Your identity documents

Uploaded documents are never public. They go straight from your browser to encrypted storage without passing through the Paynecta application, and they are read back only through a link that expires within minutes and works for one file. Reviewers see them through the same short-lived links, and every time a reviewer opens a submission or a document it is recorded against their name.

Your session

One device at a time

Signing in somewhere new ends the previous session immediately. If someone else signs in as you, you are signed out and will know.

Out of reach of scripts

Your session lives in a cookie the browser will not hand to JavaScript, so a compromised page cannot read it.
Signing out ends the session on our side, not only in your browser. So does resetting your password.

Passwords

Stored only as a slow one-way hash. Nobody at Paynecta can read your password, which is also why nobody at Paynecta will ever ask you for it.
We will never ask for your password, a verification code, or your settlement details by email, phone or message. If you are asked, it is not us. Forward it to support@paynecta.co.ke.

Signing in tells you nothing you did not know

If you mistype an email address at sign-in, the answer is the same as for a wrong password. That is deliberate: a message distinguishing them would tell anyone who asked which addresses have Paynecta accounts.

Reporting something

Found a vulnerability, or seen something that looks wrong? Email support@paynecta.co.ke with what you did and what happened. Please do not test against other people’s businesses.