Trust
Security, data protection & AML/KYC
TLS, tokenisation posture, compulsory 2FA, Shufti Pro hosted KYC, and an AML/CFT programme written in SBP and FATF language.
Data encryption
TLS 1.2+ in transit. AES-256 at rest design. Secure key management practices.
Access controls
Role-based access control (RBAC) and compulsory multi-factor authentication for staff and merchants — SMS first, then a physical security key, then an authenticator app (scannable QR + setup key).
Security monitoring
Continuous monitoring for suspicious activity with defined incident response paths.
Compliance framework
CDD/EDD design, Shufti Pro hosted KYC (document, face, consent, AML screening; address for merchants), sanctions-screening architecture, and STR pathways to the Financial Monitoring Unit — implemented with licensing, not as a sticker.
Security & data protection statement
Stratos Fintech (Private) Limited is committed to protecting the confidentiality, integrity and availability of data entrusted to us. Security is embedded by design, least privilege is enforced, defence in depth is applied, and regular assessments identify vulnerabilities.
AML/KYC compliance statement
We are committed to full compliance with applicable Anti-Money Laundering (AML) and Counter-Financing of Terrorism (CFT) laws in Pakistan, including the Anti-Money Laundering Act, 2010, State Bank of Pakistan AML/CFT Regulations, and FATF Recommendations as adopted in Pakistan.
Our AML/KYC programme (to be implemented upon licensing) will include:
- Customer Due Diligence (CDD) with authorised verification services.
- Enhanced Due Diligence (EDD) for higher-risk customers including PEPs.
- Transaction monitoring for suspicious patterns and sanctions matches.
- Suspicious Transaction Reporting (STR) to the Financial Monitoring Unit (FMU).
- Record keeping for a minimum of five years as required by applicable law.
- Regular AML/CFT staff training.
PCI-DSS tokenisation posture
Card data handling will be designed around tokenisation and minimised scope, targeting PCI-DSS aligned controls via licensed acquiring partners. No live card processing is offered today.
Hosted identity (Shufti Pro)
Merchant and customer identity journeys on the control panel run through Shufti Pro. The production stack is:
- Document verification — CNIC, passport or driving licence, including the reverse of the card.
- Facial biometrics — liveness against the document photo.
- Consent — recorded agreement to KYC/AML processing.
- AML screening — PEP, sanctions and watchlists on accepted identities.
- Address verification — merchants only (utility bill, bank statement or ID address).
- Document two — second identity document for merchant owners.
Phone MFA stays on the Stratos portal (Twilio), not inside Shufti. Know Your Business (KYB) for merchant companies is the next service to enable. Enhanced due diligence and STR/CTR reporting to the Financial Monitoring Unit sit in the AML programme and scale with SBP licensing — they are not implied by a single KYC pass.
Two-factor authentication
Portal sign-in for founders, team and merchants requires a second factor. Preferred order:
- SMS code — a 6-digit one-time password texted to the enrolled mobile.
- Physical security key — FIDO2 / WebAuthn hardware such as a YubiKey or Titan key.
- Authenticator app — TOTP with a scannable QR code and a visible setup key for Google Authenticator, Authy or 1Password.
Report a security concern
Email support@stratosfin.pk with subject "Security Report". We aim to acknowledge within 48 business hours.