Skip to content

Security

Security and data protection in SaccoMonitor

A SACCO system holds members’ savings records and personal details. SaccoMonitor protects them with controls on who can do what, a permanent record of every change, and careful handling of sign-ins and data.

Controls on money

  • Role-based access. Each action needs a specific permission; SACCOs build roles from a fixed catalogue and the server enforces them on every request.
  • Maker–checker. The officer who captures a loan application cannot approve it, nobody approves or disburses their own loan, and withdrawals above the SACCO’s limit need a second officer.
  • Approval levels. Larger loans need more sign-offs, by role.
  • Reversals, not deletions. Posted transactions and journals are never edited or removed; corrections are separate, linked entries.
  • Closed periods. Once an accounting period is closed, nothing can be posted into it.
  • Double submissions. A repeated click or a network retry cannot post the same transaction twice.

A complete audit trail

Changes to members, accounts, loans, transactions, staff, roles and settings are recorded with who made them, when, from which IP address and device, and the values before and after. Sign-ins, failed attempts and password events are logged separately. Auditors can export both.

Sign-in and sessions

ControlWhat it does
Password hashingPasswords are stored as one-way hashes.
No shared passwordsMembers and staff added by a SACCO activate their own account — they confirm a code sent to their phone or email and choose their own password.
Session time-outsIdle sessions sign out automatically, and every session has a maximum lifetime.
Other devicesUsers can see their active sessions and sign out other devices; changing a password signs out other devices.
LeaversDeactivating a staff member ends their sessions immediately.
Attempt limitsSign-in and password-reset attempts are rate-limited.

Data separation and privacy

Each SACCO’s records are kept separate from every other SACCO’s, and members can only ever see their own accounts. Private screens, the member portal and the API are excluded from search engines, and API responses are marked not to be cached. How personal data is used is described in the privacy policy.

Shared responsibility

Security also depends on how the SACCO uses the system: give each person their own login, grant only the permissions a role needs, and remove access promptly when someone leaves.

Frequently asked questions

No. Every record belongs to one SACCO, and every request is checked against the SACCO the signed-in staff member works for. Branch-level staff are further limited to their own branches.

No. Mistakes are corrected with a reversal — a new, linked transaction that undoes the original in the accounts. The original stays on record, and the reversal is audited.

Passwords are stored only as one-way hashes, never in readable form. Staff created by an administrator must change their temporary password on first sign-in.

No. Only the public information pages are open to search engines. The application, the member portal and the API are excluded from indexing and require sign-in.

Run your SACCO on clear, balanced books

Register your SACCO, import your members from Excel and post your first deposit the same day.