• Security

Security is
our infrastructure.

Every payment Payonus processes is protected by multiple independent layers of security — from the moment a transaction is initiated to the moment funds settle.

AES-256

Encryption at rest

TLS 1.3

Encryption in transit

99.9%

Uptime SLA

< 50 ms

Risk engine response

— Compliance & Certifications

Built to meet the
highest standards.

PCIDSS Level 1

Payment Card Industry

Payonus is PCIDSS Level 1 certified — the highest tier of card payment security, verified by a qualified security assessor.

ISO 27001

Information Security

Our Information Security Management System (ISMS) is aligned with ISO 27001, governing how we manage and protect sensitive data.

NDPC Trust Mark

Nigeria Data Protection

Payonus holds the NDPC Trust Mark and is registered with the Nigeria Data Protection Commission as a data controller and processor.

CBN Licensed

Via Paylode Services Limited

Payonus is a product of Paylode Services Limited, a Central Bank of Nigeria licensed Payment Service Solution Provider, holding it to the highest regulatory standards in Nigeria.

TLS 1.3

Encryption in Transit

All data in transit is encrypted using TLS 1.3. Older protocol versions are rejected at the network edge — no exceptions.

— 01

Data Protection

Encryption at rest

All stored data is encrypted with AES-256. Encryption keys are managed through a dedicated KMS with strict rotation policies — your data is never stored in plaintext.

Tokenisation

Sensitive account numbers and card details are immediately replaced with opaque tokens at the point of entry. The raw value never touches our application layer.

Data residency

Customer data is stored and processed within African data centres by default. Cross-border transfers comply with applicable data localisation rules.

Data minimisation

We collect only what is necessary to process a transaction. No behavioural profiling, no selling of data to third parties — ever.

— 02

Infrastructure Security

Cloud-native hardening

Our infrastructure runs on enterprise-grade cloud providers with VPC isolation, private subnets, and no public-facing databases. All services are behind managed API gateways.

DDoS & WAF protection

Distributed denial-of-service mitigation and a Web Application Firewall operate at the network edge, filtering malicious traffic before it reaches application servers.

Independent penetration testing

We engage independent third-party security firms to conduct penetration tests at least once per year. Critical findings are remediated within 72 hours.

99.9% uptime SLA

Our architecture uses multi-region failover, automated health checks, and circuit breakers. System status is published in real time at status.payonus.com.

— 03

Access & Identity

Zero-trust access model

Every internal service call is authenticated and authorised. No service is implicitly trusted by virtue of being inside the network perimeter.

MFA enforced company-wide

Multi-factor authentication is mandatory for every Payonus employee and contractor — no exceptions. Privileged access requires hardware security keys.

Least-privilege principle

Access to production systems is granted on a need-to-know basis and reviewed quarterly. Engineers do not have standing access to production data.

Background checks

All employees and contractors with access to financial data undergo background verification before their first day.

— 04

Fraud & Risk

Real-time monitoring

Every transaction is evaluated by our risk engine in under 50ms. Suspicious patterns trigger instant holds and alerts without interrupting legitimate payments.

Velocity & anomaly checks

We apply velocity rules, geolocation checks, and behavioural baselines to detect account takeover, card testing, and money mule patterns.

Chargeback management

Merchants are notified immediately on dispute creation and provided with evidence bundles to support representments. Average dispute resolution time: 72 hours.

KYC & AML programme

Our compliance team enforces Know Your Customer and Anti-Money Laundering controls aligned with GIABA and FATF recommendations.

— Responsible Disclosure

Found a
vulnerability?

We welcome responsible security research. If you discover a potential vulnerability in Payonus systems, please report it to us privately before public disclosure. We commit to:

  • Acknowledge your report within 24 hours
  • Provide a timeline for investigation and fix
  • Keep you informed throughout the process
  • Give credit in our security acknowledgements
Report to security@payonus.com

In scope

payonus.com and subdomains
Payonus merchant dashboard
Public REST API endpoints
Mobile applications (iOS & Android)
Authentication and authorisation flows

Out of scope

Social engineering and phishing attacks
Denial-of-service or load testing
Third-party services not under our control
— Common Questions

Security FAQs.

Payonus is a product of Paylode Services Limited, a Central Bank of Nigeria licensed Payment Service Solution Provider. Payonus is certified under ISO 27001, PCIDSS Level 1, and the NDPC Trust Mark. These certifications represent the highest standards of financial and data security compliance in the industry.

All transaction data is encrypted end-to-end using AES-256 and TLS 1.2+. Our infrastructure is ISO 27001 certified, and we undergo regular third-party penetration testing. No unencrypted card data is ever stored on our systems.

We follow a documented incident response plan. Affected customers are notified within 72 hours of confirmation in accordance with NDPC requirements. A post-incident report is published for significant events, and we work swiftly to contain, remediate, and prevent recurrence.

API keys are hashed before storage using a one-way function — we cannot recover them. Secrets are managed through a dedicated secrets manager with audit logging on every read. Key rotation is available on demand from your dashboard.

Transaction records are retained for 7 years to meet CBN and NDPC regulatory requirements. All other data is deleted within 30 days of account closure. You can request immediate deletion of non-regulatory data at any time by contacting compliance@payonus.com.

Security questions
for your team?

Our security team reviews every enterprise onboarding. Send your questionnaire, request our latest pen-test report, or ask about our DPA — we respond within one business day.

Contact Security TeamGeneral Support
Related:ISMS Policy →API Documentation →Fintech →