Trust

Security, data protection & AML/KYC

TLS, tokenisation posture, compulsory 2FA, Shufti Pro hosted KYC, and an AML/CFT programme written in SBP and FATF language.

Data encryption

TLS 1.2+ in transit. AES-256 at rest design. Secure key management practices.

Access controls

Role-based access control (RBAC) and compulsory multi-factor authentication for staff and merchants — SMS first, then a physical security key, then an authenticator app (scannable QR + setup key).

Security monitoring

Continuous monitoring for suspicious activity with defined incident response paths.

Compliance framework

CDD/EDD design, Shufti Pro hosted KYC (document, face, consent, AML screening; address for merchants), sanctions-screening architecture, and STR pathways to the Financial Monitoring Unit — implemented with licensing, not as a sticker.