Security

Security Trust Center

Sending money home means trusting us with both your money and your identity. Here is exactly how we protect both.

How we protect you

Six things we hold ourselves to

  • Encryption everywhere

    Data is encrypted in transit with TLS 1.2+ and at rest with AES-256. Card and bank details never touch our servers unencrypted — they go straight to our PCI-DSS Level 1 payment partners.

  • Regulated custody

    Customer USD balances sit in pooled custodial accounts at our partner bank, segregated from company funds and eligible for FDIC insurance up to $250,000 per depositor. See the licences page.

  • Identity verification

    Every account is verified against sanctions and PEP watchlists before it can send money, and again at higher limits, in line with US Bank Secrecy Act requirements.

  • Fraud monitoring

    Transfers are screened in real time for account takeover, mismatched recipient details and unusual sending patterns before funds ever leave your balance.

  • Independent audits

    Our infrastructure and controls are reviewed annually by an independent security firm. A summary report is available to enterprise and banking partners on request.

  • Least-privilege access

    Employee access to customer data is role-based, logged, and reviewed quarterly. Support staff never see full card or bank account numbers.

Responsible disclosure

Found a vulnerability?

We run a private bug bounty with our security partners, and we take reports from anyone. Email [email protected] with reproduction steps — we acknowledge within one business day and do not pursue legal action against good-faith researchers who report privately and give us reasonable time to fix the issue before disclosure. Full terms are in the Vulnerability Disclosure Policy.

For account-specific concerns (a compromised login, a transfer you did not make), contact support directly instead — it moves faster than a security report.