Skip to content

Loan management for Kenyan lenders

Your loan book and your ledger, finally the same number.

One system for microfinance companies, SACCOs and digital lenders in Kenya: paybill payments matched to loans automatically, real double-entry books written at the same moment, and every branch and officer reporting the same way.

A 30-minute walkthrough on your own numbers. No card, no obligation.

Portfolio dashboard · all branches, consolidated
The portfolio dashboard: total loaned out KES 803,000.00, principal repaid KES 141,334.63, interest earned KES 38,097.33, portfolio outstanding KES 661,665.37, with collections, income and client counts beneath.

Built for the Kenyan market, not translated into it

M-PESA Daraja
C2B collections and B2C disbursement on your own shortcode.
DTB
Bank statement import and reconciliation against the ledger.
KRA · SHIF · NSSF
Payroll that deducts what Kenyan payroll has to deduct.
Data Protection Act 2019
Built to the Act, with a DPA you can hand to your lawyer.

Why lenders move

Three things go wrong on almost every book we are shown.

Not because anyone is careless. Because the loan system, the bank, and the accounts were never the same system, and someone has to hold them together by hand.

“Payments come in on the paybill and someone matches them by hand.”

A statement is exported, a spreadsheet is opened, and account numbers are read off a screen and typed into a loan. It works until it is month end, or the person is on leave, or there are four hundred payments instead of forty.

What it costs: Two days a month, and the errors nobody finds

“The books and the loan system disagree at month end.”

The loan module says one figure for interest earned, the accounts say another, and the difference is reconciled by whoever is most confident. A board pack is produced from the one that looks right.

What it costs: Numbers you cannot defend to a board or an auditor

“Every branch reports differently.”

Mombasa sends a spreadsheet, Nakuru sends a WhatsApp message, and head office rebuilds both into a third format. By the time it is consolidated the position is a week old.

What it costs: Decisions made on last week's portfolio

The product

Four screens, and what each one removes from your week.

These are photographs of the running system, not drawings of it. The numbers in them come out of a book that balances.

Origination & approvals

From application to disbursement, with someone accountable at each step.

Capture the client once, run the application through the approval queue, and disburse. Approvals are maker-checker: the officer who creates a disbursement is not the one who releases it, and the schedule, the processing fee and the guarantors are all fixed at the moment money leaves.

  • Flat or reducing balance, any term, fees and penalties per product
  • Approval queue with maker-checker, so nobody approves their own file
  • Top-up, reschedule, settle, reassign and write-off — each one journalled
  • Guarantors, collateral and documents attached to the loan, not to an email
Loan LN-00001 · schedule, balances and guarantors
A loan record showing terms of KES 60,000.00 principal at 5% per month flat over six months, outstanding balances, a six-row repayment schedule with two instalments paid, and a guarantor.

Repayments & M-PESA

The paybill payment finds its own loan.

We register the Daraja C2B callback against your shortcode. A payment that carries a recognisable account number is matched to the loan, applied to the schedule in order, and posted to the ledger — in one movement, without anyone typing it. What cannot be matched goes to suspense for a human to decide, because a guess is worse than a queue.

  • C2B collections matched automatically; B2C to disburse from the system
  • Unmatched payments held in suspense and resolved deliberately
  • Cancellations and reversals posted as reversals, never as deletions
  • Every receipt carries the M-PESA reference, so the audit is one lookup
Repayment register · principal, interest and penalty split per receipt
The repayment register listing four payments totalling KES 33,656.68, each row split into principal, interest and penalty with the receipt number and payment mode.

Accounting

A real general ledger, not a report that adds up loans.

Double-entry from the chart of accounts up. Every disbursement, repayment, fee, penalty, expense and payroll run writes its own journal at the moment it happens, so the trial balance is a consequence of the operations rather than a monthly reconstruction of them.

  • Chart of accounts, journals, general ledger and sub-ledgers
  • Trial balance, profit & loss, balance sheet and cash flow
  • Bank statement import and reconciliation against the ledger
  • Export to Excel, PDF or CSV for your auditor, on any screen that shows figures
Trial balance · balanced, consolidated across branches
A trial balance listing cash, bank, loans receivable, PAYE, SHIF and NSSF payable, interest and penalty income and expenses, with debit and credit totals both equal to 924,089.27 and a Balanced marker.

People & branches

Who can see what, decided once and enforced everywhere.

Roles are per user and portfolios are scoped by branch and by officer. A relationship officer sees their own clients; a team leader sees their branch; head office sees the consolidated position on the same screen, with the same definitions. Targets and performance are measured against the book itself, not against a spreadsheet someone maintains.

  • Roles and granular permissions, granted rather than assumed
  • Branch and officer portfolio scoping applied at the query, not the menu
  • Officer targets, collections performance and portfolio-at-risk
  • HR and payroll with PAYE, SHIF and NSSF, posted straight to the ledger
Users & staff · role and branch on every account
The users and staff screen listing eight accounts with their role — Root, Relationship Officer, Team Leader — the branch each belongs to, a staff number and an active status.

