The safest money is money that stays in the bank. NuPay is built so school funds, card details and banking passwords never pass into our hands, and so every figure in the books can be traced back to where it came from.
NuPay handles the information about a payment. The institutions built to hold money handle the money.
Parents pay, the bank settles into the school’s own account, and NuPay reads the transaction. There is no NuPay wallet and no balance waiting to be paid out.
Card numbers and wallet PINs are entered on the payment gateway’s own secure page. NuPay receives the result of the payment, never the card.
A bank feed gives NuPay the transactions on the accounts the school has authorised. It cannot make a payment or move funds.
Most losses in a school accounts office are not break-ins. They are entries altered after the fact. NuPay is built so that a correction always leaves a mark.
School finance is audited by people who did not enter the transactions. NuPay’s Data Flow view shows them, action by action, exactly what the system did.
The school’s records are held on infrastructure built for banks and governments, close to home.
NuPay runs in Amazon Web Services’ Africa (Cape Town) region, so school records stay on the continent, in data centres with physical security and independent certification.
Everything between your browser and NuPay travels over an encrypted connection (TLS 1.2 or higher). Stored data, including backups, is encrypted with AES-256.
A full backup is taken daily at midnight and stored encrypted, so the school’s records can be restored if something goes wrong.
A password alone is not enough. Signing in to NuPay takes a second step, so a stolen or guessed password does not open the school’s books.
The school decides who has an account and what each person can do, so a clerk, a bursar and a head each see what their job needs.
Changes are run through end-to-end scenarios with system-wide checks: journals balance, sub-ledgers tie to their control accounts, cash reconciles.
Student, parent and fee records belong to the school. NuPay uses them only to provide the service, and never sells them or uses them for advertising.
Personal information is handled in line with the Cyber and Data Protection Act. The detail is in our privacy policy.
Good security is a partnership. A system can record who did what, but only the school can decide who should be allowed to.
Built into the product.
Good habits that no software can do for you.
No system can promise it will never be attacked. What we can promise is what happens next.
We isolate the affected systems, revoke the access involved and stop the incident from spreading.
We establish what happened, which schools are affected and what information was involved.
We tell each affected school and the Data Protection Authority within 24 hours of confirming a breach, and help the school inform the parents and students concerned.
We close the gap, restore from backup if records were damaged, and give the school a written account of what happened and what has changed.
Because NuPay never holds school funds or card details, a breach of NuPay cannot empty a school’s bank account or expose a parent’s card.
No. Payments settle directly in the school’s own bank account. NuPay never holds school funds; it reads the transaction so it can match it and keep the books.
No. The bank connection gives NuPay information about transactions on the accounts the school has authorised. It cannot make payments or transfers.
No. Parents enter card numbers and wallet PINs with the payment gateway. NuPay receives the result of the payment, not the card.
Not silently. A posted invoice or bill is voided with a reversal entry and the original is kept. An invoice that has a payment against it cannot be edited or voided.
On Amazon Web Services, in the Africa (Cape Town) region. Stored data is encrypted with AES-256, and everything sent between your browser and NuPay is encrypted with TLS 1.2 or higher.
Yes. A full backup is taken every day at midnight and stored encrypted, so records can be restored if something goes wrong.
No. NuPay uses two-step sign-in, so a stolen or guessed password is not enough on its own.
We contain it, establish what was affected, and notify each affected school and the Data Protection Authority within 24 hours of confirming it. We then help the school inform the people concerned and give a written account of what happened and what has changed.
The full trail. Every action is recorded, and the Data Flow view shows what each action wrote and what changed, down to the field. Any event can be exported.
The users the school has given accounts to, within the access their role allows. The school owns its data, and NuPay uses it only to provide the service, as set out in our privacy policy.
Contact us straight away. If you suspect someone has accessed an account they should not have, tell us and remove that user’s access.
We’ll post a payment in front of you and show exactly what the system recorded.