Security Trust Center
Sending money home means trusting us with both your money and your identity. Here is exactly how we protect both.
Six things we hold ourselves to
-
Encryption everywhere
Data is encrypted in transit with TLS 1.2+ and at rest with AES-256. Card and bank details never touch our servers unencrypted — they go straight to our PCI-DSS Level 1 payment partners.
-
Regulated custody
Customer USD balances sit in pooled custodial accounts at our partner bank, segregated from company funds and eligible for FDIC insurance up to $250,000 per depositor. See the licences page.
-
Identity verification
Every account is verified against sanctions and PEP watchlists before it can send money, and again at higher limits, in line with US Bank Secrecy Act requirements.
-
Fraud monitoring
Transfers are screened in real time for account takeover, mismatched recipient details and unusual sending patterns before funds ever leave your balance.
-
Independent audits
Our infrastructure and controls are reviewed annually by an independent security firm. A summary report is available to enterprise and banking partners on request.
-
Least-privilege access
Employee access to customer data is role-based, logged, and reviewed quarterly. Support staff never see full card or bank account numbers.
Found a vulnerability?
We run a private bug bounty with our security partners, and we take reports from anyone. Email [email protected] with reproduction steps — we acknowledge within one business day and do not pursue legal action against good-faith researchers who report privately and give us reasonable time to fix the issue before disclosure. Full terms are in the Vulnerability Disclosure Policy.
For account-specific concerns (a compromised login, a transfer you did not make), contact support directly instead — it moves faster than a security report.