Privacy Policy & Security Standards
Transparent parameters outlining how we shield customer transactional logs and preserve tenant space integrity.
This specification document was last updated on May 23, 2026. By connecting your active client ledgers and processor APIs to Todellaa, you agree to these operational security constraints.
1. Data Enclosure & Row-Level Security
All inbound transactional logs, Paystack API streams, and ZenBank spreadsheet entries are strictly partitioned via Postgres Row-Level Security (RLS). Cross-tenant matching is systematically isolated at the core database engine layer. Your verification workspace data remains entirely enclosed.
2. Statement Ingest Cache Lifetime
Raw ZenBank CSV statements and bank spreadsheets ingested into our matching pipelines are parsed instantly in-memory. Expected ledger files are cached solely for the matching pipeline execution window and are purged thoroughly within 24 hours of matching session resolution.
3. Cryptographic Token Protections
Client integration credentials utilized for payment processor webhooks (such as Stripe or Paystack API tokens) are enveloped using high-strength hardware security modules (HSM). Todellaa developers and administrators have zero plaintext exposure to these integration parameters.
4. Compliance & Audit Tracking Logs
Every manual mismatch verification state toggle, file export action, or RLS token request registers a permanent cryptographic audit token, accessible from your compliance status panel. These logs are stored in static ledger spaces to ensure absolute auditing integrity.