How we protect your account, your money, and your data.
Security is not an afterthought at Electrik.NG — it is built into every layer of the platform, from how we store your password to how we verify payment webhooks. This page describes the measures we take and what you can do to keep your account secure.
All traffic between your browser and our servers uses TLS 1.2 or higher. Connections over plain HTTP are automatically redirected to HTTPS.
Passwords are hashed using PBKDF2 with a random per-user salt. We never store or have access to your plain-text password.
Card numbers, CVVs, and bank credentials are processed entirely by Paystack (PCI DSS compliant). They never touch our servers.
Every form submission is protected by an anti-forgery token. Requests without a valid token are rejected before any action is taken.
Paystack and WhatsApp webhook payloads are verified using HMAC-SHA256 signatures before any funds are moved or tokens are delivered.
WhatsApp phone numbers are stored only as SHA-256 hashes. We cannot reverse the hash to recover your original number.
All third-party API keys are encrypted at rest using ASP.NET Core Data Protection and are only decrypted inside isolated service components.
Login and registration endpoints are rate-limited per IP to prevent brute-force and credential stuffing attacks.
All administrative actions are recorded in a tamper-evident audit log with actor ID, timestamp, and IP address.
electrik.ng before entering your login credentials or payment details. We will never ask for your password by email or SMS.@electrik.ng domain. Any email claiming to be from Electrik.NG from another domain is fraudulent — do not click any links in it.We welcome responsible disclosure from security researchers and the wider community. If you discover a vulnerability in our platform, please report it privately so we can fix it before it is exploited.
We will credit researchers who responsibly disclose valid vulnerabilities, where they wish to be credited.
To report a security issue: security@electrik.ng
For general account security concerns: support@electrik.ng