Security

Your data is safe with us

BizTrack is built with security at every layer. Your business finances deserve the same protection as a bank.

TLS 1.2+Encryption in transit
AES-256Encryption at rest
KDPA 2019Compliant
2FAAvailable for all accounts
Audit LogsAll access logged
Security Framework

Six pillars of BizTrack security

Encryption Everywhere

All data in transit is encrypted with TLS 1.2+. Sensitive database fields — financial records, personal identifiers — are encrypted at rest with AES-256.

TLS 1.3 on all endpoints

Password Security

Passwords are hashed using bcrypt with a high work factor. We never store raw passwords. We never ask for your password outside the login screen.

bcrypt hashing

Two-Factor Authentication

Enable 2FA on your account to require a one-time code at every login. Supported via TOTP apps (Google Authenticator, Authy) and SMS.

TOTP + SMS

Access Controls

Role-based access for team members. Each role sees only what they need. All internal access to production data requires MFA and is fully audit-logged.

RBAC + least privilege

Infrastructure Security

Our servers are hosted in ISO 27001-certified data centres. We use separate environments for development, staging, and production — no dev access to live data.

ISO 27001 hosting

Backups & Recovery

Automated daily encrypted backups with point-in-time recovery. Backups are stored in a separate geographic region and tested monthly.

Daily encrypted backups
In Practice

How we protect your account

These are the specific technical measures active on every BizTrack account, every day.

1

Session tokens expire automatically

Web sessions expire after 24 hours of inactivity. Mobile app tokens expire after 30 days and require re-authentication. All sessions are invalidated on password change.

JWT with short expiry + refresh tokens
2

Rate limiting on all login attempts

Failed login attempts trigger progressive delays and CAPTCHA challenges. After 10 consecutive failures, the account is temporarily locked and you receive an SMS alert.

Redis-backed rate limiting
3

M-Pesa PIN never touches BizTrack

When you pay via M-Pesa STK Push, the PIN prompt appears on Safaricom's secure system — not in BizTrack. We receive only the transaction result, never the PIN.

Daraja API v2 STK Push
4

USSD sessions are PIN-protected

Every USSD session requires your 4-digit PIN before any data is shown or recorded. Sessions time out after 30 seconds of inactivity.

Africa's Talking encrypted channel
5

Security incident notifications

If we detect suspicious activity on your account — unusual login location, multiple failed attempts, or a potential breach — we notify you immediately via SMS and email.

Real-time alerts
Responsible Disclosure

Found a security vulnerability?

We take security reports seriously and are grateful to researchers who help us keep BizTrack safe. If you discover a vulnerability, please report it responsibly — we do not pursue legal action against good-faith researchers.

1

Email your findings to security@biztracksme.com with full details and reproduction steps

2

We acknowledge receipt within 24 hours and begin investigation immediately

3

We fix verified issues within 30 days and credit you in our security hall of fame

Report a vulnerability
BizTrack Support
Online • Typically replies in minutes

Hi there! 👋 Please provide your details so we can assist you better.