Security

How we protect your account and the money records of every group.

Last updated: 23 September 2026

Account security

  • Passwords of at least 10 characters; sign-in locks for 15 minutes after 5 failed attempts.
  • Sessions in secure HTTP-only cookies with a maximum lifetime; you can see and end any session.
  • Password, email, phone and payout-account changes require your password and a one-time security code, and always trigger a notification.
  • New-device sign-in alerts.

Identity verification

Organisers and collectors must verify a government ID and accept a written undertaking before handling other people's money. Collectors are also approved by our compliance team.

Financial traceability

Every payment is confirmed with Paystack by our servers. Each ledger entry records who, what, when, how and where to. Records cannot be edited or deleted; corrections are separate linked entries approved by two authorised staff members.

Fraud prevention

We hold payouts for review when there are risk signals — such as a recently changed payout account, an unverified recipient or a large amount — and we review repeated complaints about a collector. Reviews use neutral language and explainable reasons; a review is not an accusation.

Security monitoring

We record security events such as repeated failed sign-ins or verification codes, new devices and payout-account changes, and investigate them.

Staff access

Staff have only the permissions their role needs. Viewing private information requires a recorded reason, sensitive actions require re-entering a password, and every action is audited.

Reporting an incident

If you think your account has been accessed by someone else, change your password, sign out other sessions, and open a case with the category “Someone else accessed my account”.

Responsible disclosure

If you believe you have found a security vulnerability in ACHIEVER, email stlsupport1515@gmail.com with the subject “Security report”. Please do not access other users' data, disrupt the service or publicly disclose the issue before we have had a reasonable time to fix it. We will acknowledge valid reports.