End-to-End Encryption
All data transmitted between devices and KolectPay is encrypted using TLS 1.3 with HSTS. Sensitive customer records and gateway credentials are encrypted at rest with AES-256 GCM.
Non-Custodial PSP Model
All payment collections and settlements are processed directly by our regulated partner, IT Consortium Ltd, fulfilling all Bank of Ghana regulatory requirements. We never hold your funds directly.
Ghana Card KYC Verification
Every business registrant undergoes automated identity verification against National Identification Authority (NIA) records, ensuring legitimate merchant accounts across the ecosystem.
Two-Factor Authentication (2FA)
Time-based One-Time Password (TOTP) 2FA via Google Authenticator protects merchant accounts and sensitive settlement operations against credential stuffing and brute-force attacks.
Multi-Tenant Isolation
Strict database scoping isolates merchant data completely. Role-based permissions ensure that staff members and administrators access only explicitly authorized resources.
Customer Mandate Consent
Funds are only debited with explicit prior customer consent via secure USSD or MoMo OTP approval. Direct debits without authorized mandates are strictly blocked.
Regulatory Compliance in Ghana
Our operations comply with the Data Protection Act, 2012 (Act 843), the Payment Systems and Services Act, 2019 (Act 987) under Bank of Ghana supervision, and the Cybersecurity Act, 2020 (Act 1038).
Responsible Disclosure
If you identify a potential security issue, please contact our security team at security@kolectpay.com or via our Contact Form. We respond to all verified security reports within 24 hours.