🔒 Enterprise-Grade Security

Data Encryption & Security Standards

How we protect your database credentials, secure your user data, and defend your API infrastructure[cite: 6].

1. AES-256 Cryptographic Vault

We understand the sensitivity of connecting remote databases[cite: 6]. When you input your database password or WhatsApp API tokens into Akmond Notify, they are immediately passed through an Advanced Encryption Standard (AES-256) algorithm using a highly secure, randomly generated application key[cite: 6].

Zero-Knowledge Architecture: Your credentials are mathematically scrambled before they ever touch our database storage[cite: 6]. Our engineering team, support staff, and database administrators cannot read your plain-text passwords[cite: 6].

2. Read-Only Enforcement Policy

Akmond Notify is designed as a passive monitoring system[cite: 6]. Our Engine only requires the ability to SELECT (read) data from your transaction tables[cite: 6].

We strongly mandate that all clients create a dedicated, Read-Only database user within their cPanel/server before mapping a connection to Akmond Notify[cite: 6]. This guarantees at the database level that our system cannot modify, delete, or drop your VTU tables, ensuring absolute data integrity[cite: 6].

3. Engine Execution Isolation

The core logic that decrypts your credentials and executes the database monitoring is structurally isolated[cite: 6]. Our engine files and decryption keys are hosted completely outside of the public web directory (public_html)[cite: 6].

This advanced structural obfuscation means that even in the highly unlikely event of a front-end web exploit, malicious actors cannot navigate to or access the core Engine files or the secure vault where the master application keys reside[cite: 6].

4. Ephemeral Data Processing

Akmond Notify operates on a continuous, lightweight loop[cite: 6]. When a transaction event is detected on your server, the data payload (Reference ID, Amount, User Phone) is held in memory just long enough to push the alert to your end-user[cite: 6].

We do not retain long-term historical logs of your users' transaction data, minimizing your exposure and ensuring compliance with modern data privacy standards[cite: 6].