Trust & Safety

NaliGrid Security Infrastructure

We implement enterprise-grade row-level database security, server-validated gateways, and strict authorization protocols.

1. Row-Level Access Controls

Every data row in our application database is protected by strict row-level access control policies:

  • Planners can only read and write data belonging to their registered organization.
  • Coordinators can only read events and tasks they are explicitly invited or assigned to.
  • Client portals are secured using secure cryptographic tokens, preventing enumeration attacks.

2. Server-Side Payment Verification

To prevent unauthorized manipulation of budget records and event states, we enforce database-level access rules. Direct client-side requests attempting to modify payment statuses are blocked by database constraints. All payments must be verified secure server-to-server via API callbacks using private signing keys.

3. Secret Key Protection

All integration keys are handled with industry-standard protection models. Private API keys for integrated services (such as Resend, Paystack, and Korapay) are never exposed to the client browser or client-side application logs. Secrets are stored encrypted in a secure vault and are only injected at runtime into isolated server environments.

4. Escrow Fund Security

Vendor advances and deposit records are secured against unauthorized transfers. Payout triggers require dual validation (Planner authorization plus system constraint checks) before disbursement commands are sent to gateway settlement endpoints.

Notifications
No notifications yet

We use cookies and local storage to keep you logged in and remember your preferences. We also use analytics tools to improve our service.