Skip to main content Scroll Top

Security Policy

Effective Date: 24th/08/2026
Last Updated: 24th/08/2026

1. Introduction

OrzPay is committed to protecting the security, confidentiality and integrity of information entrusted to us by our customers, merchants, partners and other users.

As a digital payment and financial technology platform, we recognize that security is fundamental to maintaining trust and providing reliable payment services.

This Security Policy describes the principles and measures OrzPay applies to help protect its systems, services, information and users from unauthorized access, misuse, loss, alteration and other security threats.

This policy should be read together with our Privacy Policy, Cookie Policy, Terms of Service and AML/KYC Policy.

2. Our Security Commitment

OrzPay takes a security-first approach to the design, operation and improvement of its digital payment services.

We seek to:

  • Protect customer and transaction information.
  • Prevent unauthorized access to systems and accounts.
  • Maintain the integrity and availability of our services.
  • Detect and respond to security threats.
  • Apply appropriate technical and organizational security controls.
  • Continuously improve our security practices as technology and threats evolve.

Where applicable, our security and data protection practices are designed to support compliance with applicable Ugandan laws and regulatory requirements.

Uganda’s Personal Data Protection Office expects organizations handling personal data to implement appropriate technical and organizational measures proportionate to the risks involved and maintain procedures for data-security breaches.

3. Information Security

Depending on the service and circumstances, OrzPay may process information such as:

  • Account information
  • Contact information
  • Identification and verification information
  • Transaction information
  • Payment-related information
  • Device and technical information
  • Authentication information
  • Communication and support records

We apply appropriate safeguards to protect this information against unauthorized access, disclosure, alteration or destruction.

4. Encryption and Secure Communications

OrzPay uses appropriate security technologies and secure communication mechanisms to protect information transmitted between users, applications and our systems.

Where appropriate, information transmitted through our online services and APIs is protected using encryption and secure communication protocols.

Sensitive authentication credentials, API credentials and other security information should never be shared publicly or transmitted through unsecured channels.

5. Account and Access Security

Access to OrzPay systems is controlled according to the responsibilities and authorization levels of users, employees and service providers.

Security controls may include:

  • Authentication mechanisms
  • Access controls
  • Role-based permissions
  • Credential protection
  • Multi-factor authentication where available
  • Session management
  • Monitoring of privileged access
  • Periodic review of access permissions

Users are responsible for maintaining the confidentiality of their account credentials and should immediately report suspected unauthorized access.

6. API and Developer Security

OrzPay provides developer-facing services and API functionality for approved integrations.

Developers and merchants are expected to:

  • Keep API keys and credentials confidential.
  • Never publish private API credentials in public repositories.
  • Use secure server-side environments for sensitive credentials.
  • Validate API responses and transaction status.
  • Use HTTPS for API communications.
  • Implement appropriate authentication controls.
  • Monitor transactions and integration activity.
  • Immediately report suspected credential compromise.

OrzPay may suspend or restrict API access where we reasonably believe that an integration presents a security or fraud risk.

7. Transaction Security

OrzPay uses security controls designed to help protect payment and transaction activities.

Depending on the service, these controls may include:

  • Transaction authentication
  • Risk monitoring
  • Transaction verification
  • Fraud detection mechanisms
  • Activity monitoring
  • Transaction limits
  • Suspicious activity review
  • Account verification

No electronic payment system can be guaranteed to be completely immune from security threats. We therefore continuously review and improve our controls.

8. Security Monitoring

OrzPay may monitor systems, network activity, application activity and transaction activity for security, operational and fraud-prevention purposes.

Monitoring may help us identify:

  • Unauthorized access
  • Suspicious transactions
  • Fraudulent activity
  • Malicious activity
  • System vulnerabilities
  • Abnormal account behavior
  • Attempts to compromise our systems

Where appropriate, suspicious activities may be investigated and reported to relevant authorities or partners in accordance with applicable law.

9. Employee and Third-Party Security

OrzPay seeks to ensure that employees, contractors and relevant third parties who have access to confidential information understand their security responsibilities.

Where appropriate, this may include:

  • Security awareness training
  • Confidentiality obligations
  • Access restrictions
  • Background or due diligence checks where appropriate
  • Secure handling procedures
  • Periodic access reviews

Third-party service providers may be required to maintain appropriate security and confidentiality controls when handling information on behalf of OrzPay.

10. Security Incident Response

OrzPay maintains procedures for identifying, assessing and responding to security incidents.

A security incident may include:

  • Unauthorized access
  • Data exposure
  • Credential compromise
  • Malware or malicious activity
  • System intrusion
  • Loss of confidential information
  • Fraudulent activity
  • Service disruption

When an incident is identified, OrzPay may take appropriate steps including:

  1. Identifying and containing the incident.
  2. Assessing the potential impact.
  3. Securing affected systems.
  4. Investigating the cause.
  5. Taking corrective action.
  6. Notifying affected parties or regulators where required by law.
  7. Implementing measures to reduce the likelihood of recurrence.

Uganda’s data protection framework requires organizations to maintain appropriate breach-response and data-security procedures.

11. Business Continuity

OrzPay seeks to maintain appropriate operational resilience and recovery measures to help ensure continuity of critical services.

Depending on the nature of the service, these measures may include:

  • System backups
  • Monitoring and alerting
  • Recovery procedures
  • Redundancy
  • Disaster recovery planning
  • Business continuity procedures

The specific availability of services may depend on third-party networks, telecommunications providers, financial institutions, payment partners and other infrastructure providers.

12. User Security Responsibilities

Customers and users also play an important role in protecting their accounts.

You should:

  • Keep your password and authentication credentials confidential.
  • Never share OTPs or security codes with another person.
  • Avoid using the same password across multiple services.
  • Keep your devices and applications updated.
  • Avoid accessing financial services through unsecured devices or networks.
  • Review transaction notifications carefully.
  • Report suspicious transactions immediately.
  • Contact OrzPay if you believe your account has been compromised.

OrzPay will never ask you to disclose your password, PIN or full authentication credentials through an unsolicited message.

13. Vulnerability Reporting

If you discover a potential security vulnerability affecting an OrzPay website, application or API, we encourage responsible disclosure.

Please report suspected vulnerabilities through:

Email: security@[orzpay.com / your actual domain]

Please do not publicly disclose a vulnerability before OrzPay has had a reasonable opportunity to investigate and address it.

14. Changes to This Security Policy

OrzPay may periodically update this Security Policy to reflect changes in technology, security practices, services or applicable legal and regulatory requirements.

The latest version will be published on this page.


15. Contact Us

If you have questions regarding this Security Policy or wish to report a security concern, please contact:

OrzPay
Plot 793 Rubaga Road
P.O. Box 3131
Kampala, Uganda

Email: info@orzpay.com