Trust & Security

Your data.
Handled properly.

QUAYLINE runs your agency's most sensitive workflow: client approvals and disbursement accounts. Here's exactly how we protect it — no vague promises, just what's actually built in.

The numbers
12/12
Pen test checks passed
100%
Tables with row-level security
Every
Action logged, timestamped

How your data is protected

01

Row-level security

Every table in the database enforces row-level security. One agency's data is never visible to another, at the database layer — not just in the app code.

02

Independent penetration testing

QUAYLINE was tested against 12 real attack scenarios: cross-tenant data access, session hijacking, unauthorized API calls, and more. All 12 passed before launch.

03

Full audit trail

Every approval, edit, and disbursement action is recorded — who did it, what changed, and when. Nothing is silent.

04

Two-factor login

Every single login requires a 6-digit code sent to your email, on top of your password. No exceptions, no "remember this device."

05

Rate limiting

Login and sensitive actions are rate-limited. Repeated wrong attempts get blocked automatically, stopping brute-force attacks before they get anywhere.

06

Locked-down infrastructure

HTTPS enforced everywhere, secure HttpOnly session cookies, and strict security headers blocking common attack vectors by default.

Built on Africa-first principles

Questions about security?

Talk to us directly before you sign up. We'll walk you through anything on this page in detail.

hello@quayline.africa