Security and Compliance
Built for the compliance requirements of institutional treasury
Every payment is pre-screened, encrypted in transit and at rest, and generates an immutable compliance record. Access is role-controlled and every action is logged.
Request AccessCompliance record
What your auditors see on every wire
A structured, timestamped record is generated at settlement. No preparation required on your side.
Every field your auditors need, automatically
The compliance record captures initiation timestamp, settlement confirmation, applied FX rate, sanction check result, corridor path, and the identity of the approving treasury user. No supplementary documentation required at audit time.
Records are available via the API, downloadable as structured JSON or PDF, and pushed to your configured webhook endpoint immediately on settlement.
Security posture
Controls that meet institutional requirements
End-to-end encryption
All payment instructions and compliance data are encrypted in transit (TLS 1.3) and at rest (AES-256). API keys are never stored in plaintext. Webhook payloads are signed with HMAC-SHA256 so your receiving endpoint can verify authenticity.
Real-time sanction screening
Every payment is screened against OFAC SDN, EU Consolidated, and UN Security Council lists before routing begins. Screening results are recorded in the compliance trail. Flagged payments are held and the initiating user is notified immediately.
Immutable audit log
Every platform action, including payment initiation, approval, corridor selection, and compliance record access, is written to an append-only audit log. Logs cannot be modified or deleted by any user role, including administrators.
Access control
Role-based access designed for treasury teams
Configurable payment limits per user role and corridor
Dual-approval workflow for payments above defined thresholds
SSO via SAML 2.0 and OIDC for enterprise identity integration
API key scoping by corridor, amount range, and operation type
Security documentation available on request
Our team can provide documentation on our security controls architecture and a technical brief for your compliance review.