Skip to main content
Security First

Built on Trust

Our ecosystem security architecture across Ogotto platforms and UtambuliSSO is designed to handle high-stakes coordination with absolute transparency, cryptographic safety, and resilience.

Security Pillars

  • UtambuliSSO Auth Engine

    Centralized authentication powered by our AGPLv3 open-source engine with PKCE flows, JWT verification, and zero-knowledge token signing.

  • Chama Financial Ledgers

    OgottoPay transactions are recorded on encrypted, multi-signature ledgers requiring group approvals before payouts.

  • KYC & ineship Trust

    Identity verification via National ID / Passport guarantees verified user badges and anti-fraud protection on ineship.

Technical Hardening

The standards we follow to ensure our infrastructure is resilient to both technical failure and malicious intent.

  • Bank-Grade Encryption

    All personal, financial, and messaging data is encrypted in transit (TLS 1.3) and at rest (AES-256-GCM) across all services.

  • Kenya DPA 2019 Compliance

    Full compliance with the Kenya Data Protection Act 2019 and ODPC guidelines for lawful data processing and retention.

  • Multi-Signature Payouts

    Chama group payouts require threshold authorizations from designated group officials to eliminate unauthorized withdrawals.

  • Social Safety & Moderation

    Automated content filtering, encrypted companion messaging, and real-time moderation safeguards for ineship travelers.

Found a vulnerability?

We take security seriously and welcome responsible disclosure from the community.

Report Vulnerability