NC

Naijacloud

Legal

Legal/Security & Data Protection

Security & Data Protection

How the platform is built to protect your workloads, what we have not built yet, and how to report a vulnerability.

Effective 30 August 2026
Version 1.0
Naijacloud Technologies Ltd · RC 8842219

1. Infrastructure

Services run in isolated containers on hardened hosts in colocated facilities in Port Harcourt and London, both with access control, 24/7 staffing and redundant power. Only a small on-call group holds production access, granted per-role and reviewed quarterly.

Managed databases have no public IP address and no public connection string. They are reachable only from services on your private network, and by you through the built-in editor over an authenticated session. That is deliberate: the most common cause of a leaked database is an exposed connection string.

2. Encryption

  • In transit: TLS 1.3 on all public endpoints, with automatic certificates and renewal. Internal service-to-database traffic is TLS-encrypted on the private network.
  • At rest: AES-256 on database volumes, object storage and backups.
  • Secrets: environment variables and secret files are encrypted at rest with envelope encryption and are only decrypted into the running container. Values marked secret are masked in the dashboard and redacted from build logs.

3. Access control

  • Two-factor authentication available on every account, and enforceable workspace-wide.
  • Role-based access per workspace, with per-environment separation between dev, UAT and production.
  • Scoped API and deploy tokens that can be revoked individually.
  • An audit trail of deploys, configuration changes, member changes and editor sessions.

4. Backups and recovery

Managed databases are backed up daily and retained for 7 days on Pro and 30 days on Scale. Object storage is replicated within its region. Restores are self-service from the dashboard and we test them on a schedule.

!

Not available yet

Point-in-time recovery, cross-region database replication and automatic failover are on the roadmap, not in production. Today, recovery from a database failure means a restore to the last daily snapshot, which can mean losing up to 24 hours of writes. If that is unacceptable for your workload, run your own logical backups on a shorter interval, and tell us, because it moves our priorities.

5. Vulnerability disclosure

Report anything you find to [email protected], with a PGP key available on request. We acknowledge within one business day, triage within three, and will keep you updated until it is closed. We will not pursue legal action against good-faith research that avoids customer data, denial of service and social engineering.

We do not run a paid bounty programme yet. We credit reporters publicly with their permission, and we intend to start paying for findings once we can do it properly.

6. Compliance status

We comply with the Nigeria Data Protection Act 2023 and offer a Data Processing Addendum with standard contractual clauses for customers who need one. Write to [email protected] and we will send it.

We are not SOC 2 or ISO 27001 certified. A SOC 2 Type I readiness assessment is planned for 2027. We would rather tell you that plainly than let a trust page imply otherwise; if your procurement process requires a certification today, we are not the right platform for you yet.

Questions about this policy?

We answer legal and privacy mail within five business days.

Email legal →

Naijacloud Technologies Ltd · 14 Aba Road, Port Harcourt, Rivers State, Nigeria. Previous versions of every policy are archived and available on request.