Security & Compliance

Aftoria employs enterprise-grade security practices to ensure data confidentiality, integrity, and availability.

Encryption

All traffic between users, merchants, and Aftoria servers is protected through HTTPS with TLS 1.2+ encryption.

Infrastructure Security

The system architecture is hosted on AWS using Virtual Private Cloud (VPC) isolation, encrypted storage (AES-256), and multi-factor authentication for administrative access.

PCI DSS Compliance

Aftoria follows the PCI DSS Self-Assessment Questionnaire A (SAQ-A) model, as the platform never stores or processes cardholder data directly — payments are routed exclusively through the hosted pages of licensed PSPs such as Paystack, Flutterwave, and Stripe.

Security Measures

  • Regular security scans, webhook signature verification, and audit logging are maintained to detect and prevent unauthorized access.
  • All employees and contractors are required to follow data protection best practices and confidentiality agreements.

Data Protection

Aftoria complies with the General Data Protection Regulation (GDPR) and the Nigerian Data Protection Act (NDPA).

For security concerns, contact support@aftoria.io.