Skip to content

Business Boost Sales: Get up to 25% OFF! Use codeBOOST26

Offer ends 14 August 2026.Shop Now
Stockovaa

Trust & Security

Your business data is the heart of your operation. Here is how we protect it.

Last updated:

Stockovaa is built on a multi-tenant architecture where each business gets its own separate database. Your data is not mixed with other customers' data in shared tables, which reduces the risk of accidental cross-account exposure and keeps your records cleanly isolated.

All traffic between your browser and Stockovaa is encrypted in transit using TLS (HTTPS). Sensitive credentials are hashed, and application secrets are stored outside the codebase. Payment details are handled by PCI-compliant gateways (such as Paystack, Flutterwave, Stripe, and PayPal) and are not stored on our servers.

Role-based permissions let you grant staff only the access they need. Every account is protected by email verification at signup, and administrative areas are gated behind authentication. We follow the principle of least privilege for our own team's access to production systems.

We run automated database backups so your records can be recovered in the event of an incident. Backups are part of our routine operations, and we continuously work to improve our recovery objectives as we scale.

The platform uses industry-standard protections including CSRF tokens on forms, parameterized database queries to prevent SQL injection, output escaping to mitigate cross-site scripting, rate limiting on sensitive endpoints (such as one-time-password requests), and security headers. Upload directories are configured to block execution of server-side scripts.

If you believe you have found a security vulnerability, we want to hear from you. Please report it privately through our Contact page and give us a reasonable opportunity to investigate and fix the issue before any public disclosure. We appreciate the security community's help in keeping our customers safe.