Trust
Security you can verify.
ScanAcc was designed so the worst-case breach is harmless. We never touch customer card data, never hold bank login credentials, and never move money. Here's exactly how the system is built.
Zero sensitive customer data
No card numbers, CVVs, PINs, OTPs or BVNs ever enter ScanAcc. Customers pay directly from their own bank app.
Money never flows through us
ScanAcc displays your account number. Transfers go straight from the customer's bank to yours — we are not a payment processor.
Encryption everywhere
TLS 1.3 in transit, AES-256 at rest. All credentials are hashed with industry-standard algorithms.
Row-level data isolation
Every database query is enforced at the row level. A business can only ever read or modify its own profile — verified by automated policy tests.
Service keys stay server-side
Privileged service keys never ship in browser bundles. Admin operations run only inside verified server handlers.
Rate-limited & deduplicated
Scan analytics are rate-limited per IP and deduplicated by a one-way hash — preventing scan-spam from inflating any business's metrics.
No tracking, no resale
We do not sell your data, do not run ad trackers, and do not share analytics with third parties.
NDPA & NDPR aligned
Built to comply with the Nigeria Data Protection Act 2023 and the NDPR — including data subject rights, lawful basis and retention limits.
What a "ScanAcc breach" would actually expose
In the unlikely event of unauthorized access, the only data at risk is information you've already chosen to make public: your business name, your handle, and your bank account number — the same details you would print on a receipt or paste on a wall. Customer payment data is structurally impossible to leak because it never enters our system.
Responsible disclosure
Found a security issue? Email nuuxperience@gmail.com with the subject "Security Disclosure". Please do not publicly disclose until we've had a chance to fix it. We acknowledge within 24 hours.