BilaFundi Security
Legal & Policies

Security

Last updated 09 August 2026 BilaFundi Technologies Ltd

Our Commitment to Security

BilaFundi takes the security of your data seriously. We apply industry-standard controls to protect the platform and our users' information, wherever they are in the world.

Infrastructure

  • Encryption in transit: all traffic is served over HTTPS/TLS
  • Cloud hosting: our infrastructure runs on DigitalOcean, with automated deployments and database backups
  • Access controls: production systems are accessible only to authorised engineers, over SSH with key-based authentication

Application Security

  • Protections against common web vulnerabilities, including SQL injection, XSS, and CSRF
  • Rate limiting on authentication and other sensitive endpoints
  • Google reCAPTCHA on login/registration to deter automated abuse
  • Regular dependency updates and security patches
  • Passwords are never stored in plain text — they are hashed using industry-standard algorithms

Payment Security

BilaFundi does not store your full card or mobile-money details. All payments are processed by our payment gateway, Pesapal, which handles cardholder data under its own compliance obligations. We store only transaction references and status.

AI Features

Our Cost Estimator and AI support features send the relevant text you submit to our third-party AI providers (currently Anthropic and Google) solely to generate a response, under those providers' enterprise data-handling terms. See our Privacy Policy for details.

Account Security Tips

  • Use a strong, unique password for your BilaFundi account
  • Never share your login credentials with anyone
  • Log out on shared or public devices
  • Contact us immediately if you notice suspicious activity on your account

Reporting a Vulnerability

If you discover a security vulnerability in BilaFundi, please report it responsibly by emailing info@bilafundi.com with:

  • A description of the vulnerability
  • Steps to reproduce it
  • Its potential impact

We will acknowledge reports within 48 hours and aim to resolve confirmed vulnerabilities promptly. We will not pursue legal action against researchers who report vulnerabilities in good faith and give us a reasonable opportunity to fix them before public disclosure.

Contact

Security or data protection concerns: info@bilafundi.com