Security
Security and data protection in SaccoMonitor
A SACCO system holds members’ savings records and personal details. SaccoMonitor protects them with controls on who can do what, a permanent record of every change, and careful handling of sign-ins and data.
Controls on money
- Role-based access. Each action needs a specific permission; SACCOs build roles from a fixed catalogue and the server enforces them on every request.
- Maker–checker. The officer who captures a loan application cannot approve it, nobody approves or disburses their own loan, and withdrawals above the SACCO’s limit need a second officer.
- Approval levels. Larger loans need more sign-offs, by role.
- Reversals, not deletions. Posted transactions and journals are never edited or removed; corrections are separate, linked entries.
- Closed periods. Once an accounting period is closed, nothing can be posted into it.
- Double submissions. A repeated click or a network retry cannot post the same transaction twice.
A complete audit trail
Changes to members, accounts, loans, transactions, staff, roles and settings are recorded with who made them, when, from which IP address and device, and the values before and after. Sign-ins, failed attempts and password events are logged separately. Auditors can export both.
Sign-in and sessions
Data separation and privacy
Each SACCO’s records are kept separate from every other SACCO’s, and members can only ever see their own accounts. Private screens, the member portal and the API are excluded from search engines, and API responses are marked not to be cached. How personal data is used is described in the privacy policy.
Shared responsibility
Frequently asked questions
Run your SACCO on clear, balanced books
Register your SACCO, import your members from Excel and post your first deposit the same day.