Trust, evidenced

BINK is licensed in every market it serves, audited against the standards regulated banks are held to, and monitored continuously. Every claim on this page is read from a policy you can open in full.

Compliance policy v2.0 · effective 1 September 2026

Attested standardsCycle
PCI DSS Level 1Annual
ISO 27001Annual surveillance
SOC 2 Type IIAnnual
Penetration testingTwice yearly

Attested state, not live platform health. Scope and cycle are read from the Compliance policy — this panel cannot show a standard the document does not.

Why enterprises trust BINK

Five reasons, each with a document behind it

The claim and the document are the same object

100%

Of regulated facts on this page read from a policy you can open

Every certification, cycle and entity on this page is read directly out of the approved policy at build time. There is no second copy to fall out of date, and no marketing edit that can quietly widen a scope. If the policy changes, this page changes with it; if it does not, this page cannot.

Licensed in every market we serve

BINK operates through a licensed entity in each of its markets. The entity named in your account agreement is the one that holds your money and the one whose permissions apply — not a parent company in another jurisdiction.

Oversight that does not report to sales

A dedicated compliance function operates independently of commercial teams and reports to the board. Policies are reviewed annually, and each control has a named owner and a testing schedule.

Audited by people who do not work here

Card environment, information security management, and security and availability are each assessed by an independent auditor on a published cycle. The platform and its APIs are tested twice a year on top of that.

Partners are assessed, not assumed

Every partner and processor is assessed before onboarding and reviewed annually, covering regulatory standing, security posture, resilience and data protection.

The protection journey

What happens around a single payment

Controls are easier to trust when you can see where each one sits. This is the same payment, from the moment an account is opened to the moment an incident is closed.

Before the account opens

Identity verified

We verify identity before an account is opened, understand the expected purpose and volume of activity, and refresh due diligence on a risk-based schedule. Enhanced diligence applies to higher-risk relationships.

Before you sign in

Phishing-resistant authentication

Passkeys and hardware security keys are supported on every account, with one-time codes for step-up verification and new devices confirmed before first use.

As the payment is made

Screened in real time

Customers, counterparties and payments are screened against applicable sanctions lists in real time. Matches are held for review, and confirmed matches are reported and blocked.

In flight

Encrypted end to end

Traffic is encrypted with TLS 1.3. Stored data is encrypted with AES-256 and keys are managed in hardware security modules with split control. Card data is tokenised and handled within PCI DSS Level 1 scope.

Continuously

Monitored for the unusual

Sessions, devices and payments are scored continuously. Unusual patterns trigger step-up verification, a temporary hold, or review by our fraud team, and alerts are investigated by trained analysts.

If something is wrong

Contained, then disclosed

Detection and triage on call at all times, affected sessions or accounts isolated, and notification to affected customers and regulators within required timeframes.

Afterwards

Reported and reviewed

Suspicious activity is reported to the relevant financial intelligence unit, and a post-incident review is published in summary where material.

Jurisdictions

Licensed where we operate

BINK is a group of companies. The entity named in your account agreement is the one you contract with, and its permissions are the ones that apply to your account.

EgyptUnited Arab EmiratesUnited Kingdom
EgyptRegistered entity

BINK PAY

United Arab EmiratesRegistered entity

BINKPAY FINANCING BROKER L.L.C

United KingdomRegistered entity

BINK PAY LTD

Entities, permissions, safeguarding and partner institutions are stated in Licenses & Regulation — version 3.0. A market cannot appear here unless the group holds an entity in it.

Compliance framework

Four assessments, four independent auditors

PCI DSS Level 1

Card data environment

Assessed by an independent auditor. Attestation reports are available to business customers under NDA through your account contact.

Annual

ISO 27001

Information security management

Assessed by an independent auditor. Attestation reports are available to business customers under NDA through your account contact.

Annual surveillance

SOC 2 Type II

Security and availability

Assessed by an independent auditor. Attestation reports are available to business customers under NDA through your account contact.

Annual

Penetration testing

Platform and APIs

Assessed by an independent auditor. Attestation reports are available to business customers under NDA through your account contact.

Twice yearly

Read from the Compliance policy — version 2.0. The cycles shown here and the cycles the document states cannot diverge.

Operational security

How production is actually run

Certifications describe what is assessed. These are the day-to-day controls the assessment is against, quoted from the Security policy.

Isolated productionLeast-privilege access, mandatory review on every change, immutable deployments.
Time-bound accessAccess to production data requires approval and expires.
Trained annuallyAll staff complete financial crime, security and data protection training at onboarding and annually.
Protected escalationEscalation routes are confidential and protected.
Change managementStandard

Peer review and automated checks

AccessStandard

Least privilege, time-bound, logged

BackupsStandard

Encrypted, tested quarterly

RecoveryStandard

RPO 15 minutes · RTO 4 hours

TLS 1.3

Traffic encrypted in transit

AES-256

Data at rest, keys split across hardware modules

Twice yearly

Independent testing of the platform and APIs

1 business day

Vulnerability reports acknowledged

Questions

What diligence teams ask first

Can I see your attestation reports?

Yes. Attestation reports are available to business customers under NDA through your account contact, or directly from the compliance team.

Which entity am I actually contracting with?

The entity named in your account agreement. BINK is a group of companies with a licensed entity in each market, and that entity’s permissions are the ones that apply to your account.

What happens to my money if BINK fails?

Customer funds are safeguarded with partner institutions and held separately from BINK’s own funds. They are electronic money rather than bank deposits, so they are not covered by deposit guarantee schemes — safeguarding is the protection that applies instead.

How often is the platform tested?

The platform and its APIs are penetration-tested twice yearly. PCI DSS Level 1 and SOC 2 Type II are assessed annually, and ISO 27001 carries annual surveillance.

Will you ask me for my password or one-time code?

Never. BINK will never ask for your password, one-time code or passkey over the phone, by email or in chat. If someone does, it is not us.

What do you do when a regulator asks for data?

We respond to lawful requests from regulators and law enforcement, disclosing only what is required and notifying affected customers where legally permitted.

How do I report a vulnerability?

Through the security channel in the application, or to security@binkpay.net. We acknowledge within one business day and will not pursue action against good-faith research, provided testing does not access other customers’ data, degrade service, or use social engineering.

Boundaries

What BINK is not

Knowing what a financial platform does not do is part of deciding whether to trust it. Each line below is stated in the licensing or privacy policy.

We do not take deposits. Balances held with BINK are electronic money, not bank deposits.

Not covered by deposit guarantee schemes. Customer funds are safeguarded with partner institutions instead.

We do not provide investment advice. Nothing in the product is a recommendation to buy or sell.

We never sell customer data. Data is shared only where there is a lawful basis to do so.

Related

Everything this page is read from

Reviewing BINK for your business?

Attestation reports are available to business customers under NDA through your account contact, or directly from the compliance team.