This page is maintained by Omega Allied Services LTD, the operator of PayKato, to answer common security and privacy questions about the product. It describes the controls we currently have in place — it is not an independent certification or audit report.
Merchants sign in with email and password through our authentication provider. Sessions are managed with signed tokens, and password resets are sent to the verified email on file.
Each merchant account is scoped to its own data — one merchant cannot read or modify another merchant's records.
PayKato does not store raw card numbers, CVVs, or bank credentials. PayKato is built to integrate with licensed payment processors and banking partners. Specific processors and availability are confirmed during onboarding based on country, merchant category, and partner approval. All card and bank payments are processed on hosted checkout pages operated by the relevant partner.
PayKato is not a bank and does not hold customer funds. Settlement, FX, and payouts are performed by the relevant partner under their licences.
PayKato platform fee from 1.5%. Processor, FX, payout, bank, and country-specific fees may apply. Final settlement amounts depend on the payment method, currency, and partner used for each transaction.
There are no monthly or setup fees to create a PayKato account.
Application data is stored in a managed Postgres database with encryption at rest and TLS in transit. Access to production data is limited to the operator of Omega Allied Services LTD.
Row-level access rules enforce that each merchant can only read or write their own merchants, payment links, invoices, and transactions.
Personal and business data submitted during merchant onboarding (name, email, ID, CAC details, bank account, address) is used only to verify the merchant, operate the PayKato service, and meet anti-money-laundering obligations.
We do not sell merchant or customer data. KYC documents and bank details are not shared with third parties other than the licensed payment, banking, and verification partners that are required to process the merchant's payments and payouts.
Transport between your browser and PayKato uses HTTPS / TLS. Stored data sits in a managed database with encryption at rest. Secrets, API keys, and partner credentials are stored as managed secrets and are not exposed in client code.
Production access is limited to the operator of Omega Allied Services LTD. Administrative access uses strong, unique credentials and is reviewed on a recurring basis.
Inside the application, row-level rules enforce that each merchant can only see their own records. Service-role keys that bypass these rules are only used in server functions and webhook handlers, never shipped to the browser.
Webhook endpoints from payment partners are verified by signature before any data is processed, so a forged callback cannot mark an unpaid invoice as paid.
Every merchant completes identity and business verification before live payment access is enabled. PayKato screens merchant categories against a prohibited-business list and may decline applications that fall outside supported categories.
Transactions are monitored for unusual patterns — for example, sudden volume spikes, repeated declines, mismatched buyer-seller geographies, and high dispute or chargeback rates. Suspicious activity may trigger additional review, temporary holds, or payout pauses.
Chargebacks and refunds are tracked at the merchant level. High dispute exposure may lead to reserves or restrictions in line with the Reserve & Hold Policy and the Chargeback Policy.
Card processing, 3-D Secure, and issuer-side fraud checks are handled by the licensed payment processor on each transaction.
PayKato is built to integrate with licensed payment processors and banking partners to move money, process cards, and settle payouts. We only mark a partner as live when the integration is generally available to approved merchants. Infrastructure and verification services are live as part of running the application.
View full partner status table
These partners are subject to their own privacy and security terms, which apply to the data they process on our behalf.
PayKato is operated by Omega Allied Services LTD, a company registered in Nigeria.
During the pilot we share the full CAC certificate privately with verified merchants and partners rather than displaying it on a public marketing page. This protects against impersonation while still being verifiable on request.
You don't have to take our word for it. Here is how to independently verify PayKato before signing up:
PayKato is built and operated by the founding team at Omega Allied Services LTD, based in Abuja, Nigeria. The team has direct operating experience with African cross-border payments, merchant onboarding, and compliance.
We sign every customer-facing email with a real name — not "The PayKato Team". For founder, press, or partnership enquiries, write to support@paykato.com and we'll route you to the right person and share a LinkedIn profile.
Detailed founder bios and headshots will be published on the About page as the team grows.
Every PayKato policy is published in full. Read before you sign up:
Want to see PayKato before applying? You can:
A recorded demo video will be added here once the pilot dashboard UI is locked.
PayKato is in a limited Nigeria pilot. We will only publish testimonials from real, named pilot merchants — with their permission and a link back to their business — rather than stock quotes or fake reviews.
No testimonials yet. If you're a pilot merchant and would like to be featured, email support@paykato.com.
PayKato is currently in closed pilot with a limited number of Nigerian merchants. We are intentionally onboarding slowly so that every merchant gets hands-on support from the founding team.
To request a spot, join the beta waitlist. We share live pilot numbers (merchants onboarded, transactions processed) privately with prospective partners and investors on request.
Current platform status and incident history will be published at status.paykato.com.
The status page is planned for a future release; if it is not yet live, check this page or contact support for uptime questions.
We use strictly necessary cookies to keep you signed in. We do not load third-party advertising trackers on the PayKato dashboard or checkout pages.
Transaction and customer records are retained for 7 years after a merchant account is closed, to meet tax, accounting, and anti-money-laundering obligations.
Merchants can request export or deletion of personal data (subject to the retention obligations above) by contacting us through the form below.
If you believe you've found a security issue, please report it to security@paykato.com or use the contact form with the subject "Security report". Please include reproduction steps and your contact details so we can follow up.
We ask that you give us a reasonable opportunity to investigate and remediate before any public disclosure, and that you do not access data that does not belong to you.
For general support and privacy enquiries, contact support@paykato.com. For security-specific reports, use security@paykato.com.
We aim to acknowledge messages within two business days.