Security Policy
Security is central to how UniEgo is built and operated. Below are the enabled controls and current practices.
1. Encryption
All traffic between your device and UniEgo is protected with HTTPS/TLS. Data is encrypted in transit and at rest by our cloud database provider.
2. Authentication
UniEgo supports email and Google sign-in. Sessions are managed with rotating secure tokens. Passwords are never stored in plain text.
3. Access control
UniEgo uses row-level security so each user, association, and role only sees data they are entitled to. Administrative actions are recorded in an audit log.
4. Payment security
Card and bank details are processed by a licensed payment partner. UniEgo does not store full card numbers, CVVs, or bank credentials.
5. Vulnerability reporting
Responsible disclosure is welcome. Report suspected security issues to security@emmtec.ng. Please do not test on live production data.
6. Incident response
In the event of a confirmed security incident affecting your data, we will notify affected users and the relevant authorities in line with applicable Nigerian law.
7. Shared responsibility
Keep your password private, use a strong unique password, and sign out on shared devices. UniEgo staff will never ask for your password or OTP.