Home / Security
Security
1. How We Protect Your Data
- TLS 1.3 encryption for all data in transit
- Encryption at rest for sensitive data
- PostgreSQL with row-level security policies
- Regular security reviews and dependency audits
2. Account Security
- SMS verification for first-time withdrawals
- Device fingerprinting detects account takeover attempts
- Velocity monitoring flags unusual activity
- Automatic account lock after suspicious activity patterns
3. Payment Security
- M-Pesa payouts use IntaSend's secured payment infrastructure
- Withdrawal requires verified M-Pesa number
- Transaction limits for new accounts
- All payouts logged with unique reference numbers
4. What We Will Never Do
We will NEVER:
- Ask for your M-Pesa PIN
- Ask for your password by email or phone
- Request payment to unlock your account
- Ask you to install remote access software
- Contact you from a non-@striveearn.com email address
5. Responsible Disclosure
Found a security vulnerability? Contact hq@striveearn.com. We respond to all security reports within 24 hours. We acknowledge all valid reports. We do not currently operate a paid bug bounty programme.
Please do not:
- Publicly disclose the issue before we have addressed it
- Access or modify other users' data
- Perform testing that degrades service for other users
6. Contact
Security concerns: hq@striveearn.com