Security & governance
Engineered to international internet-banking security standards from day one.
Not a compliance checklist bolted on at the end — the controls below are how the platform works, and each one is held in place by automated tests.
Identity
Authentication without passwords
Passkeys, not passwords
Step-up for money movement
Signatures bound to documents
Sessions
Session security, assumed hostile
Hashed, rotated tokens
Automatic theft response
Kill switch
Governance
Four eyes, enforced in software
Maker ≠ checker ≠ approver
Thresholds you set
Permissions, not job titles
Fails safe
Evidence
Append-only, regulator-ready
Every auth event on record
Books that cannot be rewritten
Decisions with their reasoning
Isolation
One funder, one environment
Each funder's deployment is dedicated: separate services, separate databases, separate models, no shared network. Application-level permissioning is defence in depth inside your environment — not the boundary between you and anyone else.
Proven, not promised
Every control on this page is exercised by automated end-to-end tests against the real system — real database, real messaging, real bank-format files, no mocks. The suites assert the refusals as well as the approvals: a self-approved payment, a replayed token, an unbalanced posting each fail the build before they could ever reach a customer. Production hardening — TLS everywhere, secrets management, breached-password screening, anomaly detection — is a stated roadmap, not fine print.
Put your security team in the room.
We'll walk the controls live and leave you the evidence trail.
