Security & Responsible Disclosure

Effective as of: July 2026 · Last Updated: 10 July 2026

Protecting your money and your personal information is central to how we build Microvest. This page describes the safeguards we use to keep the platform secure, the steps you can take to protect your account, and how security researchers can responsibly report issues to us. It should be read together with our Privacy Policy and AML & KYC Policy.

How we protect your data

We apply multiple layers of protection to keep your information safe, including:

  • Encryption in transit. Information exchanged between the app and our servers is protected with strong, industry-standard encryption rather than being sent as plain text.

  • Encryption at rest on your device. Sensitive information stored on your device, such as your login session and any data cached for offline use, is kept in encrypted form rather than as plain text.

  • Identity verification. We verify users through our AML & KYC checks to reduce fraud and impersonation.

  • Access controls. Access to personal data is restricted to authorised personnel who need it to operate the Services.

  • Monitoring. We monitor accounts and transactions for suspicious activity and act on it.

For security reasons we do not publish the specific technical details of our safeguards. We also recognise that no method of electronic transmission or storage is completely secure, and we work continuously to strengthen our protections.

Account security features

You also have tools to help keep your own account secure:

  • One-time passwords (OTP). We verify sign-up and key actions using one-time codes sent to you.

  • Biometric login. Where your device supports it, you can secure the app with fingerprint or face recognition.

Your role in staying secure

  • Keep your login credentials confidential and never share your password or one-time codes with anyone, including people claiming to be from Microvest.

  • Use a strong, unique password and enable the security features available on your device.

  • Contact us immediately at support@microvest.ng or 070021212121 if you suspect any unauthorised access to your account.

Reporting a vulnerability

If you believe you have found a security vulnerability in our website or app, we encourage you to report it to us responsibly. Please email support@microvest.ng with a description of the issue and clear steps to reproduce it. We ask that you:

  • Give us a reasonable opportunity to investigate and fix the issue before disclosing it publicly;

  • Do not access, modify, or delete data that does not belong to you, and do not degrade or disrupt our Services;

  • Do not use social engineering, phishing, or physical attacks against our staff or infrastructure; and

  • Act in good faith and within the limits of applicable law.

We will acknowledge valid reports, keep you updated as we investigate, and work to resolve confirmed issues promptly. We appreciate the work of the security community in helping keep Microvest and our users safe.