Skip to main content
Security & control

Members trust you with their savings. We take that seriously.

A cooperative platform holds other people's money and identity documents. SaccoSphere is built so that access is minimal, actions are witnessed, and nothing can be quietly changed after the fact.

Tenant isolation Two-factor ready Maker-checker Immutable audit trail Period locking
Controls

Eight controls working together

Security here is not a checklist bolted onto a member register. Each control below protects a specific failure mode that costs cooperatives real money.

Strict Tenant Isolation

Every record is scoped to a single organisation. One cooperative can never reach another's members, transactions or reports — isolation is enforced at the query level, not left to the interface.

Authentication & Two-Factor

Strong password policy, optional two-factor verification on login, session visibility and remote sign-out for staff accounts.

Granular Role Permissions

Roles are composed from explicit capabilities. A cashier records, an approver approves — and the interface only offers what a role is entitled to do.

Maker-Checker on Money Movement

Sensitive financial actions require a second authorised person. Initiator and approver are always different, and both are recorded.

Immutable Audit Trail

Activity is logged with the actor, timestamp, source address and before/after values, giving auditors a defensible chain of events.

Period Locking & Reversals

Closed accounting periods cannot be silently edited. Corrections are made through reversing entries that leave an explainable paper trail.

Encrypted in Transit

All traffic between staff, members and the platform is served over TLS, including payment provider webhook callbacks.

Safe Payment Ingestion

Provider callbacks are validated, logged and processed idempotently, so a repeated delivery can never double-credit a member account.

Tenant isolation

One platform, watertight compartments

SaccoSphere is multi-tenant, which means many cooperatives share the same platform. Isolation is therefore the single most important control in the system — and it is enforced in the data layer, not left to the interface to hide things.

Every record carries its owning organisation, and every query is scoped to the organisation of the signed-in user. Within that boundary, branch scoping and role permissions narrow access further, so a teller in one branch sees their own till and members — not the whole cooperative.

Organisation-scoped queries

A cooperative can never read another cooperative's records.

Branch-scoped operations

Staff see the branches and tills their role permits.

Granted capabilities only

Screens and actions not granted to a role are not rendered.

Operational security practices

Applied across every cooperative by default

  • Role-scoped access for every staff member
  • Two-factor verification available on all accounts
  • Session and device visibility for account holders
  • Maker-checker separation on financial approvals
  • Full activity log retained for audit review
  • Closed accounting periods are protected from edits
  • Payment callbacks validated and deduplicated
  • No member data shared with third parties without instruction

On certifications

We would rather describe what the platform actually enforces than display badges we have not earned. Formal certification and independent penetration testing are part of the commercial roadmap; ask us for the current status and we will tell you plainly.

Segregation of duties

The person who records is never the person who approves

Most cooperative losses are not sophisticated attacks — they are single individuals with end-to-end control of a transaction. Maker-checker removes that possibility.

Maker

A teller or officer records the transaction — a deposit correction, a loan, a withdrawal, an expense.

System

Rules evaluate the value, type and risk band, then decide whether the action needs a second pair of eyes.

Checker

A different authorised person reviews and approves. Their name, reason and timestamp are recorded permanently.

Every approval, correction and configuration change writes to the audit trail with the acting user, source address, timestamp and the before and after values — so an auditor can reconstruct exactly what happened, in what order, and on whose authority.

Ask us the uncomfortable security questions

Bring your auditor or your IT committee. We will walk through isolation, access control, approvals and the audit trail in detail — and tell you honestly where the platform's boundaries are.

  • No obligation
  • Mapped to your products
  • Honest fit assessment
Request a Demo Contact our team

Typical response within one business day.