72 hours of confirmed breach (NDPA s.40 compliant).
  • Audit log preserved for 7 years for forensic + AML reconstruction (matches Retention below).
  • Single-pager runbook covering credential rotation + sub-processor isolation.
  • Status page (status.9jatesters.com) for transparency on operational incidents.

Retention

  • Personal data on account closure: deleted within 90 days. Mirrors /privacy section 6.
  • Session recordings: 90 days after client approval, then deleted unless retained on contract.
  • Test transcripts + summaries: kept for the lifetime of the parent client account, deletable on request.
  • payout-account hash + audit-log entries: 7 years post-account-closure (CBN anti-money-laundering + Nigerian tax-record-keeping). Export available on request.
  • Anonymised, non-re-identifiable aggregate metrics: may be retained indefinitely.
Sub-processors

The services we use to run 9jatesters

We notify Enterprise customers 30 days before adding or changing a sub-processor that handles personal data. Click any row to read the provider's own privacy policy.

ProviderData
CloudflareCDN, DDoS protection, and the secure tunnel that exposes our self-hosted app to the internet. Terminates TLS at the global edge and proxies requests to our origin server.In-flight request metadata (IP, headers, URL) transiting the edge. Does not persistently store our users' data.
FlutterwavePayment processing for client billing, plus bank account name resolution for tester payouts.bank account number, account name, transfer reference, client billing details.
ResendTransactional email delivery — login one-time codes (OTP) and receipts. DKIM-signed on our verified domain.Recipient email address and message content.
country.isIP-to-country lookup for display only. Never used for gating.Request IP used transiently to compute an ISO 3166-1 alpha-2 country code; raw IP not persisted by us.
FAQ

Things procurement teams ask

Do you have SOC 2 / ISO 27001?

Not certified yet — we're a 2026 startup. We operate to SOC-2-aligned controls (access, encryption, audit logging, incident response, change management) and have started a Vanta-style continuous-monitoring trial to evidence those controls for procurement reviews. Pursuing Type II once revenue justifies the audit cost (~$15-25K/yr). For enterprise contracts we sign a custom DPA with the practical equivalents and walk procurement through our controls live on a call. Procurement reviewers can request a control evidence pack at [email protected] — typically a 24-hour turnaround.

Where does our data live?

On hardware we own and control — our own server, not AWS, Google Cloud, Azure, or any other third-party cloud. That infrastructure runs the Postgres database (accounts, payout-account hash, payouts, session metadata), the self-hosted authentication stack, the session-recording video files, and the Next.js application. Payment data flows through Flutterwave's PCI-DSS compliant, CBN-licensed environment in Nigeria. For the full data-transfer disclosure — including the transient touchpoints, Cloudflare edge routing and Mailtrap email delivery — see /trust/data-residency.

Can you sign a DPA?

Yes — for Growth, Team-with-DPA-addon, and Enterprise tiers we sign a standard Data Processing Agreement covering NDPR roles (controller/processor), sub-processor change notification, deletion timelines, and breach reporting. Request via [email protected].

What if a tester asks to delete their data?

Per NDPA Article 32 we honour deletion within 30 days. Payout-account hash is removed, video files purged from storage, profile rows tombstoned. Audit-log rows are retained (for fraud-prevention legal-basis) but the user-id link is anonymised. Email [email protected].

Do you train AI on our data?

No. We never use a client's session data to train any model. Primary data — including session recordings — stays on our own self-hosted infrastructure and is not handed to a third party for model training.

How do we report a vulnerability?

[email protected] (PGP key on /.well-known/security.txt). We aim to acknowledge within 24 hours and remediate critical issues within 30 days. We don't run a paid bug-bounty yet but credit researchers publicly with their consent.

Data Protection Officer

[email protected]

Subject access, deletion, NDPA enquiries.

Security disclosures

[email protected]

PGP key on /.well-known/security.txt · 24-hour ack.

Procurement & DPA

[email protected]

Custom DPAs, vendor questionnaires, security reviews.

Need a vendor questionnaire filled out?

Email us the form (Word, PDF, Notion link, anything). We'll complete the security section and return it within 2 business days — included on Growth, Team-with-DPA-addon, and Enterprise.

Send us your questionnaire

See also: Privacy · Terms · Enterprise DPA

9jatesters is a Nigerian company — Ranked Technologies Ltd, registered in Lagos, testing with a Nigerian panel. We self-host on hardware we own and control rather than renting a third-party cloud. For the full data-transfer disclosure, including our sub-processors, see data residency.