Integrations

Four connections, described precisely.

Everyone in this market claims all four. Here is exactly what each one does here, so you can ask the same question of whoever else you are talking to.

M-PESA · Daraja C2B

Collections on your own paybill or till

The callback is registered against your shortcode, so Safaricom delivers each payment to us as it happens. A payment carrying a recognisable account number is matched to the loan, applied to the schedule and journalled automatically. Anything ambiguous is held in suspense for a person to resolve — never guessed, never silently dropped.

Your shortcode, your credentials, stored encrypted.

M-PESA · Daraja B2C

Disbursement out to the borrower

Approved loans are paid out from the system to the borrower's M-PESA number, with the result written back against the disbursement. The initiator password is held only as Safaricom's RSA-encrypted SecurityCredential; the Integrations screen refuses a plaintext one pasted into that field.

Requires a B2C shortcode and Safaricom source-IP whitelisting.

DTB · bank statements

Reconciliation against the ledger

Import the bank statement and reconcile it line by line against the general ledger, not against a list of loans. Matched lines clear; unmatched lines stay visible until someone decides what they were. The bank balance in the accounts is the bank balance on the statement, or you can see exactly which line disagrees.

Other banks by statement import; direct feeds on request.

SMS · TextSMS or Advanta

Reminders, receipts and arrears notices

Templated messages on repayment received, instalment due and instalment overdue, sent from your own sender ID. Billed by your provider on your own account, at their rate — we do not resell SMS or add a margin, and the message count is on screen so you can check the bill against what was actually sent.

Your provider account, your sender ID.

Direct debit (DDA) collections are available on Enterprise, subject to your bank’s mandate process. If you need a connection that is not listed, ask — it is a scoping conversation, not a yes on a webpage.

Security & compliance

Your book is in its own database, behind its own credentials.

Not a shared table with a column marking whose row it is. A separate database per customer, and a separate database user that cannot reach past it.

One database per customer, one user per database

The usual way to build software like this is one database with a customer column on every table, and a bug in one query away from showing your book to somebody else. We do not do that. Each customer gets their own database and their own MySQL user, granted on that database only, and the application connects as that user.

So the boundary holds even when the application layer is wrong. That connection cannot list another customer’s database, let alone read one — and we tested it rather than assuming it:

# connected as another customer’s database user

mysql> SHOW DATABASES;

  their own database only — ours is not listed

mysql> USE tenant_umoja_sacco;

ERROR 1044 (42000): Access denied

Measured against MySQL, not asserted. It is recorded in our engineering decision log along with everything that has not been proved.

Encrypted integration credentials

Your Daraja consumer key, secret and passkey are encrypted at rest. The B2C initiator password is never stored in plaintext at all — only as Safaricom's RSA-encrypted SecurityCredential, and the Integrations screen refuses a plaintext one pasted into that field.

Two-factor authentication

Available on every account and enforceable across your whole organisation, with recovery codes. Sign-in is rate limited, and passwords are held to a real policy rather than a length check.

Append-only audit trail

Every create, edit and delete, with who did it, what changed and when. Entries are written, never rewritten — a correction is a new entry, so the trail of a disputed figure survives the dispute.

Per-customer backup and export

Because the database is yours alone, so is its backup — and restoring it cannot touch anybody else's data. You can export your whole book at any time, in a format you can read.

Data Protection Act 2019

Built to the Act: purpose, retention and deletion written down rather than implied, and a data processing addendum you can hand to your lawyer without asking us for one.

Safaricom supplier standard

We are working the Supplier Information Security Standard v4.0 workbook row by row — access control, API security, transport — and answering only the rows that are actually addressed to a partner like this one. The parts still open are recorded as open rather than answered optimistically.

Audit log · every create, edit and delete
The audit log, filterable by event, module and user, listing entries such as a client update by Admin, a disbursement of KES 128,000.00, repayments of KES 11,400.01, an expense payment, a payroll run and accrued penalties, each with a timestamp and the user responsible.

What we do not claim

You are being sold to by several companies this month. Here is what we are not going to tell you, so you know what to ask them:

  • An uptime percentage. We do not publish one, because we have not been running long enough for the figure to mean anything.
  • ISO 27001, SOC 2 or any other certification. We hold none of them, and we will not imply otherwise.
  • A third-party penetration test. Not yet done. When it is, the report date will be on this page.
  • A customer count or a portfolio total. We would rather show you the product than a number about it.

Everything above this box is either running in the product today or written down in our engineering log. That is the whole standard we hold this page to.

Pricing

Priced in shillings, printed on the page.

Three tiers. What is in each one, and what is not, so you can work out which you need before you speak to anybody.

Starter

One office, one book, properly kept.

KES 18,500

per month

1 branch · up to 5 users · up to 500 active loans

  • Client onboarding, loan origination and approvals
  • Repayment schedules, penalties and statements
  • M-PESA C2B — paybill collections matched automatically
  • Full double-entry accounting: journals, trial balance, P&L
  • Your data exported on request, in a format you can read
  • Not included: M-PESA B2C disbursement
  • Not included: Bank statement reconciliation
  • Not included: Payroll
Request a demo

Most lenders start here

Growth

Several branches, officers with targets, money moving both ways.

