Trust & Safety

Security at CoopOS

Your members' financial data and cooperative records deserve the highest level of protection. Security is not a feature — it's the foundation everything we build is built on.

Last updated: July 23, 2026

Security Pillars

How We Protect Your Cooperative Data

CoopOS employs multiple layers of security controls to protect member data, financial records, and cooperative operations at all times.

Encryption at Rest & In Transit

All data transmitted to and from CoopOS is encrypted using TLS 1.2/1.3. Data stored on our servers — including member records, loan data, and financial ledgers — is encrypted at rest using AES-256 industry-standard encryption.

Multi-Factor Authentication (MFA)

CoopOS supports and encourages multi-factor authentication for all administrator accounts. MFA adds an extra layer of identity verification, significantly reducing the risk of unauthorized access even if credentials are compromised.

Least-Privilege Access Controls

We enforce role-based access control (RBAC) throughout the platform. Users only see and interact with data relevant to their role — whether they are cooperative officers, loan officers, accountants, or administrators.

Secure Cloud Infrastructure

CoopOS is hosted on enterprise-grade cloud infrastructure with redundant systems, automatic failover, and geographic data replication. Our infrastructure providers maintain SOC 2 Type II and ISO 27001 certifications.

Vulnerability Management

We conduct regular vulnerability assessments and penetration testing of our platform. Critical vulnerabilities are patched within 24 hours. Our security team monitors for emerging threats and applies security updates proactively.

Automated Backups

Cooperative data is backed up automatically on a daily basis, with point-in-time recovery capabilities. Backup integrity is tested regularly to ensure data can be restored quickly in the event of an incident.

Organisational Security

People, Process & Policies

Technical controls are only as strong as the people and processes that support them. At Toplorgical, we take a holistic approach to security — combining engineering rigour with team training, clear policies, and a security-first culture.

All employees who have access to production systems undergo background checks, sign data access agreements, and complete mandatory annual security training. Access is revoked immediately upon offboarding.

Security awareness training for all Toplorgical employees with access to production systems

Strict onboarding and offboarding procedures for staff accessing customer data

Formal incident response plan with defined escalation paths and notification timelines

Separation of duties between development, operations, and security teams

Regular third-party security audits and code reviews

Dedicated security bug bounty program for responsible disclosure

All production access logged and monitored in real-time

Continuous monitoring with automated anomaly detection and alerting

Compliance

Regulatory Compliance

CoopOS and Toplorgical Nigeria Limited operate in accordance with applicable Nigerian laws and international data protection standards.

Nigeria Data Protection Act (NDPA)

CoopOS and Toplorgical Nigeria Limited comply with the NDPA, which governs the collection, storage, processing, and transfer of personal data for individuals in Nigeria.

NDPR (Nigeria Data Protection Regulation)

We adhere to the requirements of the NDPR, including data subject rights, breach notification obligations, and the appointment of a Data Protection Officer.

PCI-DSS Compliance for Payments

Payment card data is never stored directly on CoopOS servers. We use PCI-DSS Level 1 compliant payment processors to handle all card transactions securely.

Cooperative Regulations (Nigeria)

CoopOS is designed to support compliance with the Co-operative Societies Act and related state regulations, including audit trail requirements, governance records, and member rights.

Incident Response

What Happens If Something Goes Wrong?

Despite our best efforts, no system is immune to all risks. We have a comprehensive incident response plan in place to ensure we respond swiftly, transparently, and effectively to any security event.

01

Detection

Automated monitoring systems detect anomalies and alert our on-call security team 24/7.

02

Containment

The affected systems or accounts are isolated immediately to limit the scope of any incident.

03

Notification

Affected cooperative administrators are notified within 72 hours of confirming a data breach, in compliance with the NDPA.

04

Remediation & Review

Root cause analysis is conducted, the vulnerability is patched, and a post-incident report is prepared.

Responsible Disclosure

If you believe you have discovered a security vulnerability in CoopOS, we encourage you to report it to us responsibly. We are committed to working with security researchers to verify and address any vulnerabilities promptly.

Please include in your report:

  • A clear description of the vulnerability and its potential impact
  • Steps to reproduce the issue
  • Any proof-of-concept code or screenshots

Send your report to:

security@toplorgical.com

We will acknowledge receipt within 24 hours and provide a more detailed response within 5 business days. We kindly ask that you do not publicly disclose the vulnerability until we have had the opportunity to address it. We do not pursue legal action against researchers who report vulnerabilities in good faith.

Security Questions?

For general security-related questions or to enquire about our data protection practices, reach out to our team directly.

Toplorgical Nigeria Limited

Security Team: security@toplorgical.com

Data Protection: dataprotection@toplorgical.com

Address: Suite F306, Ogba Central Mall, Lagos, Nigeria

Still have questions about our policies?

Our compliance and legal teams are here to help. Reach out to us for any clarifications.