SECURITY AND COMPLIANCE

The safest record is the one we never took.

Bona sits between institutions that hold sensitive records and platforms that want answers from them. The controls below exist so that the answers can move without the records having to — and so that what does move is the smallest thing that answers the question.

Data residency
Nigeria
NIN storage
Tokenised
Consent check
Every call
Audit coverage
Every read
01 — MINIMISATION

There is no column for the things people fear.

Grades, transcripts, fees, debt, discipline and attendance are absent from the schema, not filtered out of responses. That is a stronger guarantee than a policy: there is nothing to leak, nothing to subpoena and nothing for a future commercial conversation to unlock. Any proposal to add them has to revisit a promise made on this page, in public, first.

HELD, AND WHY
Name, date of birth and photograph — to bind a record to a person
A NIN token — to match identity at claim, never to display or return
Matric number and NSID — the institution’s key and the national one
Programme, level, entry session — to compute a completion date
Consent grants and verification history — so a student can audit us
ABSENT FROM THE SCHEMA
Grades and transcripts
Fees, debt and payment history
Disciplinary and conduct records
Attendance
Plain NIN — matched against, never stored
03 — REGULATION

Nigerian law, named and applied.

Nigeria Data Protection Act 2023

Lawful basis is recorded per field rather than per system. Institutions rely on legitimate interest and public task for the enrolment record they already keep; anything shared beyond attestation runs on the student’s consent, which is specific, informed and revocable — the standard the Act actually sets.

GAID 2025

Bona is registered with the NDPC as a Data Controller of Major Importance and files the returns that go with it. The General Application and Implementation Directive is why our consent screens show real values before a choice and why every grant carries an expiry, rather than an indefinite tick box.

Data subject rights

Access, rectification, erasure, portability and objection, handled in the student app and answered inside the statutory window. Rectification of enrolment facts routes to the institution that owns them, with the request tracked so the student can see it move rather than being told to email a registry.

Data residency

Student data is stored and processed in Nigeria. Cross-border transfer is limited to what an integration genuinely requires, is listed in the data processing agreement, and never includes a raw NIN because we do not hold one.

Retention

Verification logs are retained for seven years — banks and NELFUND are audited on lending decisions and the log is the evidence. Consent grants are retained for as long as they are live plus the same statutory window. Quick Verify results are snapshotted at delivery and the purchaser’s email is used for the receipt and nothing else.

Sector obligations

Tier 2 identity-linked access is restricted to organisations with a lawful basis to hold identity data — CBN-licensed institutions, NELFUND and equivalent — evidenced at KYB and re-checked, with mTLS on top of the bearer key.

04 — CONTROLS

What is switched on today.

ACCESS AND IDENTITY
MFA enforced on every institution and admin account, from first login
Sandbox and production keys carry different prefixes so a mix-up is visible on sight
Production keys are shown once; rotation keeps the old key alive 24 hours
Per-key rate limits, and 10 checks an hour per IP on the public lookup
Every administrative action is attributed to a named person and audited
DATA AND RECOVERY
TLS in transit; encryption at rest on every store holding student data
Bulk uploads are fully reversible for 24 hours — the pre-commit state is kept, not a diff
Identity merges are reversible for 30 days and recorded field by field
Disruptions require a dry run and a second approver before they touch a date
Completion dates are append-only traces: nothing is edited, everything is replayable
05 — MISUSE

Watching the people who ask, not just the people being asked about.

A verification network fails quietly when a legitimate consumer starts asking questions it was not approved for. Bona monitors query patterns against each consumer’s declared use — a sudden jump in distinct subjects, sequential NSID enumeration, a high miss rate that suggests guessing — and acts on them.

Declared use, enforced

A consumer states what it verifies students for at KYB. Traffic that does not look like that gets flagged to a human within the hour, and access can be suspended without waiting for a complaint.

The student can object

Every check appears in the student’s activity list with an “I don’t recognise this” action. It opens a case against the consumer, and the consumer has to answer it.

Prohibited outright

Bulk enumeration, resale of results, use in advertising or scoring, and any check made without the subject’s knowledge where consent was required. Termination, not a warning.

06 — DEPENDENCIES

Who else touches the data, and what happens when they are down.

NIMC
A NIN and a name, at claim time only
Claims degrade to manual review by a person at Bona. A student is never blocked from claiming because an upstream register is unavailable.
NUC · NBTE · NCCE
Programme and accreditation status, no student data
Retried with backoff. Stale accreditation flags the programme for review; it never voids an enrolment, because a student did not choose their institution’s paperwork.
Paystack
A Quick Verify purchaser’s email and amount. No student data.
Checkout says so and takes no money. A charge that succeeds for the wrong amount or currency is refused delivery and escalated to a human.
Providus
A one-time account number and a settlement amount
The account expires unused and the check is never started, so there is nothing to refund.
SMS providers
A phone number and a one-time code
Failover across three Nigerian providers. Codes are transactional, so they reach numbers on the NCC Do-Not-Disturb register.
07 — HONESTLY

What we have not finished.

A security page that lists only strengths is a security page nobody experienced believes. These are open, with owners and dates, and your review team will find them anyway.

ISO 27001 certification
In progress. Controls are implemented and the audit is scheduled; the certificate is not in hand and we will not imply otherwise.
Outbound webhook delivery
Not switched on. The signature scheme, header name and event names are final, so integrations written against them now will not change. Poll until then.
Automated retention jobs
Retention periods are defined and enforced on request; the scheduled deletion job is built and not yet running unattended.
Independent penetration test
One completed internally, one commissioned externally. The external report and our remediation notes go to institutions and consumers under NDA on request.

Report a vulnerability to security@bona.ng. We acknowledge inside one working day, we do not threaten researchers, and we credit anyone who wants to be credited.

Send us your security questionnaire.

We answer the long ones. Data processing agreement, sub-processor list, architecture notes and the penetration test report are available under NDA.