KES 45,000

per month

Up to 5 branches · up to 25 users · up to 5,000 active loans

  • Everything in Starter
  • M-PESA B2C — disburse to the borrower from the system
  • Bank statement import and reconciliation (DTB)
  • SMS via TextSMS or Advanta, with per-message cost visible
  • Group lending, meetings and group guarantees
  • Branch scoping, officer portfolios and targets
  • HR and payroll with PAYE, SHIF and NSSF
  • Not included: Direct debit (DDA)
  • Not included: API access
Request a demo

Enterprise

A branch network, your own domain, and someone to call.

From KES 120,000

per month

Unlimited branches and users · negotiated loan volume

  • Everything in Growth
  • Direct debit (DDA) collections
  • Your own branded public site and online application form, on your domain
  • API access for your own integrations
  • A named contact, and a migration plan with dates on it
Talk to us

Billed monthly in KES, cancel anytime. Migration from your existing system is scoped and quoted separately — we will not pretend it is free. SMS is billed by your own provider at their rate, and M-PESA transaction charges are Safaricom’s — neither passes through us.

Where this comes from

Not a demo build.

“Before this, matching paybill payments to loans was one person, two screens and a spreadsheet, and at the end of every month the loan system and the books disagreed. Now the payment posts itself against the schedule and writes the journal in the same moment. The trial balance and the loan ledger are the same number, and nobody spends the last two days of the month proving it.”

Tivim Credit

The lender this system was built for, and still runs on today

In the interest of not overstating it: Our own first customer, and we say so rather than presenting it as an independent reference. We would rather show you the running system on your own numbers than quote somebody you cannot ring.

Every module in the screenshots is shipped
Origination, repayments and M-PESA, the general ledger, branches, officers, HR and payroll. Nothing on this page is a roadmap item photographed early.
Your instance is created, not configured
Provisioning a new lender runs 14 automated steps — database, database user, schema, chart of accounts, roles, first administrator — and completes in about 24 seconds.

Questions

The eight things everyone asks.

Answered here rather than on a call, because you should be able to rule us out without spending an hour on it.

Something not here? Email us or send a WhatsApp message.

Who owns the data?

You do. It is your loan book, your clients and your ledger. You can export the whole of it at any time, including while an invoice is unpaid — we do not hold a regulated business's records hostage over a bill. If you leave, you get a full export and your database is destroyed on a schedule we will put in writing.

Can you move us off our current system?

Usually yes. We migrate clients, active loans with their outstanding balances and schedules, repayment history and opening balances for the chart of accounts. We scope it first against a copy of your data and quote it separately, because a migration priced blind is a migration that goes wrong.

Does it really reconcile M-PESA on its own?

Yes, for paybill collections. We register the Daraja C2B callback for your shortcode, and a payment that carries a recognisable account number is matched to the loan and posted to the ledger without anyone typing it. Payments that cannot be matched go to a suspense list for a human to decide, rather than being guessed at. Cancellations and reversals are handled as reversals, not as deletions.

What happens when the connection is bad?

The system is a web application and needs a connection to record work. What it does not do is lose an M-PESA payment while you are offline: Safaricom delivers the callback to our servers, not to your browser, so collections keep posting whether or not your branch is online. Statements and reports are downloadable as PDF and CSV to work from when you are not.

What do SMS messages cost?

They are billed by your SMS provider — TextSMS or Advanta — on your own account, at their rate. We do not resell SMS or add a margin to it. The system shows the message count so you can check the bill against what was actually sent.

Who inside my company can see what?

Roles and permissions are per user, and portfolios are scoped by branch and by officer. A relationship officer sees their own clients; a team leader sees their branch; only the roles you grant can approve, disburse, write off or touch the chart of accounts. Approvals are maker-checker, so the person who creates a disbursement is not the person who releases it.

Is our data separate from other lenders on the platform?

Separate database, not a shared table with a column marking whose row it is. Each customer also gets its own MySQL user, granted on that one database, and the application connects as that user — so a customer's connection cannot list another customer's database, let alone read it. We tested that rather than assuming it.

What support do we get?

Email and WhatsApp during Kenyan business hours, Monday to Friday, 8:00 AM to 6:00 PM. Enterprise customers get a named contact. We are a small team and we would rather tell you that than quote a response time we cannot hold to.

Already a customer?

Your team signs in on your own address — yourcompany.microfin.co.ke — not here. Your database, your users, your subdomain.

Lost your address? Message us

Bring one month of your paybill statement.

Thirty minutes, on your own numbers rather than a demo book. We will match a month of real payments to real loans in front of you, and show you the journals it wrote while doing it. If it does not fit your business, we will say so.

  • No card and no obligation
  • A written migration scope before any commitment
  • We reply the same working day

Request a demo

Three fields. That is the whole form.

We use this to contact you about a demo and nothing else. Privacy policy.

Want to tell us more first? Use the longer form.