Skip to content

Security

How we protect your account and your money.

Last updated 2 Oct 2026

Money

  • Flutterwave webhooks are checked against our secret hash, then every transaction is re-verified with Flutterwave by id before we credit anything.
  • Ledger writes are idempotent on the Flutterwave transaction id and double-entry: every movement is two or more rows that sum to zero.
  • Payouts go only to name-matched bank or mobile-money accounts; manual payouts above ₦500,000 need two staff approvals.
  • A daily job reconciles our ledger with Flutterwave settlement reports.
  • Funds between payment and release are held with a licensed partner; the ledger records ownership.

Access

  • Every backend function declares the role and tenant it needs through one access wrapper; tenant isolation is tested on every release.
  • Staff use SSO with hardware keys and least-privilege roles. Sensitive actions are written to an append-only audit log, exported weekly.

Edge

  • Cloudflare WAF managed rules, Turnstile on sign-up, login, checkout and AI endpoints, and per-IP and per-user rate limits.
  • Strict security headers: CSP with nonces, HSTS, frame-ancestors none. Secrets live only in Workers secrets.

Report a vulnerability

Email security@schoolxense.ng. We acknowledge within 48 hours.