Security Policy

Last updated: 1 August 2026

How tickets are protected

Every ticket QR code is a cryptographically signed token, generated and verified server-side. A ticket is atomically marked used the instant it's scanned, so the same code - even from a saved screenshot - cannot be scanned in twice.

How payments are protected

Mobile Money and card payment collection is handled by our payment processor, Moolre; Nsaa does not collect or store your Mobile Money PIN or full card number. A payment is never marked successful based on a webhook notification alone - we independently re-check the payment's status directly against Moolre's own systems before an order is ever confirmed paid or a ticket issued.

Reporting a vulnerability

If you believe you've found a security vulnerability in Nsaa, please report it privately to our team rather than disclosing it publicly, and give us a reasonable amount of time to investigate and address it before any public disclosure.