Kenya-hosted data
Customer transaction data is stored on servers physically located in Kenya and handled under the Kenya Data Protection Act 2019.
Gigva protects financial transaction data with Kenya-hosted infrastructure, encryption, role-based access and clear audit trails.
Customer transaction data is stored on servers physically located in Kenya and handled under the Kenya Data Protection Act 2019.
Gigva uses AES-256 encryption at rest, TLS 1.3 in transit, and encrypted storage for sensitive Daraja credentials.
Role-based access, MFA for sensitive systems, access logs, data modification logs and 12-month audit retention support accountable operations.
C2B webhook events are processed with idempotency safeguards so duplicate deliveries do not create duplicate transaction records.
Security reports go to [email protected] and are investigated promptly with resolution timelines communicated for valid reports.
API Gateway is monitored continuously and currently marked operational.
Daraja Integration is monitored continuously and currently marked operational.
Webhook Engine is monitored continuously and currently marked operational.
Reconciliation Engine is monitored continuously and currently marked operational.
Database (KE) is monitored continuously and currently marked operational.
Report Generator is monitored continuously and currently marked operational.
Auth Service is monitored continuously and currently marked operational.
Email Delivery is monitored continuously and currently marked operational.