Severus

TRUST

Security at Severus.

Approvals authorise payouts. We treat the surface area that supports that decision — auth, data, audit — as a primary product, not a checkbox.

Last revised 07 May 2026 · Questions? Email support

Architecture

Severus runs a two-tier architecture: a gateway service that terminates customer traffic and a canonical core service that owns the data model. The gateway is what your browser talks to; the core service is private and never exposed to the public internet directly.

Authentication

Data protection

Audit & monitoring

Every approval, disbursement, admin change, and authentication event is recorded to a tamper-evident audit log retained for at least 7 years. The log is read-only inside the product; unredacted exports are available to admins for compliance use.

Incident response

Customer-impacting incidents are tracked publicly on status.severus.ng. We commit to a postmortem within five business days for any sev-1 / sev-2 incident, posted to the same channel.

Reporting issues

Email security@severus.ng with any vulnerability disclosure. We respond within one business day. Please do not file public issues — we coordinate disclosure timelines with affected customers first.