SECURITY

YOUR MONEY. PROTECTED LIKE FAMILY.

ScalMoney is built on the same security standards as global banks — and audited independently. Here is how we keep every transfer safe from the moment you speak it to the moment it lands.

ENCRYPTED END-TO-END

Every transfer, voice note, and message is encrypted in transit (TLS 1.3) and at rest (AES-256).

REGULATED PARTNERS

Funds are processed by licensed payment institutions under FCA, FinCEN, and equivalent regulators per corridor.

BIOMETRIC SIGN-IN

Face ID, fingerprint, or one-time code. We never store your biometric data — it stays on your device.

REAL-TIME FRAUD WATCH

Every transfer is screened against sanctions lists and unusual-pattern detection before it leaves your account.

KYC / AML COMPLIANT

Tiered identity verification meets global anti-money-laundering standards. Verified users unlock higher limits.

ISOLATED CUSTODY

Customer funds are held in segregated safeguarding accounts — never mixed with company operating funds.

FOR BANKING PARTNERS

THE FULL TECHNICAL & COMPLIANCE PICTURE

Everything your risk, compliance, and InfoSec teams need to onboard ScalMoney as a partner — at a glance.

CERTIFICATIONS & FRAMEWORKS

SOC 2 TYPE II

Annual independent audit of security, availability, and confidentiality controls.

PCI-DSS LEVEL 1

Card data handled exclusively by PCI-DSS L1 certified processors — never touches our servers.

ISO 27001

Information Security Management System certified by accredited third party.

GDPR / CCPA

Data subject rights, regional data residency, and 72-hour breach notification baked in.

PSD2 / SCA

Strong Customer Authentication on every payment initiation in EU/UK corridors.

FATF TRAVEL RULE

Originator and beneficiary data exchanged with counter-parties on qualifying transfers.

SECURITY STACK

INFRASTRUCTURE

Tier-IV cloud, multi-region active-active, WAF + DDoS protection, private VPC peering with banking partners. 99.99% uptime SLA.

DATA PROTECTION

AES-256 at rest with envelope encryption via HSM-backed KMS. Field-level encryption on PII. Tokenized card and account numbers. Daily encrypted backups with point-in-time recovery.

ACCESS CONTROL

Zero-trust internal access, hardware security keys (FIDO2) mandatory for all staff, role-based access with quarterly reviews, full audit log of every privileged action.

MONITORING & SIEM

24/7 SOC, real-time anomaly detection, immutable logging, automated alerting on policy violations. Mean time to detect under 5 minutes.

FRAUD & AML

Behavioural biometrics, device fingerprinting, velocity rules, sanctions/PEP screening (OFAC, UN, EU, HMT) on every transaction, SAR filing workflow.

PEOPLE & PROCESS

Background-checked staff, mandatory annual security training, secure SDLC with mandatory code review, quarterly penetration tests by CREST-accredited firms.

RESILIENCE

Documented BCP/DR with RPO ≤ 5 min and RTO ≤ 1 hour. Tested quarterly with banking partners. Wind-down plan filed with regulators.

DUE DILIGENCE PACK

Available under NDA: SOC 2 report, pen test summary, BCP/DR plan, AML policy, information security policy, and completed CAIQ / SIG questionnaire.

REQUEST OUR DUE-DILIGENCE PACK

Banks, EMIs, and licensed payment partners can request our full security questionnaire responses, SOC 2 report, and penetration test summary under NDA.

REPORT A VULNERABILITY

We welcome responsible disclosure. Email security@scalmoney.com with details and we will respond within 48 hours.