Trust

Security, data protection & AML/KYC

TLS, tokenisation posture, compulsory 2FA, Shufti Pro hosted KYC, and an AML programme aligned to FATF language and partner-institution expectations.

Data encryption

TLS 1.2+ in transit. AES-256 at rest design. Secure key management practices.

Access controls

Role-based access control (RBAC) and compulsory multi-factor authentication for staff and merchants — SMS first, then a physical security key, then an authenticator app (scannable QR + setup key).

Security monitoring

Continuous monitoring for suspicious activity with defined incident response paths.

Compliance framework

CDD/EDD design, Shufti Pro hosted document-and-face KYC, and sanctions-screening architecture that scales with the partner’s regulated perimeter.