- Payments settle on a private chain. Checkout shows the company name, not the person who paid.
- There are no passwords. You sign in with a one-time email link, and there is no third-party login.
- Live money and live keys stay locked until you verify your name and country.
- Secret keys belong on your server. Webhooks must use https. Confirm every payment before you deliver.
- We never ask you to forward a sign-in link or share a secret key, M-Pesa PIN, or card security code.
- Found a weakness? Report it to supportnorashillings@benuru.com. Section 15 explains how.
01What this page is
This page describes how Nuru Shillings protects accounts, keys, and payments, what each side is responsible for, and how to report a problem. It applies to wallet holders, companies, and developers.
It is a description of the product’s controls. It is not a certificate from an auditor, it does not claim a banking licence, and it does not make Nuru a bank. The Terms of Service and the Privacy Notice also apply.
02Who is responsible for what
Security is shared. Nuru protects the Service; you protect your sign-in, your keys, and your own platform.
| Area | Nuru does | You do |
|---|---|---|
| Sign-in | Sends one-time links that expire in 20 minutes; stores only hashes; offers no third-party login | Keep your email account secure; log out on shared devices |
| Verification | Locks live money and live keys until you verify | Give a true name and country |
| API keys | Separates test and live keys; creates a live key only after verification; stores keys as hashes | Keep keys on your server; report a leak at once |
| Payments | Records the status, amount, company, and reference; settles privately | Store your reference; deliver only when paid |
| Webhooks | Accepts https endpoints only; sends the payment id so you can confirm it | Confirm with GET /v1/payments/:id; ignore duplicates |
| Your platform | — | Secure your own servers, accounts, and customer data |
03Private settlement
A paid payment is marked chain: "private". It is not written to a public ledger, so no one can read a public chain to trace who paid whom. The company, the buyer, and Nuru can still match the payment id to the reference the company stored, which is what refunds and support need.
04What checkout shows
Checkout shows the company name and the amount. It does not show the name of the person who paid. The payment fields are limited to amount, unit, reference, and company. A platform should keep it that way: do not place a buyer’s name, email, or phone number inside the reference.
05Earnings
Nuru does not hold a company’s earnings on a card network that can freeze the payout. A company receives the amount of each paid payment less the 1% fee. Refunds are made by payment id and return both the amount and the fee. A buyer can sell back and withdraw to PayPal, a card, or M-Pesa at 100 Nuru Shillings to 1 US dollar.
06Account protection
Email sign-in links
There are no passwords, so there is no password to guess, reuse, or leak. To sign in, you enter your email and we send a link. The link works once and expires after 20 minutes. We store only a one-way SHA-256 hash of it.
The secret part of the link sits after the # in the address. Browsers do not send that part to servers, so email security scanners that open links cannot use it up. The page sends it to Nuru only when you open it yourself.
Anyone who can read your email can sign in, so protect your email account with a strong password and two-step verification. There is no sign-in through Google or any other company.
Limits
We limit how many links can be requested for one email address and from one IP address in a short time. A hidden form field also catches automated form-fillers. Together they stop simple scripts from opening accounts in bulk or flooding an inbox.
Sessions
A session is kept in an HttpOnly, Secure cookie that page scripts cannot read. It lasts up to 30 days on that device, or until you log out. Logging out ends the session on our servers at once. Always log out on a shared or public computer.
07The verification gate
Until you verify the name on the account and your country, a wallet cannot add, send, pay, or withdraw live money, and Business tools cannot create a live key. Sandbox and the test key work before verification and can never move a live balance. Verification is free and done once.
08API keys
| Key | Prefix | Moves live money | Available |
|---|---|---|---|
| Test key | nsh_test_ | No | Any time, in Sandbox |
| Live key | nsh_live_ | Yes | After verification |
- A key is shown in full once, when you create it. Nuru keeps only a one-way hash and the last four characters, so we cannot show it to you again. Copy it straight into your server’s settings.
- Keep secret keys in server-side environment variables or a secrets manager.
