Security
Platform Security
The security architecture and capabilities of the remittance platform — and what is the operator's responsibility in a self-hosted deployment.
Quick Answer
The remittance platform provides authentication, role-based authorization, MFA, encryption in transit and at rest, secrets management, structured logging, immutable audit trails, and a documented secure development lifecycle. In a self-hosted deployment, security is shared: the platform supplies the features, and the operator is responsible for secure configuration, hosting hardening, patching and monitoring. No specific certification is claimed unless independently documented.
Key Takeaways
- Security is a shared responsibility in self-hosted deployments.
- Audit trails and structured logging support regulatory reporting.
- No certification (SOC 2, ISO 27001, PCI DSS) is claimed without evidence.
- Operators must harden and monitor their own hosting environment.
Security capability areas
Authentication
Customer and admin authentication with session management, token rotation and optional MFA.
Authorization (RBAC)
Role-based access control for administration portal actions and data visibility.
MFA support
Multi-factor authentication for admins and optional for customers.
Encryption in transit
TLS for all external traffic and service-to-service communication where applicable.
Encryption at rest
Database and storage encryption configurable on the hosting infrastructure.
Secrets management
Secrets held in a secrets manager, not in source or configuration files.
API authentication
OAuth2 and API-key authentication with scoped permissions and rotation.
Logging
Structured application and access logs with configurable retention.
Audit trails
Immutable audit log of material actions for regulatory reporting and disputes.
Secure SDLC
Code review, dependency scanning and documented release process.
Dependency management
Inventory of third-party dependencies and their licenses.
Vulnerability management
Scanning and a process for addressing reported vulnerabilities.
Backups
Database backups with documented retention and restore testing.
Disaster recovery
Recovery point and time objectives documented for the deployment topology.
High availability
Multi-instance deployment patterns for stateless services.
Monitoring
Metrics, alerting and health checks for core services.
Shared responsibility
| Area | Platform provides | Operator responsible |
|---|---|---|
| Authentication features | Yes | Configure & enforce policies |
| Hosting hardening | Guidance | Yes |
| Secrets storage | Integration points | Provision & rotate |
| Patching OS/runtime | — | Yes |
| Monitoring & alerting | Metrics endpoints | Operate |
| Penetration testing | — | Commission & remediate |
| Compliance certification | — | Pursue as needed |
Frequently asked questions
Review security for your deployment
Request a demo to discuss the security architecture, configuration and your hosting requirements.