No sections match this search.
Framework#
A dedicated compliance function operates independently of commercial teams and reports to the board. Policies are reviewed annually, and each control has a named owner and a testing schedule.
Certifications#
| Standard | Scope | Cycle |
|---|---|---|
| PCI DSS Level 1 | Card data environment | Annual |
| ISO 27001 | Information security management | Annual surveillance |
| SOC 2 Type II | Security and availability | Annual |
| Penetration testing | Platform and APIs | Twice yearly |
Attestation reports are available to business customers under NDA through your account contact.
AML and KYC#
We verify identity before an account is opened, understand the expected purpose and volume of activity, and refresh due diligence on a risk-based schedule. Enhanced diligence applies to higher-risk relationships.
We may request documents at any point in the relationship. Functionality can be limited until a request is satisfied.
Sanctions screening#
Customers, counterparties and payments are screened against applicable sanctions lists in real time. Matches are held for review, and confirmed matches are reported and blocked.
Transaction monitoring#
Automated rules and behavioural models review activity continuously. Alerts are investigated by trained analysts, and suspicious activity is reported to the relevant financial intelligence unit.
Third-party risk#
Every partner and processor is assessed before onboarding and reviewed annually, covering regulatory standing, security posture, resilience and data protection.
Training and culture#
All staff complete financial crime, security and data protection training at onboarding and annually. Escalation routes are confidential and protected.
Regulatory requests#
We respond to lawful requests from regulators and law enforcement, disclosing only what is required and notifying affected customers where legally permitted.
