BizTrack is built with security at every layer. Your business finances deserve the same protection as a bank.
All data in transit is encrypted with TLS 1.2+. Sensitive database fields — financial records, personal identifiers — are encrypted at rest with AES-256.
Passwords are hashed using bcrypt with a high work factor. We never store raw passwords. We never ask for your password outside the login screen.
Enable 2FA on your account to require a one-time code at every login. Supported via TOTP apps (Google Authenticator, Authy) and SMS.
Role-based access for team members. Each role sees only what they need. All internal access to production data requires MFA and is fully audit-logged.
Our servers are hosted in ISO 27001-certified data centres. We use separate environments for development, staging, and production — no dev access to live data.
Automated daily encrypted backups with point-in-time recovery. Backups are stored in a separate geographic region and tested monthly.
These are the specific technical measures active on every BizTrack account, every day.
Web sessions expire after 24 hours of inactivity. Mobile app tokens expire after 30 days and require re-authentication. All sessions are invalidated on password change.
JWT with short expiry + refresh tokensFailed login attempts trigger progressive delays and CAPTCHA challenges. After 10 consecutive failures, the account is temporarily locked and you receive an SMS alert.
Redis-backed rate limitingWhen you pay via M-Pesa STK Push, the PIN prompt appears on Safaricom's secure system — not in BizTrack. We receive only the transaction result, never the PIN.
Daraja API v2 STK PushEvery USSD session requires your 4-digit PIN before any data is shown or recorded. Sessions time out after 30 seconds of inactivity.
Africa's Talking encrypted channelIf we detect suspicious activity on your account — unusual login location, multiple failed attempts, or a potential breach — we notify you immediately via SMS and email.
Real-time alertsWe take security reports seriously and are grateful to researchers who help us keep BizTrack safe. If you discover a vulnerability, please report it responsibly — we do not pursue legal action against good-faith researchers.
Email your findings to security@biztracksme.com with full details and reproduction steps
We acknowledge receipt within 24 hours and begin investigation immediately
We fix verified issues within 30 days and credit you in our security hall of fame
Hi there! 👋 Please provide your details so we can assist you better.