Security at CoopOS
Your members' financial data and cooperative records deserve the highest level of protection. Security is not a feature — it's the foundation everything we build is built on.
Last updated: July 23, 2026
How We Protect Your Cooperative Data
CoopOS employs multiple layers of security controls to protect member data, financial records, and cooperative operations at all times.
Encryption at Rest & In Transit
All data transmitted to and from CoopOS is encrypted using TLS 1.2/1.3. Data stored on our servers — including member records, loan data, and financial ledgers — is encrypted at rest using AES-256 industry-standard encryption.
Multi-Factor Authentication (MFA)
CoopOS supports and encourages multi-factor authentication for all administrator accounts. MFA adds an extra layer of identity verification, significantly reducing the risk of unauthorized access even if credentials are compromised.
Least-Privilege Access Controls
We enforce role-based access control (RBAC) throughout the platform. Users only see and interact with data relevant to their role — whether they are cooperative officers, loan officers, accountants, or administrators.
Secure Cloud Infrastructure
CoopOS is hosted on enterprise-grade cloud infrastructure with redundant systems, automatic failover, and geographic data replication. Our infrastructure providers maintain SOC 2 Type II and ISO 27001 certifications.
Vulnerability Management
We conduct regular vulnerability assessments and penetration testing of our platform. Critical vulnerabilities are patched within 24 hours. Our security team monitors for emerging threats and applies security updates proactively.
Automated Backups
Cooperative data is backed up automatically on a daily basis, with point-in-time recovery capabilities. Backup integrity is tested regularly to ensure data can be restored quickly in the event of an incident.
People, Process & Policies
Technical controls are only as strong as the people and processes that support them. At Toplorgical, we take a holistic approach to security — combining engineering rigour with team training, clear policies, and a security-first culture.
All employees who have access to production systems undergo background checks, sign data access agreements, and complete mandatory annual security training. Access is revoked immediately upon offboarding.
Security awareness training for all Toplorgical employees with access to production systems
Strict onboarding and offboarding procedures for staff accessing customer data
Formal incident response plan with defined escalation paths and notification timelines
Separation of duties between development, operations, and security teams
Regular third-party security audits and code reviews
Dedicated security bug bounty program for responsible disclosure
All production access logged and monitored in real-time
Continuous monitoring with automated anomaly detection and alerting
Regulatory Compliance
CoopOS and Toplorgical Nigeria Limited operate in accordance with applicable Nigerian laws and international data protection standards.
Nigeria Data Protection Act (NDPA)
CoopOS and Toplorgical Nigeria Limited comply with the NDPA, which governs the collection, storage, processing, and transfer of personal data for individuals in Nigeria.
NDPR (Nigeria Data Protection Regulation)
We adhere to the requirements of the NDPR, including data subject rights, breach notification obligations, and the appointment of a Data Protection Officer.
PCI-DSS Compliance for Payments
Payment card data is never stored directly on CoopOS servers. We use PCI-DSS Level 1 compliant payment processors to handle all card transactions securely.
Cooperative Regulations (Nigeria)
CoopOS is designed to support compliance with the Co-operative Societies Act and related state regulations, including audit trail requirements, governance records, and member rights.
What Happens If Something Goes Wrong?
Despite our best efforts, no system is immune to all risks. We have a comprehensive incident response plan in place to ensure we respond swiftly, transparently, and effectively to any security event.
Detection
Automated monitoring systems detect anomalies and alert our on-call security team 24/7.
Containment
The affected systems or accounts are isolated immediately to limit the scope of any incident.
Notification
Affected cooperative administrators are notified within 72 hours of confirming a data breach, in compliance with the NDPA.
Remediation & Review
Root cause analysis is conducted, the vulnerability is patched, and a post-incident report is prepared.
Responsible Disclosure
If you believe you have discovered a security vulnerability in CoopOS, we encourage you to report it to us responsibly. We are committed to working with security researchers to verify and address any vulnerabilities promptly.
Please include in your report:
- A clear description of the vulnerability and its potential impact
- Steps to reproduce the issue
- Any proof-of-concept code or screenshots
Send your report to:
We will acknowledge receipt within 24 hours and provide a more detailed response within 5 business days. We kindly ask that you do not publicly disclose the vulnerability until we have had the opportunity to address it. We do not pursue legal action against researchers who report vulnerabilities in good faith.
Security Questions?
For general security-related questions or to enquire about our data protection practices, reach out to our team directly.
Toplorgical Nigeria Limited
Security Team: security@toplorgical.com
Data Protection: dataprotection@toplorgical.com
Address: Suite F306, Ogba Central Mall, Lagos, Nigeria
Still have questions about our policies?
Our compliance and legal teams are here to help. Reach out to us for any clarifications.