What this guide answers
These are the questions people tend to ask first—whether they find this page on search or someone forwards the link. Skim the list, then read at your own pace. The headings below come back to each topic with plain language, examples, and habits you can reuse in your own circle chat.
- What kinds of circle data does Sousou focus on—and what should never live in chat?
- How are transport, storage, and least-privilege access designed to reduce breach impact?
- What are members and admins responsible for on devices, passwords, and phishing?
- What should you do immediately if you suspect unauthorised access or a scam DM?
- Why do backups, vendor transparency, and youth safeguards matter for community finance apps?
These guides use a calm, practical tone on purpose: money and friendships in the same room deserve clarity, not hype.
Security is never “finished”—it is a set of practices that evolve with threats. Sousou combines technical safeguards with clear product boundaries so you know what the platform protects and what still depends on your device hygiene and member choices.
What Sousou stores—and what should stay private
Sousou focuses on information needed to operate circles: identities for authentication, circle metadata, schedules, statuses, and audit history. The product does not need full card numbers for members to track contributions; payment credentials belong with regulated processors when you purchase paid features, not in casual chat logs. Avoid pasting PANs or PINs anywhere in circle messages—ever.
Transport and storage
Traffic between your browser or app and our services should use modern TLS configurations; stored secrets should be hashed or tokenised per industry norms. Infrastructure providers undergo regular patching and monitoring. No stack is perfect, but defence-in-depth reduces blast radius when issues arise.
Roles and least privilege
Members should see their circles—not everyone else’s. Admins see operational views appropriate to their duties. Platform operators may access limited diagnostic data for support tickets, but bulk browsing of private circles should be policy-prohibited and technically constrained. Ask your vendor for a clear data processing agreement if you run enterprise programmes.
Your responsibilities as a user
Use unique passwords, enable device encryption, log out on shared tablets, and verify links before signing in. Social engineering targets community finance because emotions run high. If someone DMs “urgent verification,” assume scam until proven otherwise through an official channel.
Incident mindset
If you suspect unauthorised access, rotate passwords, revoke sessions, and notify support with timestamps. Preserve screenshots of suspicious messages. Rapid reporting helps investigators correlate events across accounts.
Device hygiene checklist for members
- OS updates applied quarterly at minimum.
- Biometric lock enabled on phones holding finance apps.
- No sideloaded APKs promising “free sousou credits.”
- Separate work and personal profiles if employer MDM applies.
Vendor and subprocessors (conceptual)
Cloud hosting, email delivery, analytics, and crash reporting may each process fragments of operational data under strict contracts. Your privacy policy should name categories even when vendor names rotate. Transparency about categories beats silence, which breeds rumours.
Backups, restores, and disaster recovery expectations
Ask your provider how often backups run and how member data is deleted upon account closure. Export your own circle archives periodically if policy allows—USB drives still beat ransomware when cloud restores lag. Practice restoring one test export annually so you are not learning the UI during a crisis.
Children’s accounts and guardianship
Minors should participate only with guardian oversight and amounts appropriate to pocket money lessons—not adult-sized pots. Document parental consent where required. Sousou accounts tied to schools or youth clubs need extra care: predators mimic finance apps, so teach kids to verify URLs and never share OTP codes.
Publish a simple “threat menu” for members: fake refund sites, cloned apps, romance-plus-sousou hybrid scams. Rotate examples quarterly because fraudsters refresh scripts. When in doubt, members should screenshot, block, and ask a steward before sending credentials anywhere.
Security is a shared contract between platform and community—honour both sides.