- Never place a key in a web page, a mobile app bundle, a browser extension, a public repository, a screenshot, or an email.
- Give access to the live key only to the people who need it.
- Use the test key in development and continuous integration.
- If a key may be exposed, open Business tools and choose Replace key. The old key stops working at once. Do not send the key itself to anyone, including us.
09Calling the API safely
- Call
https://norashillings.benuru.com/v1from your server only, over https. - Send the key in the header:
Authorization: Bearer nsh_live_…. - Send amounts as strings of Nuru Shillings, for example
"1800", to avoid rounding errors. - Use your own unique
referenceper order, and check it before creating a second payment for the same order. - Treat any status other than
paidas not paid.
10Webhooks
Nuru sends payment.paid and payment.refunded to the endpoint you save with POST /v1/webhooks. The endpoint must use https and a public host name; addresses on private networks are refused. Nuru waits up to 5 seconds for a reply and records whether delivery succeeded. Each event carries the event id, the type, the payment id, the reference, and the status.
- Fulfil an order from the webhook, never from a browser redirect, which a user can fake.
- Before you deliver, confirm the payment with
GET /v1/payments/:idusing your secret key. - Check that the payment’s
referenceandamountmatch the order you stored. - Record the event id and ignore an event you have already processed.
- Reply with a 2xx status quickly and do slow work afterwards.
- Use
POST /v1/webhooks/testto check your endpoint before going live.
11Go-live checklist
- Your account is verified and the live key is stored on the server only.
- No key appears in client code, logs, or your repository history.
- Your webhook endpoint uses https and passes the test event.
- Orders are delivered only after a confirmed
paidstatus. - Duplicate events cannot deliver an order twice.
- Refunds use the original payment id.
- Your checkout shows your company name, your terms, and your refund policy.
- The payment reference holds an order id, not personal data.
12Fraud and abuse
We may refuse a payment, limit requests, or suspend an account to stop fraud, stolen payment methods, scripted sign-ups, or any use the Terms prohibit. A refused payment does not move a balance and is free. If you believe a payment was refused by mistake, write to us with the payment id and a person will review it.
13Phishing and impersonation
Nuru will never ask you to forward a sign-in link, or for your secret API key, your M-Pesa PIN, your card security code, or a one-time code from your bank. We will not ask you to move your balance to “protect” it.
Real sign-in links always open norashillings.benuru.com. Before you open one, check the address it points to, and never open a sign-in email you did not ask for. If you receive a message that claims to be from Nuru and asks for any of these, do not reply. Forward it to supportnorashillings@benuru.com.
14If there is an incident
If we find a security incident, we act to contain it, investigate what was affected, and fix the cause. If it affects your account or personal information, we will tell you without undue delay, explain what happened and what you should do, and notify the relevant authority where the law requires.
15Reporting a vulnerability
If you believe you have found a security weakness in Nuru, email supportnorashillings@benuru.com with the subject line “Security report”. Please include:
- a description of the issue and its possible impact;
- the steps to reproduce it, and the page or API route involved;
- how we can contact you.
What we ask of you
- Test only against your own account and the test key.
- Do not access, change, or delete data that is not yours.
- Do not run denial-of-service tests, spam, or social engineering against people.
- Give us reasonable time to fix the issue before you tell anyone else.
What we commit to
- We will acknowledge your report within 5 business days.
- We will keep you updated while we work on it and tell you when it is fixed.
- If you act in good faith and follow these rules, we will not pursue legal action against you for your research.
16Limits of this page
This page states the product rules and the controls Nuru is built around. It does not claim a banking licence, deposit insurance, or a completed third-party audit. The commitments you can rely on are the ones written here and in the Terms: the rate is fixed at 100 NSH = 1 USD, settlement is private, checkout shows the company name, live money waits for verification, and a refund uses the original payment id.
17Contact
Security reports and account help: supportnorashillings@benuru.com. Include the payment id if it is about a payment. Never send a sign-in link or a secret key.
Nuru Shillings · Security · Version 10 October 2026