Security & compliance
CedarPay is built as a financial system from the ground up. This page describes the controls built into the platform; it is not a claim of any third-party certification.
Two-factor authentication
Mandatory for all CedarPay staff and available to every merchant user.
Secrets never stored in plain text
API secrets are shown once and kept only as a keyed hash. Bank account numbers and authenticator keys are encrypted at rest.
Tamper-evident audit trail
Every sensitive action is logged with who, what, when and from where. Entries are hash-chained so alteration is detectable.
Least-privilege roles
Staff and merchant users only get the permissions their job needs. Financial approvals follow maker-checker rules.
Tenant isolation
Each merchant can only ever see its own data, enforced on the server for every request.
Private document storage
KYC documents are stored outside the web root, type-checked on upload, and every access by staff is recorded.
Responsible disclosure
Found a vulnerability? Email support@example.com with details. Please do not access other merchants' data or disrupt the service.
Regulation
CedarPay is preparing the operator agreements and regulatory approvals that apply to its business model in Uganda. Live processing is enabled only once these are in place.