Built for procurement reviewers, not just product managers
NDPR/NDPA aligned. Primary data self-hosted on hardware we own — no hyperscaler — with TLS 1.3 in transit. Audit log on every privileged action. Below is the answer to every question a Lagos fintech buyer will ask before signing.
Last reviewed 28 August 2026 · Annual review cycle · [email protected]
NDPR + NDPA 2023 aligned
We process Nigerian personal data under the Nigeria Data Protection Regulation and the Nigeria Data Protection Act 2023. Data Protection Officer correspondence: [email protected].
Real Nigerians, not panels or proxies
Tests are run by real people on real Nigerian phones and networks — no emulators, no VPNs, no synthetic personas. Payout bank details are stored because Nigerian transfers require the real account number; only the last 4 digits ever appear in the product, they are never shared with clients or data buyers, and a separate HMAC-SHA256 hash (server-side pepper) is used for duplicate detection.
Encrypted in transit, self-hosted on our own hardware
TLS 1.3 enforced on every endpoint with HSTS (Strict-Transport-Security: max-age=63072000); Cloudflare terminates TLS at its edge and proxies to our origin server. Primary data — accounts, payout-account hash, payout data, session recordings — is stored on hardware the company owns and controls: not AWS, not Google Cloud, not Azure, not any hyperscaler. Application secrets are held on that same infrastructure, not in any third-party hosting dashboard.
Audit trail on every state change
Every payout, demo review, and admin action writes a row to audit_log with actor, action, entity, and structured metadata. Queryable for incident forensics.
Controls
The day-to-day controls our auditor would care about
Identity & access
Email one-time code (OTP) via our self-hosted authentication stack — passwordless by design, no password to leak.
Service-to-service auth via short-lived JWTs scoped per role (tester / client / admin).
Postgres row-level security policies on every multi-tenant table.
Admin actions gated by a separate role flag, not just a user setting.
Panel integrity: every tester is bank-account verified, and since 28 August 2026 every new tester also attaches a work or education proof (CV, student ID or certificate) reviewed by a person before specialist work unlocks.
Data handling
Payout bank-account number: we do store it. Paying a Nigerian bank account requires the real number at transfer time, so the payout destination is held in our own database as bank code + account number. Only the last 4 digits are ever shown in the product, and the number is never shared with clients or AI-data buyers. A separate HMAC-SHA256(value, pepper) hash is kept for duplicate-account detection.
Session-recording video files: stored on local disk on our own server and served only through authenticated, ownership-checked streaming proxies — never a public URL.
Backups: nightly encrypted database snapshots (pg_dump) with ~14-day retention, plus — since 28 August 2026 — a nightly AES-256-encrypted off-site copy of the database and the consented data corpus, with the encryption key held offline and a restore drill performed and verified the day the leg shipped.
A Data Protection Impact Assessment and a Record of Processing Activities are maintained (last updated 28 August 2026) and a Data Protection Officer is designated. Procurement reviewers can request both under NDA at [email protected].
Incident response
Notify affected users within 72 hours of confirmed breach (NDPA s.40 compliant).
Audit log preserved for 7 years for forensic + AML reconstruction (matches Retention below).
Status page (status.9jatesters.com) for transparency on operational incidents.
Retention
Personal data on account closure: deleted within 90 days. Mirrors /privacy section 6.
Session recordings: 90 days after client approval, then deleted unless retained on contract.
Test transcripts + summaries: kept for the lifetime of the parent client account, deletable on request.
payout-account hash + audit-log entries: 7 years post-account-closure (CBN anti-money-laundering + Nigerian tax-record-keeping). Export available on request.
Anonymised, non-re-identifiable aggregate metrics: may be retained indefinitely.
Sub-processors
The services we use to run 9jatesters
We notify Enterprise customers 30 days before adding or changing a sub-processor that handles personal data. Click any row to read the provider's own privacy policy.
Provider
Purpose
Region
Data
CloudflareCDN, DDoS protection, and the secure tunnel that exposes our self-hosted app to the internet. Terminates TLS at the global edge and proxies requests to our origin server.
CDN, DDoS protection, and the secure tunnel that exposes our self-hosted app to the internet. Terminates TLS at the global edge and proxies requests to our origin server.
HQ United States; edge: global anycast.
In-flight request metadata (IP, headers, URL) transiting the edge. Does not persistently store our users' data.
FlutterwavePayment processing for client billing, plus bank account name resolution for tester payouts.
Payment processing for client billing, plus bank account name resolution for tester payouts.
Nigeria (Flutterwave PCI-DSS compliant, CBN-licensed). Payments are processed inside Nigeria.
bank account number, account name, transfer reference, client billing details.
ResendTransactional email delivery — login one-time codes (OTP) and receipts. DKIM-signed on our verified domain.
Transactional email delivery — login one-time codes (OTP) and receipts. DKIM-signed on our verified domain.
US.
Recipient email address and message content.
country.isIP-to-country lookup for display only. Never used for gating.
IP-to-country lookup for display only. Never used for gating.
Global anycast.
Request IP used transiently to compute an ISO 3166-1 alpha-2 country code; raw IP not persisted by us.
FAQ
Things procurement teams ask
Do you have SOC 2 / ISO 27001?
Not certified yet — we're a 2026 startup. We operate to SOC-2-aligned controls (access, encryption, audit logging, incident response, change management) and have started a Vanta-style continuous-monitoring trial to evidence those controls for procurement reviews. Pursuing Type II once revenue justifies the audit cost (~$15-25K/yr). For enterprise contracts we sign a custom DPA with the practical equivalents and walk procurement through our controls live on a call. Procurement reviewers can request a control evidence pack at [email protected] — typically a 24-hour turnaround.
Where does our data live?
On hardware we own and control — our own server, not AWS, Google Cloud, Azure, or any other third-party cloud. That infrastructure runs the Postgres database (accounts, payout-account hash, payouts, session metadata), the self-hosted authentication stack, the session-recording video files, and the Next.js application. Payment data flows through Flutterwave's PCI-DSS compliant, CBN-licensed environment in Nigeria. For the full data-transfer disclosure — including the transient touchpoints, Cloudflare edge routing and Mailtrap email delivery — see /trust/data-residency.
Can you sign a DPA?
Yes — for Growth, Team-with-DPA-addon, and Enterprise tiers we sign a standard Data Processing Agreement covering NDPR roles (controller/processor), sub-processor change notification, deletion timelines, and breach reporting. Request via [email protected].
What if a tester asks to delete their data?
Per NDPA Article 32 we honour deletion within 30 days. Payout-account hash is removed, video files purged from storage, profile rows tombstoned. Audit-log rows are retained (for fraud-prevention legal-basis) but the user-id link is anonymised. Email [email protected].
Do you train AI on our data?
No. We never use a client's session data to train any model. Primary data — including session recordings — stays on our own self-hosted infrastructure and is not handed to a third party for model training.
How do we report a vulnerability?
[email protected] (PGP key on /.well-known/security.txt). We aim to acknowledge within 24 hours and remediate critical issues within 30 days. We don't run a paid bug-bounty yet but credit researchers publicly with their consent.
Email us the form (Word, PDF, Notion link, anything). We'll complete the security section and return it within 2 business days — included on Growth, Team-with-DPA-addon, and Enterprise.
9jatesters is a Nigerian company — Ranked Technologies Ltd, registered in Lagos, testing with a Nigerian panel. We self-host on hardware we own and control rather than renting a third-party cloud. For the full data-transfer disclosure, including our sub-processors, see data residency.