Trust, evidenced
BINK is licensed in every market it serves, audited against the standards regulated banks are held to, and monitored continuously. Every claim on this page is read from a policy you can open in full.
Compliance policy v2.0 · effective 1 September 2026
Attested state, not live platform health. Scope and cycle are read from the Compliance policy — this panel cannot show a standard the document does not.
Why enterprises trust BINK
Five reasons, each with a document behind it
The claim and the document are the same object
100%
Of regulated facts on this page read from a policy you can open
Every certification, cycle and entity on this page is read directly out of the approved policy at build time. There is no second copy to fall out of date, and no marketing edit that can quietly widen a scope. If the policy changes, this page changes with it; if it does not, this page cannot.
Licensed in every market we serve
BINK operates through a licensed entity in each of its markets. The entity named in your account agreement is the one that holds your money and the one whose permissions apply — not a parent company in another jurisdiction.
Oversight that does not report to sales
A dedicated compliance function operates independently of commercial teams and reports to the board. Policies are reviewed annually, and each control has a named owner and a testing schedule.
Audited by people who do not work here
Card environment, information security management, and security and availability are each assessed by an independent auditor on a published cycle. The platform and its APIs are tested twice a year on top of that.
Partners are assessed, not assumed
Every partner and processor is assessed before onboarding and reviewed annually, covering regulatory standing, security posture, resilience and data protection.
The protection journey
What happens around a single payment
Controls are easier to trust when you can see where each one sits. This is the same payment, from the moment an account is opened to the moment an incident is closed.
Before the account opens
Identity verified
We verify identity before an account is opened, understand the expected purpose and volume of activity, and refresh due diligence on a risk-based schedule. Enhanced diligence applies to higher-risk relationships.
Before you sign in
Phishing-resistant authentication
Passkeys and hardware security keys are supported on every account, with one-time codes for step-up verification and new devices confirmed before first use.
As the payment is made
Screened in real time
Customers, counterparties and payments are screened against applicable sanctions lists in real time. Matches are held for review, and confirmed matches are reported and blocked.
In flight
Encrypted end to end
Traffic is encrypted with TLS 1.3. Stored data is encrypted with AES-256 and keys are managed in hardware security modules with split control. Card data is tokenised and handled within PCI DSS Level 1 scope.
Continuously
Monitored for the unusual
Sessions, devices and payments are scored continuously. Unusual patterns trigger step-up verification, a temporary hold, or review by our fraud team, and alerts are investigated by trained analysts.
If something is wrong
Contained, then disclosed
Detection and triage on call at all times, affected sessions or accounts isolated, and notification to affected customers and regulators within required timeframes.
Afterwards
Reported and reviewed
Suspicious activity is reported to the relevant financial intelligence unit, and a post-incident review is published in summary where material.
Jurisdictions
Licensed where we operate
BINK is a group of companies. The entity named in your account agreement is the one you contract with, and its permissions are the ones that apply to your account.
EgyptUnited Arab EmiratesUnited KingdomBINK PAY
BINKPAY FINANCING BROKER L.L.C
BINK PAY LTD
Entities, permissions, safeguarding and partner institutions are stated in Licenses & Regulation — version 3.0. A market cannot appear here unless the group holds an entity in it.
Compliance framework
Four assessments, four independent auditors
PCI DSS Level 1
Card data environment
Assessed by an independent auditor. Attestation reports are available to business customers under NDA through your account contact.
AnnualISO 27001
Information security management
Assessed by an independent auditor. Attestation reports are available to business customers under NDA through your account contact.
Annual surveillanceSOC 2 Type II
Security and availability
Assessed by an independent auditor. Attestation reports are available to business customers under NDA through your account contact.
AnnualPenetration testing
Platform and APIs
Assessed by an independent auditor. Attestation reports are available to business customers under NDA through your account contact.
Twice yearlyRead from the Compliance policy — version 2.0. The cycles shown here and the cycles the document states cannot diverge.
Operational security
How production is actually run
Certifications describe what is assessed. These are the day-to-day controls the assessment is against, quoted from the Security policy.
Peer review and automated checks
Least privilege, time-bound, logged
Encrypted, tested quarterly
RPO 15 minutes · RTO 4 hours
TLS 1.3
Traffic encrypted in transit
AES-256
Data at rest, keys split across hardware modules
Twice yearly
Independent testing of the platform and APIs
1 business day
Vulnerability reports acknowledged
Questions
What diligence teams ask first
Can I see your attestation reports?
Yes. Attestation reports are available to business customers under NDA through your account contact, or directly from the compliance team.
Which entity am I actually contracting with?
The entity named in your account agreement. BINK is a group of companies with a licensed entity in each market, and that entity’s permissions are the ones that apply to your account.
What happens to my money if BINK fails?
Customer funds are safeguarded with partner institutions and held separately from BINK’s own funds. They are electronic money rather than bank deposits, so they are not covered by deposit guarantee schemes — safeguarding is the protection that applies instead.
How often is the platform tested?
The platform and its APIs are penetration-tested twice yearly. PCI DSS Level 1 and SOC 2 Type II are assessed annually, and ISO 27001 carries annual surveillance.
Will you ask me for my password or one-time code?
Never. BINK will never ask for your password, one-time code or passkey over the phone, by email or in chat. If someone does, it is not us.
What do you do when a regulator asks for data?
We respond to lawful requests from regulators and law enforcement, disclosing only what is required and notifying affected customers where legally permitted.
How do I report a vulnerability?
Through the security channel in the application, or to security@binkpay.net. We acknowledge within one business day and will not pursue action against good-faith research, provided testing does not access other customers’ data, degrade service, or use social engineering.
Boundaries
What BINK is not
Knowing what a financial platform does not do is part of deciding whether to trust it. Each line below is stated in the licensing or privacy policy.
We do not take deposits. Balances held with BINK are electronic money, not bank deposits.
Not covered by deposit guarantee schemes. Customer funds are safeguarded with partner institutions instead.
We do not provide investment advice. Nothing in the product is a recommendation to buy or sell.
We never sell customer data. Data is shared only where there is a lawful basis to do so.
Related
Everything this page is read from
Reviewing BINK for your business?
Attestation reports are available to business customers under NDA through your account contact, or directly from the compliance team.
