Tajami › Security

Security & compliance

Your data is safe with us.

Your customers trust you with their messages, their addresses and their money. So Tajami connects only to your business account, never sees a card number, and encrypts everything it holds. Here is exactly what that means — what is built, what comes before launch, and what we will not claim.

  • Encrypted in transit and at rest
  • Business accounts only
  • Card details never reach us
  • Written to the NDPA
What Tajami holdsYour account
Messages sent to your business
Encrypted
The token that connects your account
Sealed · revocable
Your catalogue, orders and customers
Walled off
Card numbers and bank logins
Never received
Your personal chats
Never connected
Your Instagram or WhatsApp password
Never asked
Readable only by the systems that answer your customers, and by you.
The boundary

What it can see, and what it never can.

To answer your customers, Tajami has to read what they send your business. That is the whole of it — and some things are out of reach by design, not by promise.

Sees, to do the work

  • Messages sent to your businessOn the accounts you connect, so it can answer them
  • Your catalogueProducts, prices, stock and delivery areas you set
  • Orders and delivery detailsSo a payment closes the right order and reaches the right door
  • Payment status and amountFrom the payment partner, never the card itself
  • Your staff loginsSo each person sees only what their role allows

Never sees

  • Your personal account and private chatsOnly business accounts can be connected
  • Card numbers, PINs and bank loginsCustomers pay on the licensed partner’s own page
  • Your platform passwordAccounts connect through the platform’s own permission screen
  • Your customers’ contacts or other chatsOnly the conversation they started with you
  • Another seller’s dataEvery account is walled off from every other
How it is protected

Encrypted, walled off, and watched.

Encrypted in transit

Every connection to and from Tajami uses modern TLS — between the platforms, our servers, the payment partner and your phone. Nothing travels in the clear.

Encrypted at rest

Messages, catalogues, orders and backups are encrypted where they are stored, with keys kept in a managed key service — never in code.

Your connection, sealed

The token that links your business account is encrypted separately, and you can revoke it in one tap, from Tajami or from the platform itself.

One seller, one vault

Every record is tied to your business and checked in the database itself. One seller’s data never informs another’s answers or reports.

No standing staff access

Nobody at Tajami browses your chats. Support sees a conversation only with your consent, for a set time, and every access is logged.

Not training anyone’s model

The AI providers we use are contracted not to train on your data, and only the context one answer needs is ever sent to them.

Your controls

You decide who gets in, and you can see who did.

Your business account is your livelihood, so the locks are yours to hold.

  • Two-step sign-in, and required for the account owner.
  • Roles for your staff — an agent can reply, a manager can change prices, only you can touch payouts.
  • Every device and session, with sign-out everywhere in one tap if a phone goes missing.
  • An activity log — who sent which reply, who changed a price, who exported data.
  • Payout details guarded — changing them asks you to confirm again, tells you on another channel, and holds the first payout.
  • Disconnect, export or delete at any time, and access stops the moment you disconnect.
SecurityAll good
Two-step sign-in
On
Signed in on
2 devices
Tolu · Manager
prices, replies
Emeka · Agent
replies only
Support access
none granted
Sign out everywhereView activity
How long it is kept

Kept for as long as it is useful, and no longer.

The same periods the privacy policy sets out, enforced by scheduled deletion rather than by someone remembering.

WhatHow long
Customer messages and order historyAs long as you keep them; deleted when you delete them or close your account
Your account, after you close itUp to 90 days, so you can come back or export, then deleted
Payment and billing recordsAs long as tax and financial law requires — usually six years
Security logsUp to 12 months
If something goes wrong

You hear it from us first, in plain words.

No system is perfectly secure, and pretending otherwise is how trust is lost. This is what happens if something affects your data.

01

Contained

The cause is stopped and the evidence kept, by a named lead who is on call at every hour.

02

You are told without delay

What happened, what data, what we have done, and what you should do — including what you need to tell your own customers, if anything.

03

The regulator is told on time

Within the time the Nigeria Data Protection Act requires, and the same for each market we operate in.

04

What changed is written down

A review within two weeks, and for anything that affected sellers, a plain summary of what we changed so it cannot happen the same way again.

Where this actually is

What is built in, what comes before launch.

Tajami is being built now. This page says only what is true today, and it is updated as each piece ships.

From day one

Before any seller connects

Encryption in transit and at rest, sealed connection tokens, each seller walled off, no card data, no standing staff access, and no customer details written to logs.

Before launch

Tested by someone else

An independent penetration test, with every critical finding fixed first. Two-step required for owners, the activity log, export, a public status page, a data protection impact assessment and a named data protection officer.

Not claimed

Certification

Tajami claims no security certification yet. When an independent audit is under way, this page will say so, and name the auditor.

Report a vulnerability

Found something? Tell us first.

Write to security@tajami.com with what you found, how to reproduce it, and how to reach you.

  • Acknowledged within two working days, and assessed within five.
  • Kept informed until it is fixed, and thanked publicly if you would like to be.
  • No legal action for good-faith research that takes only what proves the issue, disrupts nothing, and gives us reasonable time to fix it.
  • No social engineering of sellers, customers or staff, and no access to data that is not yours.
/.well-known/security.txtContact: mailto:security@tajami.com
Policy: https://tajami.com/security#report
Preferred-Languages: en
Canonical: https://tajami.com/.well-known/security.txt
Questions

Asked before you connect anything.

Is it end-to-end encrypted?

No, and any service that answers your messages for you cannot honestly say it is. WhatsApp chats are end-to-end encrypted between people; when a customer messages a business that uses software to answer, the platform delivers the message to that software so it can reply. From there, Tajami keeps it encrypted in transit and at rest, readable only by the systems that answer it and by you.

Can Tajami staff read my customers’ messages?

Not by default. Nobody has standing access. Support can open a conversation only when you grant it, for a set time, and every access is logged. The only exceptions are a legal requirement or an active security incident, and those are logged too.

Where is my data stored?

With cloud providers, some of which store or process data outside Nigeria. Where that happens, the safeguards the law recognises apply, as the privacy policy explains.

What if my phone is stolen?

Sign in from another device and sign out everywhere in one tap. Two-step sign-in stops a stolen phone alone from getting in, and changing payout details asks you to confirm again and holds the first payout.

A customer asked me to delete their data. Can I?

Yes. You can delete a customer’s conversations and details from your account, and it is removed from Tajami too. Records the law requires us to keep, like payments, are kept only for as long as it requires.

What happens to my data if I leave?

Disconnecting stops all access at once. If you close your account, your data is kept for up to 90 days so you can come back or export it, and then deleted.