Security overview
Last updated May 2026. This overview summarises PACIN's security practices for institutional buyers and compliance teams.
Security posture
PACIN is built for regulated lending institutions. We apply defense-in-depth controls across authentication, API access, data processing, and operational monitoring.
Access and authentication
Institutional accounts use email verification, role-based access, and audited sign-in events. Sessions are encrypted in transit (TLS) and scoped to your organisation.
Two-factor authentication for institutional users is on our roadmap for general availability.
Consent and data handling
Every score requires documented borrower consent before data ingestion. Consent records, model versions, and provenance metadata are retained for audit.
Data is processed only for authorised underwriting and risk workflows defined in your institution agreement.
Encryption and infrastructure
Data in transit is protected with TLS 1.2+. Sensitive credentials and tokens are stored using industry-standard hashing and secret management practices.
Production infrastructure is hosted on managed cloud services with network isolation, monitoring, and regular patching.
Audit and compliance alignment
Platform operations are logged with timestamps, actor identity, and API context. We align controls with expectations under Kenya DPA, Nigeria NDPR, and Rwanda Data Protection Law.
Institutions may request security documentation, subprocessors list, and data processing addenda via contact@pacinnetwork.com.
Incident response
We maintain incident response procedures and publish service status at /status. Material incidents affecting availability or confidentiality are communicated to affected institutions.