Trust

Security you can verify.

ScanAcc was designed so the worst-case breach is harmless. We never touch customer card data, never hold bank login credentials, and never move money. Here's exactly how the system is built.

Zero sensitive customer data

No card numbers, CVVs, PINs, OTPs or BVNs ever enter ScanAcc. Customers pay directly from their own bank app.

Money never flows through us

ScanAcc displays your account number. Transfers go straight from the customer's bank to yours — we are not a payment processor.

Encryption everywhere

TLS 1.3 in transit, AES-256 at rest. All credentials are hashed with industry-standard algorithms.

Row-level data isolation

Every database query is enforced at the row level. A business can only ever read or modify its own profile — verified by automated policy tests.

Service keys stay server-side

Privileged service keys never ship in browser bundles. Admin operations run only inside verified server handlers.

Rate-limited & deduplicated

Scan analytics are rate-limited per IP and deduplicated by a one-way hash — preventing scan-spam from inflating any business's metrics.

No tracking, no resale

We do not sell your data, do not run ad trackers, and do not share analytics with third parties.

NDPA & NDPR aligned

Built to comply with the Nigeria Data Protection Act 2023 and the NDPR — including data subject rights, lawful basis and retention limits.

What a "ScanAcc breach" would actually expose

In the unlikely event of unauthorized access, the only data at risk is information you've already chosen to make public: your business name, your handle, and your bank account number — the same details you would print on a receipt or paste on a wall. Customer payment data is structurally impossible to leak because it never enters our system.

Responsible disclosure

Found a security issue? Email nuuxperience@gmail.com with the subject "Security Disclosure". Please do not publicly disclose until we've had a chance to fix it. We acknowledge within 24 hours.