Security
Last updated September 2026
How we protect your money, your meter and your data โ and what we ask of you in return.
Signing in
meter.ng has no passwords. You sign in with a code sent to your phone, which means there's no password to be guessed, reused or leaked in someone else's breach. Codes are single-use and expire quickly.
Your card details
Card payments are handled inside Paystack's own checkout. Your card number, expiry and CVV never touch our servers, so they can't be exposed by us. We only ever see that a payment succeeded and for how much.
Your tokens and data
- Traffic between your device and meter.ng is encrypted in transit with TLS.
- Electricity tokens are encrypted where they're stored, so a copy of the database alone doesn't expose them.
- Payment notifications from our providers are cryptographically signed, and we reject any that don't verify โ so a forged 'payment received' message can't credit an account.
- Every purchase carries a unique key, so a retry or a double-tap can't charge you twice or vend twice.
What we ask of you
- Keep control of your phone number โ it's the key to your account.
- Never share a login code. We will never ask you for one, by call, SMS or WhatsApp.
- Check the meter number before paying. Tokens are issued against the number you enter.
Reporting a problem
If you've found a vulnerability, we want to hear about it before anyone else does. Email hello@meter.ng with enough detail to reproduce it. Please don't test against other people's accounts or run anything that degrades the service for real customers. We'll acknowledge you and keep you posted on the fix.