Security Policy
Last updated: 1 August 2026
How tickets are protected
Every ticket QR code is a cryptographically signed token, generated and verified server-side. A ticket is atomically marked used the instant it's scanned, so the same code - even from a saved screenshot - cannot be scanned in twice.
How payments are protected
Mobile Money and card payment collection is handled by our payment processor, Moolre; Nsaa does not collect or store your Mobile Money PIN or full card number. A payment is never marked successful based on a webhook notification alone - we independently re-check the payment's status directly against Moolre's own systems before an order is ever confirmed paid or a ticket issued.
Reporting a vulnerability
If you believe you've found a security vulnerability in Nsaa, please report it privately to our team rather than disclosing it publicly, and give us a reasonable amount of time to investigate and address it before any public disclosure.