Certifications
Audited end-to-end
- PCI DSS Level 1 (annual on-site)
- ISO 27001 information security
- SOC 2 Type II (continuous)
- NACHA-aligned ACH controls
- Egyptian Central Bank reporting
Compliance isn't a feature here — it's the foundation. Every wallet, card and transfer runs on rails certified by the same standards regulated banks use, and verified by the same third-party auditors.
Certifications
KYB & KYC
AML monitoring
Audit-grade controls don't come from a slide deck — they come from the rituals a team commits to running every week, year after year.
Column-level KMS for sensitive fields. TLS 1.3 in flight. Hardware-isolated key custody.
Role-based access. Two-factor required for every admin action. Quarterly access reviews.
Every state change is recorded with actor, timestamp and reason. Retained for seven years.
Read-replica reconciliation, automated failover, chaos-tested incident drills monthly.
Independent red-team engagements. Bug-bounty program with public disclosure policy.
We collect only what compliance requires. Customer data is never sold or shared for marketing.
Compliance isn't bolted on after launch — it's the foundation we built BINKPAY on. Every product on the platform inherits the same controls.