RRemitSource

Security

Platform Security

The security architecture and capabilities of the remittance platform — and what is the operator's responsibility in a self-hosted deployment.

Written by RemitSource Editorial TeamLast updated October 2026

Quick Answer

The remittance platform provides authentication, role-based authorization, MFA, encryption in transit and at rest, secrets management, structured logging, immutable audit trails, and a documented secure development lifecycle. In a self-hosted deployment, security is shared: the platform supplies the features, and the operator is responsible for secure configuration, hosting hardening, patching and monitoring. No specific certification is claimed unless independently documented.

Key Takeaways

  • Security is a shared responsibility in self-hosted deployments.
  • Audit trails and structured logging support regulatory reporting.
  • No certification (SOC 2, ISO 27001, PCI DSS) is claimed without evidence.
  • Operators must harden and monitor their own hosting environment.
Important: The capabilities below are architectural features of the platform, not attestations of compliance. We do not state that the platform has passed specific certifications, audits or penetration tests unless those have actually occurred and been documented.

Security capability areas

Authentication

Customer and admin authentication with session management, token rotation and optional MFA.

Authorization (RBAC)

Role-based access control for administration portal actions and data visibility.

MFA support

Multi-factor authentication for admins and optional for customers.

Encryption in transit

TLS for all external traffic and service-to-service communication where applicable.

Encryption at rest

Database and storage encryption configurable on the hosting infrastructure.

Secrets management

Secrets held in a secrets manager, not in source or configuration files.

API authentication

OAuth2 and API-key authentication with scoped permissions and rotation.

Logging

Structured application and access logs with configurable retention.

Audit trails

Immutable audit log of material actions for regulatory reporting and disputes.

Secure SDLC

Code review, dependency scanning and documented release process.

Dependency management

Inventory of third-party dependencies and their licenses.

Vulnerability management

Scanning and a process for addressing reported vulnerabilities.

Backups

Database backups with documented retention and restore testing.

Disaster recovery

Recovery point and time objectives documented for the deployment topology.

High availability

Multi-instance deployment patterns for stateless services.

Monitoring

Metrics, alerting and health checks for core services.

Shared responsibility

AreaPlatform providesOperator responsible
Authentication featuresYesConfigure & enforce policies
Hosting hardeningGuidanceYes
Secrets storageIntegration pointsProvision & rotate
Patching OS/runtime—Yes
Monitoring & alertingMetrics endpointsOperate
Penetration testing—Commission & remediate
Compliance certification—Pursue as needed

Frequently asked questions

Review security for your deployment

Request a demo to discuss the security architecture, configuration and your hosting requirements.

Contact Us on Telegram