Trust and compliance, built into the platform.

Gigva protects financial transaction data with Kenya-hosted infrastructure, encryption, role-based access and clear audit trails.

Kenya-hosted data

Customer transaction data is stored on servers physically located in Kenya and handled under the Kenya Data Protection Act 2019.

Encryption and transport

Gigva uses AES-256 encryption at rest, TLS 1.3 in transit, and encrypted storage for sensitive Daraja credentials.

Access control and audit trails

Role-based access, MFA for sensitive systems, access logs, data modification logs and 12-month audit retention support accountable operations.

Reliable webhook processing

C2B webhook events are processed with idempotency safeguards so duplicate deliveries do not create duplicate transaction records.

Responsible disclosure

Security reports go to [email protected] and are investigated promptly with resolution timelines communicated for valid reports.

API Gateway

API Gateway is monitored continuously and currently marked operational.

Daraja Integration

Daraja Integration is monitored continuously and currently marked operational.

Webhook Engine

Webhook Engine is monitored continuously and currently marked operational.

Reconciliation Engine

Reconciliation Engine is monitored continuously and currently marked operational.

Database (KE)

Database (KE) is monitored continuously and currently marked operational.

Report Generator

Report Generator is monitored continuously and currently marked operational.

Auth Service

Auth Service is monitored continuously and currently marked operational.

Email Delivery

Email Delivery is monitored continuously and currently marked operational.