Security and Data Protection
FeePrime is trusted by cooperatives, schools, insurers, and merchants to run the operations their businesses depend on. Protecting their data — and keeping them in control of it — is a first-order design goal, not an afterthought. This page summarises how we do that.
Your data stays yours
FeePrime is a multi-tenant platform, but every organisation’s data is strictly isolated. Access to any record is verified on every request against the caller’s identity and their active membership of that specific organisation, at a single enforcement point that cannot be bypassed. One organisation can never see, reach, or widen its scope into another’s data.
For organisations that require the highest level of control, FeePrime can also be deployed on your own premises — your data never leaves your building, and you hold your own keys and backups. More on that below.
Encryption
All traffic to and from FeePrime is served exclusively over HTTPS/TLS, with certificates issued and renewed automatically, including for white-label customer domains.
The most sensitive data at rest is encrypted with strong asymmetric and one-way cryptography: payment credentials are encrypted before storage and only ever decrypted in memory at the moment of use; passwords are stored as one-way hashes and are never recoverable, even by us; and backups are encrypted with a key held off the server.
Access control & four-eyes approval
Access in FeePrime is role-based and enforced server-side — never trusted from the client. Each member holds a defined role per module, from read-only through to administrator, and every action is re-checked against that role at the moment it happens.
Sensitive changes flow through a maker/checker approval pipeline: a change made by one person takes effect only once a second, authorised person approves it. This four-eyes control — standard in banking, rare in the tools most SMEs are offered — protects against both error and fraud, and is available across the platform.
Authentication options include passwordless one-time codes, single sign-on, and authenticator-app multi-factor authentication for possession-based second-factor security.
Complete, tamper-evident audit trail
Every change in FeePrime is recorded — automatically and immutably — as part of how the system works, not as a bolt-on log that can drift from reality. Each record carries its full history: who changed what, when, with a field-by-field before-and-after view, and the identity of whoever approved it.
Every organisation’s history is stamped with a gap-free sequence, so an auditor can verify that nothing is missing. This history is available on records across the platform — contacts, invoices, transactions, inventory, members, and more.
Backups & recovery
FeePrime performs automated, encrypted nightly backups, with an automatic health check that detects any silent failure. Recovery follows a documented, tested procedure — a known, repeatable process rather than an improvisation. Because backups are encrypted with a key kept off the server, a stolen backup yields nothing usable.
We never hold your money
This is central to how FeePrime is built. FeePrime does not operate any pooled, platform-owned, or custodial account, and never holds customer funds.
Mobile-money collections (MTN MoMo and Orange Money, through a licensed, regulated aggregator) settle directly into each merchant’s own account, initiated with that merchant’s own credentials, which are encrypted at rest and isolated per organisation. FeePrime’s role is orchestration and reconciliation only — it is never the account holder and has no path to redirect settlement away from you.
The practical consequence: FeePrime sits outside the flow of funds. Your money is never ours to lose, hold, or misdirect.
Deployment options: cloud or on-premise
You choose where FeePrime runs.
- Managed cloud — hosted on dedicated, isolated infrastructure in the European Union, with separate production and staging environments and encrypted backups managed for you.
- On-premise — deployed on your own hardware, inside your own network. Your data never leaves your premises, you control disk encryption and backups, and you hold your own keys. Suited to organisations with strict data-residency, sovereignty, or regulatory requirements.
Business continuity
Because FeePrime never holds your funds, there is nothing for a vendor to hold hostage — your money moves through your own account, under your own control, independent of us. Your full dataset is portable and restorable at any time, so you are never locked in. Should the worst happen, your operations and your money remain yours.
We’re happy to walk qualified prospects and their security teams through a detailed due-diligence pack under NDA, covering data residency, sub-processors, isolation architecture, and incident response in depth. Contact us to request it.