Security
Last updated: 17 August 2026
Most of what protects your money at Zend is structural. We hold naira, not crypto, so there is no crypto balance in your account to steal, and every transfer out needs your transaction PIN. This page sets out the rest: the controls you have, what we do on our side, and the messages that are always a scam.
Zend will never ask you for your password, your transaction PIN, or a one-time code. Not by phone, not by email, not in a DM. Anyone who does is stealing from you, whatever name they use.
Where your money actually sits
Your Zend balance is naira, and only naira. It is not a crypto balance shown in naira, and it is not a claim on a coin we are holding somewhere on your behalf.
That single fact removes most of the ways a crypto business loses customer money. There is no hot wallet holding user balances, so there is nothing to drain. There is no exchange position to go wrong. A collapse in the price of an asset you sent us last week does not touch the naira it already became.
Naira balances sit with our regulated banking partners, not on our own books as a pooled trading float.
Why the app has no buy button
Zend never holds crypto for you. Crypto you deposit becomes spendable naira the moment it lands, and you cannot buy crypto through us or keep a crypto balance. You can send stablecoins out: choose USDT or USDC, and Zend converts from your naira at the point of transfer.
This is a security decision as much as a product one. There is no crypto balance sitting in your account for an attacker to move. Naira can be sent to any bank account or out as stablecoins, so what protects it is your transaction PIN: every transfer needs it, it is separate from your password, and someone who gets into your account without it still cannot send anything.
It also means a converted deposit is final. We cannot reverse a conversion, and neither can anyone who gets into your account.
Protecting your account
Four controls, all in Profile → Security & PIN:
- Password: stored hashed, never in readable form. We could not tell you your own password if you asked.
- Transaction PIN: a separate code required to move money. Someone who learns your password still cannot send anything without it.
- Biometric login: Face ID or fingerprint, handled by your phone's secure hardware. Zend never receives your biometric data.
- Two-factor authentication: an extra step at login, on top of the password.
Turn on both biometric login and two-factor authentication. They defend different doors: biometrics protect the phone in someone's hand, 2FA protects the account from someone who has your password but not your phone.
Card controls
No Zend card holds a balance. Every authorisation is debited from your naira wallet at the moment it happens, so a stolen card cannot spend more than your wallet holds, and a wallet you have emptied cannot be spent from at all.
From Cards you can, instantly:
- Freeze and unfreeze a card. A frozen card declines everything and can be unfrozen just as fast, so freezing a card you have merely misplaced costs you nothing.
- Switch international payments, online payments and ATM withdrawals on or off independently. Most card fraud arrives through one channel; turning off the ones you do not use closes it.
- Set a spending limit, capping what the card can move regardless of your wallet balance.
- Change the card PIN.
Cards are issued by our card partner, and card numbers are held in their PCI-compliant environment rather than ours.
Encryption and infrastructure
All traffic between the app and our servers runs over TLS. Data is encrypted at rest. Passwords and PINs are stored as one-way hashes, so a copy of the database does not yield either.
Access to production systems is restricted to the people who need it, requires its own authentication, and is logged. Card details and identity documents are held by the specialist providers that handle them rather than duplicated into our own systems wherever that is avoidable.
Monitoring and screening
Every account is verified before it can transact, and transactions are screened for fraud, sanctions and the patterns associated with laundering. Deposits are checked against the network they arrived on, and unusual activity can hold a transaction or an account while we look at it.
This occasionally inconveniences people who have done nothing wrong. We would rather ask you a question about a transaction than let a stolen card or a laundered deposit through, and we will always tell you why we are asking when the law allows us to.
What Zend will never ask you for
Almost every account takeover in this market starts with a convincing message, not a broken system. So this list is worth memorising:
- We will never ask for your password, your transaction PIN, or a one-time code. Not by phone, not by email, not on WhatsApp, not in a DM, and not in live chat.
- We will never ask you to install remote-access or screen-sharing software.
- We will never ask you to move your money to a "safe" or "verification" account. There is no such thing.
- We will never contact you first to offer a better rate, a refund, or an unlock in exchange for a payment.
- Our support address is support@zend.africa. Anything from a lookalike domain is not us.
Anyone asking you for those things is stealing from you, whatever name they are using. Stop, and email us.
What you can do
- Use a password you use on no other site. Reused passwords are how breaches elsewhere become losses here.
- Turn on two-factor authentication and biometric login.
- Set a transaction PIN that is not your birth year, your phone number, or your card PIN.
- Keep card channels you do not use switched off, and freeze a card the moment you cannot find it.
- Check the asset and network before sending a deposit. Crypto sent on the wrong network is generally gone for good. That is the blockchain's rule, not ours.
- Keep your phone's operating system and the Zend app updated.
If your phone is lost or your account is compromised
Move in this order:
- Freeze your cards from any device you can log in on.
- Change your password, which ends other sessions.
- Email support@zend.africa from the address on the account, with your account email and anything you know about what happened.
If you cannot get in at all, email us anyway, because we can lock the account from our side. Tell us early rather than accurately; we would far rather investigate a false alarm than start an hour late.
Reporting a vulnerability
If you have found a security flaw in the Zend app, this website or our APIs, we want to hear about it. Email security@zend.africa with enough detail to reproduce it, and give us a reasonable window to fix it before you publish.
We will acknowledge your report, keep you updated, and we will not pursue legal action against researchers who act in good faith: test only against your own account, do not access, alter or destroy anyone else's data, do not degrade the service, and do not use social engineering or physical attacks against our staff or partners.
We do not currently run a paid bounty programme, and we will say so plainly rather than imply one.
Contact
Security reports: security@zend.africa
Fraud, lost devices and account trouble: support@zend.africa