FAQ
Common questions before we talk
Answers to the questions we hear most from CIOs, CISOs, COOs and compliance teams before an engagement starts. Don't see yours? Reach out directly.
Do you only work with banks?
No. While Nigerian banks are our primary focus, we also work with fintechs, insurers, government institutions and other regulated businesses that need auditable, least-privilege access.
Do you work with organizations outside Nigeria?
Our team and current client base are based in Nigeria, and that's where our deepest regulatory expertise (CBN, NDPA) sits today. We're building toward supporting organizations elsewhere in West and East Africa as we take on work in those markets.
What environments do you support — on-prem, cloud, or both?
All three. We work with on-prem directories like Active Directory and LDAP, hybrid setups using directory sync and federation, and cloud platforms including Microsoft Entra ID, Okta, AWS and GCP IAM.
Do we have to adopt every module, or can we start with one?
Each module — IGA, PAM, SSO/MFA, CIAM, machine/third-party identity, compliance reporting, and managed services — can run on its own or as part of a combined program. Most engagements start with one or two priority modules and expand from there.
Will this replace the tools we already use?
Not necessarily. We work with widely used platforms such as SailPoint, CyberArk, Okta and Microsoft Entra, and typically integrate with what you already have rather than requiring a rip-and-replace.
How does an engagement typically start?
Most engagements begin with a scoping conversation to understand your current identity landscape and priority risks, followed by a focused pilot on one module before expanding into a broader program.
How long does a typical rollout take?
It depends on scope, but a focused pilot — for example, a single IGA or PAM rollout — often reaches a working first phase within weeks, with broader programs phased over months.
How do you handle our data and our compliance requirements as a vendor?
We take data protection as seriously as we ask our clients to. If you need details on our own data handling practices for a vendor risk assessment, contact us directly and we'll share what you need.