Security
How we approach the security of the platform and the data it carries.
Last updated: August 2026
Access control
Accounts support user roles and access management so organizations can control who can send, view reports and manage credentials.
Credentials
API access uses environment-scoped keys. Keys can be rotated, and should never be embedded in client-side code or shared outside your organization.
Data in transit
Traffic to platform interfaces is encrypted in transit using industry-standard transport security.
Monitoring
We monitor platform activity for abuse, unusual sending patterns and operational faults, and maintain access logs for investigation.
Responsible disclosure
If you believe you have found a security issue, report it to hello@pweza.co.tz with enough detail to reproduce it. Please do not disclose it publicly before we have had a chance to respond.
Certifications
We publish certifications and formal assurance reports only once they have been completed and independently verified.
PWEZA is a technology platform operated by DigiStorm (T) Limited. This page is provided for general information and does not constitute legal advice. Where services are subject to regulatory or licensing requirements, those requirements apply.