Trust

Security & trust

How we protect this marketing hub — and how product apps handle payments, accounts, and business data.

Last updated: 4 August 2026

HTTPS + HSTS

Content Security Policy

Form abuse controls

Minimal hub data

This website (WaZoBia OS hub)

wazobiaos.com is a marketing, documentation, and routing hub. It does not host product logins, process card payments, or store your accounting data. Security controls below apply specifically to this site.

Transport security

Pages are served over HTTPS. Production responses include Strict-Transport-Security (HSTS) so browsers prefer encrypted connections, plus clickjacking and MIME-sniffing protections.

Content Security Policy

A CSP restricts which scripts, styles, and connections this site may load — reducing the impact of injected third-party content while allowing essential analytics after cookie consent.

Form & API abuse controls

Contact and partner forms use signed short-lived tokens, honeypot fields, same-origin checks, input validation, and rate limiting. Optional Upstash Redis can make limits durable across serverless instances.

What we collect here

Only information you submit through contact or partner forms, optional consent-gated analytics, and standard hosting logs. Secrets (email API keys, form HMAC) stay on the server.

Payments (product apps)

Card and bank collections happen in WaZoBia product applications via payment gateways — not on this marketing hub.

Paystack & Flutterwave

Invoice, Books, and Events redirect users to Paystack or Flutterwave secure checkout for Naira and local-currency payments.

No cards on the OS hub

WaZoBia OS forms do not accept card numbers. Product apps follow gateway practices so card details are not stored on WaZoBia application servers.

Product applications

AES-256 local storage, MFA, RBAC, session cookies, and audit trails apply to WaZoBia Invoice, Books, Events, partner portals, and related apps — not to this static/SSR marketing site.

Access control & sessions

Team roles, admin/agent/ASP portals, HTTP-only session cookies, and (where enabled) admin MFA are implemented in the product codebases and portals.

Encryption & device security

Features such as AES-256 local-first storage and PIN/biometrics are Invoice (and related) app capabilities. Verify current details on each product’s own security or privacy documentation.

Compliance features

NDPR/NDPA alignment, tax workflows in Books, and product audit trails are designed into the applications. Contact us for data-subject requests relating to data we hold.

Hosting

This hub is deployed on Vercel edge infrastructure with automatic HTTPS and isolated serverless API routes.

Edge platform

Vercel provides TLS termination, DDoS protections at the edge, and environment-isolated deployments for production secrets.

Upstream product data

Partner lists and some stats are proxied from the Invoice platform API. Product databases and Redis (e.g. Upstash for portals) live outside this repository.

Common questions

Does WaZoBia OS (this website) store my payment card details?
No. This site is a marketing and navigation hub. Payments happen in product apps via Paystack or Flutterwave under their PCI-compliant checkout flows.
Are AES-256, MFA, and role-based access implemented on wazobiaos.com?
Those controls describe WaZoBia product apps and portals. This hub focuses on HTTPS/HSTS, CSP, validated forms with bot defenses, and minimal data collection.
Where is my Invoice business data stored?
Primarily according to the Invoice product model (including local-first options). Portal and cloud features follow that product’s privacy policy — not this hub.
How do I report a security concern?
Email security@wazobiaos.com or support@wazobiaos.com with details. We take responsible disclosure seriously and will respond as quickly as possible.

Related policies

Read our Privacy Policy, Terms of Service, and product-specific policies on WaZoBia Invoice and WaZoBia Books.

Questions? admin@wazobia-books.ng

Security & Trust · WaZoBia OS