Security
Security at LoDuko
Last updated: May 2026
LoDuko is a product of TopTech Innovations Hub Ltd. TopTech Innovations Hub Ltd is responsible for the security of the platform. This page describes the practices we operate today. It is a statement of our own commitments, not a third-party certification.
Data in transit
All traffic between your browser and LoDuko is served over HTTPS with modern TLS. We do not serve the application over unencrypted connections.
Accounts and access
- Authentication is handled by our managed authentication provider; we never store your password in plain text.
- Your projects and reports are scoped to your account and organisation, and access rules are enforced on the server for every request.
- Internal access to production data is limited to team members who need it to operate and support the service.
Payments
Payments are processed by Flutterwave. Card details are entered on the processor's hosted checkout and never reach LoDuko's servers. We store only transaction metadata — reference, amount, currency and status — so we can show your payment history and grant access to what you bought. Payment notifications we receive are cryptographically verified before they are trusted.
Your business inputs and AI
The answers you give in the guided interview are sent to our AI provider solely to generate your reports. We do not sell your inputs and we do not use them to train third-party models.
Infrastructure
LoDuko runs on reputable managed cloud infrastructure with automated backups of the primary database. Secrets and API keys are stored in managed secret storage and are never committed to source code.
Reporting a vulnerability
If you believe you have found a security issue, email hello@loduko.com with the subject line “Security”. Please include the steps to reproduce and give us a reasonable opportunity to fix the issue before disclosing it publicly. Do not access, modify or exfiltrate data belonging to other users while testing. We acknowledge reports within 2 business days.
Your part
Use a strong, unique password, keep your email account secure, and sign out on shared devices. Contact us immediately if you suspect unauthorised access to your account.