Services Pricing About Contact
Sign in Get started
Security & trust

Built for businesses that care about security.

You put real money, stock, customers, debts and staff records into EAZYDEV. Here is exactly how we protect that data — plainly, and honestly.

Per-business data isolation Two-factor authentication Full audit trail HTTPS in production Secure payment handling

How your data is protected

Defence in depth — isolation, access control and logging working together, not a single switch.

Business data isolation

Every business is a separate tenant. Products, sales, customers, debts, expenses and staff records are scoped to your business on every request — one business can never read another's data.

Role-based access control

Owner, Manager, Staff and Viewer roles each see only what they should. Staff can sell but not change prices; viewers are read-only. Permissions are enforced on the server, not just hidden in the screen.

Two-factor authentication

Add a second step at sign-in with an authenticator app (TOTP) or an emailed code, plus single-use recovery codes. Passwords are hashed with industry-standard PBKDF2 — we never store them in plain text.

Audit trail & staff activity logs

Sensitive changes — stock corrections, price edits, approvals, expenses — are recorded with who did it, when, and the before-and-after values. Owners and managers can review exactly what staff changed.

Encrypted HTTPS traffic

In production the site runs over HTTPS with HSTS, secure cookies and an automatic HTTP → HTTPS redirect, so data is encrypted in transit between your browser and our servers.

Payment keys stored securely

Card payments are processed by Stripe, Paystack and Flutterwave. Secret keys live only in server environment configuration — never in the browser, never in our code — and every webhook signature is verified.

Abuse & brute-force protection

Login, 2FA, registration and public forms are rate-limited per IP, and a security layer blocks scanners and site-rippers. Hardening headers (CSP, nosniff, frame protection) ship on every response.

Backups & data portability

Your data belongs to you. Business owners can export their full records (CSV / JSON / Excel / PDF) any time — EAZYDEV is designed to reduce vendor lock-in. The production database runs on managed PostgreSQL with operational backups, and automated Google Cloud backup is available on Business plan and above. Exports are permission-controlled and audit-logged.

Privacy-first data handling

We collect only what the service needs, never sell your data, and keep logs free of passwords, tokens and payment secrets. Optional cookies are off until you allow them.

In plain words

No jargon. Here is what we promise about your business data.

  • Every business account is isolated from every other business.
  • Staff only see what their role allows.
  • Sensitive changes are logged with who, when and what changed.
  • Owners can review important staff actions at any time.
  • Payment secrets are never exposed in the browser.
  • We use secure HTTPS connections in production.
  • We never sell your data, and you can export it any time.
  • Cloud backup is available on Business plan and above; Google Cloud backup can be configured for eligible businesses.
  • We are actively building toward stronger compliance standards.

Privacy & data protection

Designed around Nigeria Data Protection Act (NDPA) / NDPC privacy principles.

We build EAZYDEV with privacy-first principles aligned to the Nigeria Data Protection Act and NDPC guidance. In practice that means:

Read the full Privacy Policy and Cookie Policy for details on what we collect, how we use it, and who processes it on our behalf.

Compliance roadmap

We are honest about where we are. These are the standards we design around and are working toward — not certifications we claim to already hold.

NDPC-aligned privacy controls

In progress · roadmap

Our privacy program is designed around the Nigeria Data Protection Act and NDPC principles. Controls we operate or are putting in place:

  • Consent-based cookie controls
  • Data minimisation & purpose limitation
  • Access control & per-business isolation
  • Defined data-retention practices
  • User data export & deletion requests
  • Breach-response & notification planning
We describe these as NDPC-aligned privacy controls. Formal NDPC registration / certification is part of our roadmap and is not yet complete — we will update this page when our status changes.

SOC 2-ready security practices

In progress · roadmap

We build with the kinds of controls a SOC 2 examination looks for, so an audit is a step we can take rather than a rebuild:

  • Access control & least privilege
  • Logging, monitoring & audit trails
  • Change tracking on sensitive actions
  • Backup & recovery practices
  • Incident-response planning
  • Secure development & payment-provider separation
We describe this as SOC 2-ready / SOC 2-aligned. We are not SOC 2 Type I or Type II certified, and we do not claim to be. We will only advertise certification once an independent audit is completed.

Security questions before you sign up?

We are happy to walk through how your data is protected. Reach out any time.