Readiness controls implementedPCI DSS readiness
Provider-hosted payment handoff, no intentional card-data storage, finance commissioning gates and verified event processing.
Not a certification claim. Merchant classification, the applicable SAQ/ROC/AOC and acquirer or QSA validation remain commissioning work.
Review payment-security controls →
Framework publishedService commitments
A practical incident, availability, maintenance and support framework. Measurable targets and remedies belong in the signed order form for the chosen hosting profile.
Not an executed SLA. No uptime, response-time, recovery or service-credit figure is represented as contractually active on this owner-review installation.
Read the SLA framework →
Framework publishedRisk management
A NIST Cybersecurity Framework 2.0-informed approach covering governance, identification, protection, detection, response and recovery.
Authenticated operators receive live control signals; external certification is neither stated nor implied.
Read the risk framework →
Rights intake implementedData protection
A Nigeria-focused privacy policy and email-verification workflow for access, correction, deletion, restriction, objection and portability requests.
The final legal controller identity, DPO/DPCO appointment and NDPC registration classification must be approved and published before commercial processing.
Read the data protection policy →
Controlled registerBusiness procedures
Fifteen defined procedures cover reservations, hotel verification, payments, privacy, incidents, access, vendors, content, backup and change management.
Each operating entity must formally adopt, assign and evidence the procedures before launch.
Open the procedure register →