AzmaPredict Tech Limited takes the security of the PesaPoll platform and its users' data and funds seriously. This Security Policy outlines the measures we implement to protect your account, transactions, and personal information.
• All data transmitted between your device and our servers is encrypted using HTTPS/TLS.
• Sensitive data including passwords are hashed and never stored in plain text.
• Database access is restricted to authorized systems only.
• All M-Pesa transactions are processed through Safaricom's official Daraja API.
• We do not store your M-Pesa PIN or full payment credentials.
• Withdrawal requests are validated and processed through secure automated systems.
• We implement webhook signature verification for all payment callbacks.
• Administrative access to the Platform is restricted to authorized personnel only.
• Multi-factor authentication is enforced for administrative accounts.
• Access logs are maintained and reviewed regularly.
• Our servers are hosted in a secure environment with firewall protection.
• Regular security updates and patches are applied to all systems.
• We perform regular backups of all critical data.
We implement the following measures to protect user accounts:
• Password hashing using industry-standard algorithms.
• Session management with automatic timeout for inactive sessions.
• Rate limiting on login attempts to prevent brute-force attacks.
• Optional Two-Factor Authentication (2FA) for user accounts.
• Email notifications for account changes and suspicious activity.
As a user of PesaPoll, you are responsible for:
• Keeping your password confidential and using a strong, unique password.
• Enabling Two-Factor Authentication for additional security.
• Not sharing your account credentials with anyone.
• Logging out of your account on shared or public devices.
• Reporting any suspicious activity or unauthorized access immediately.
• Keeping your registered email address and phone number up to date.
We actively monitor for fraudulent activity including:
• Unusual transaction patterns or large unexpected withdrawals.
• Multiple account creation from the same device or IP address.
• Attempts to manipulate market outcomes.
• Identity fraud during KYC verification.
Accounts suspected of fraud will be suspended pending investigation. We cooperate fully with law enforcement authorities in fraud investigations.
In the event of a security incident:
• We will notify affected users within 72 hours of becoming aware of a breach.
• We will take immediate steps to contain and remediate the incident.
• We will report significant breaches to the Office of the Data Protection Commissioner as required by the Kenya Data Protection Act, 2019.
• We will provide guidance on steps users should take to protect themselves.
If you discover a security vulnerability in our Platform, we encourage responsible disclosure. Please report vulnerabilities to:
• Email: support@pesapoll.com
We commit to acknowledging your report within 48 hours and working with you to resolve the issue. We ask that you do not publicly disclose the vulnerability until we have had a reasonable opportunity to address it.
PesaPoll integrates with the following third-party services, each with their own security standards:
• Safaricom Daraja API — for M-Pesa payment processing.
We review the security practices of our third-party providers and only work with reputable services that maintain appropriate security standards.
Our security practices are designed to comply with:
• Kenya Data Protection Act, 2019.
• Central Bank of Kenya guidelines on digital payments.
• Safaricom M-Pesa integration security requirements.
• General industry best practices for web application security.
This Security Policy may be updated from time to time to reflect improvements in our security practices or changes in applicable laws. Updates will be posted on the Platform with a revised effective date.
For security concerns or to report an incident:
• General: support@pesapoll.com
• Website: https://pesapoll.com