The safest record is the one we never took.
Bona sits between institutions that hold sensitive records and platforms that want answers from them. The controls below exist so that the answers can move without the records having to — and so that what does move is the smallest thing that answers the question.
There is no column for the things people fear.
Grades, transcripts, fees, debt, discipline and attendance are absent from the schema, not filtered out of responses. That is a stronger guarantee than a policy: there is nothing to leak, nothing to subpoena and nothing for a future commercial conversation to unlock. Any proposal to add them has to revisit a promise made on this page, in public, first.
Consent is enforced at read time, not at signup.
No verification returns a field without a live consent row for that consumer, that student and that field. Scopes are checked against the grant, not against the consumer’s tier — a Tier 2 consumer holding status-only consent gets status only. A revocation takes effect on the next call, because there is no cache in front of the check.
Status is always included — it is the question being asked. Programme, level and institution are ticked individually, with the student’s real values shown next to each one before they decide.
Every grant carries an expiry. A bank verifying an account opening does not keep read access for the length of the degree, and a student can end a grant early from their phone without asking anyone.
Every check writes a row the student can read: who asked, when, which fields were returned. Including Tier 0 attestation checks, which need no consent — needing no permission is not the same as being invisible.
Nigerian law, named and applied.
Lawful basis is recorded per field rather than per system. Institutions rely on legitimate interest and public task for the enrolment record they already keep; anything shared beyond attestation runs on the student’s consent, which is specific, informed and revocable — the standard the Act actually sets.
Bona is registered with the NDPC as a Data Controller of Major Importance and files the returns that go with it. The General Application and Implementation Directive is why our consent screens show real values before a choice and why every grant carries an expiry, rather than an indefinite tick box.
Access, rectification, erasure, portability and objection, handled in the student app and answered inside the statutory window. Rectification of enrolment facts routes to the institution that owns them, with the request tracked so the student can see it move rather than being told to email a registry.
Student data is stored and processed in Nigeria. Cross-border transfer is limited to what an integration genuinely requires, is listed in the data processing agreement, and never includes a raw NIN because we do not hold one.
Verification logs are retained for seven years — banks and NELFUND are audited on lending decisions and the log is the evidence. Consent grants are retained for as long as they are live plus the same statutory window. Quick Verify results are snapshotted at delivery and the purchaser’s email is used for the receipt and nothing else.
Tier 2 identity-linked access is restricted to organisations with a lawful basis to hold identity data — CBN-licensed institutions, NELFUND and equivalent — evidenced at KYB and re-checked, with mTLS on top of the bearer key.
What is switched on today.
Watching the people who ask, not just the people being asked about.
A verification network fails quietly when a legitimate consumer starts asking questions it was not approved for. Bona monitors query patterns against each consumer’s declared use — a sudden jump in distinct subjects, sequential NSID enumeration, a high miss rate that suggests guessing — and acts on them.
A consumer states what it verifies students for at KYB. Traffic that does not look like that gets flagged to a human within the hour, and access can be suspended without waiting for a complaint.
Every check appears in the student’s activity list with an “I don’t recognise this” action. It opens a case against the consumer, and the consumer has to answer it.
Bulk enumeration, resale of results, use in advertising or scoring, and any check made without the subject’s knowledge where consent was required. Termination, not a warning.
Who else touches the data, and what happens when they are down.
What we have not finished.
A security page that lists only strengths is a security page nobody experienced believes. These are open, with owners and dates, and your review team will find them anyway.
Report a vulnerability to security@bona.ng. We acknowledge inside one working day, we do not threaten researchers, and we credit anyone who wants to be credited.
We answer the long ones. Data processing agreement, sub-processor list, architecture notes and the penetration test report are available under NDA.