Trust

Security

How we approach the security of the platform and the data it carries.

Last updated: August 2026

Access control

Accounts support user roles and access management so organizations can control who can send, view reports and manage credentials.

Credentials

API access uses environment-scoped keys. Keys can be rotated, and should never be embedded in client-side code or shared outside your organization.

Data in transit

Traffic to platform interfaces is encrypted in transit using industry-standard transport security.

Monitoring

We monitor platform activity for abuse, unusual sending patterns and operational faults, and maintain access logs for investigation.

Responsible disclosure

If you believe you have found a security issue, report it to hello@pweza.co.tz with enough detail to reproduce it. Please do not disclose it publicly before we have had a chance to respond.

Certifications

We publish certifications and formal assurance reports only once they have been completed and independently verified.

PWEZA is a technology platform operated by DigiStorm (T) Limited. This page is provided for general information and does not constitute legal advice. Where services are subject to regulatory or licensing requirements, those requirements apply.