Security
Security at Agriloom
We take security seriously. Learn about our practices, protocols, and how we protect your data and transactions on the Agriloom platform.
Our Commitment
Security is built into everything we do
Data Encryption
All data is encrypted in transit using TLS 1.2+ and at rest using industry-standard encryption algorithms.
Multi-Factor Authentication
MFA is required for sensitive operations including bulk payments and account changes.
Audit Logging
Every action is logged with immutable audit trails for full traceability and compliance.
Regular Security Audits
We conduct regular penetration testing and security audits to identify and address vulnerabilities.
Access Controls
Strict role-based access controls ensure employees only have access to data they need for their job.
Incident Response
24/7 monitoring and a dedicated incident response team to handle security events swiftly.
Data Protection
How we protect your data
✓
Encryption in transit — All data transmitted between your device and our servers is encrypted using HTTPS/TLS
✓
Encryption at rest — Sensitive data is encrypted in our databases using AES-256 encryption
✓
Secure payment processing — Payment credentials are never stored. We use PCI-compliant payment processors
✓
Regular backups — Data is backed up regularly and stored in secure, geographically distributed locations
✓
Data retention policies — We retain data only as long as necessary for business operations and legal compliance
Payment Security
Securing financial transactions
LoomPay Security
Dual-channel MFA (SMS + email) for payment authorization. Every payment requires verification from multiple channels.
Escrow Protection
Funds are held in escrow until delivery confirmation, protecting both buyers and sellers.
Transaction Monitoring
Real-time monitoring of all transactions to detect and prevent fraudulent activity.
M-Pesa Integration
Secure integration with M-Pesa API using encrypted credentials and signed callbacks.
Audit Trails
Complete audit logs for every payment including authorization, verification, and settlement.
Rate Limiting
OTP rate limiting prevents brute force attacks on payment authorization codes.
Account Security
Keeping your account secure
We provide several features to help you keep your account secure:
✓
Strong password requirements — We enforce strong password policies and encourage password managers
✓
Email verification — Email addresses must be verified before account activation
✓
Mobile verification — Mobile numbers are verified via OTP for payment authorization
✓
Session management — Secure session handling with automatic timeout
✓
Login monitoring — We monitor for suspicious login attempts and may require additional verification
Responsible Disclosure
Reporting security vulnerabilities
If you discover a security vulnerability in our platform, we encourage responsible disclosure. Please:
1
Email security@agriloom.co.ke with details of the vulnerability
2
Provide sufficient information for us to reproduce and understand the issue
3
Allow us reasonable time to address the vulnerability before public disclosure
4
Avoid exploiting the vulnerability for any purpose other than testing
We appreciate responsible security research and will work with researchers to acknowledge and address vulnerabilities appropriately.
Compliance
Regulatory compliance
Kenya Data Protection Act
We comply with the Kenya Data Protection Act 2019 and related regulations.
CBK Regulations
Our payment operations comply with Central Bank of Kenya regulations.
International Standards
We follow international security best practices and standards.
Security Questions?
Contact our security team
If you have questions about our security practices or need to report a security concern, please reach out.