SECURITY
YOUR MONEY. PROTECTED LIKE FAMILY.
ScalMoney is built on the same security standards as global banks — and audited independently. Here is how we keep every transfer safe from the moment you speak it to the moment it lands.
ENCRYPTED END-TO-END
Every transfer, voice note, and message is encrypted in transit (TLS 1.3) and at rest (AES-256).
REGULATED PARTNERS
Funds are processed by licensed payment institutions under FCA, FinCEN, and equivalent regulators per corridor.
BIOMETRIC SIGN-IN
Face ID, fingerprint, or one-time code. We never store your biometric data — it stays on your device.
REAL-TIME FRAUD WATCH
Every transfer is screened against sanctions lists and unusual-pattern detection before it leaves your account.
KYC / AML COMPLIANT
Tiered identity verification meets global anti-money-laundering standards. Verified users unlock higher limits.
ISOLATED CUSTODY
Customer funds are held in segregated safeguarding accounts — never mixed with company operating funds.
FOR BANKING PARTNERS
THE FULL TECHNICAL & COMPLIANCE PICTURE
Everything your risk, compliance, and InfoSec teams need to onboard ScalMoney as a partner — at a glance.
CERTIFICATIONS & FRAMEWORKS
SOC 2 TYPE II
Annual independent audit of security, availability, and confidentiality controls.
PCI-DSS LEVEL 1
Card data handled exclusively by PCI-DSS L1 certified processors — never touches our servers.
ISO 27001
Information Security Management System certified by accredited third party.
GDPR / CCPA
Data subject rights, regional data residency, and 72-hour breach notification baked in.
PSD2 / SCA
Strong Customer Authentication on every payment initiation in EU/UK corridors.
FATF TRAVEL RULE
Originator and beneficiary data exchanged with counter-parties on qualifying transfers.
SECURITY STACK
INFRASTRUCTURE
Tier-IV cloud, multi-region active-active, WAF + DDoS protection, private VPC peering with banking partners. 99.99% uptime SLA.
DATA PROTECTION
AES-256 at rest with envelope encryption via HSM-backed KMS. Field-level encryption on PII. Tokenized card and account numbers. Daily encrypted backups with point-in-time recovery.
ACCESS CONTROL
Zero-trust internal access, hardware security keys (FIDO2) mandatory for all staff, role-based access with quarterly reviews, full audit log of every privileged action.
MONITORING & SIEM
24/7 SOC, real-time anomaly detection, immutable logging, automated alerting on policy violations. Mean time to detect under 5 minutes.
FRAUD & AML
Behavioural biometrics, device fingerprinting, velocity rules, sanctions/PEP screening (OFAC, UN, EU, HMT) on every transaction, SAR filing workflow.
PEOPLE & PROCESS
Background-checked staff, mandatory annual security training, secure SDLC with mandatory code review, quarterly penetration tests by CREST-accredited firms.
RESILIENCE
Documented BCP/DR with RPO ≤ 5 min and RTO ≤ 1 hour. Tested quarterly with banking partners. Wind-down plan filed with regulators.
DUE DILIGENCE PACK
Available under NDA: SOC 2 report, pen test summary, BCP/DR plan, AML policy, information security policy, and completed CAIQ / SIG questionnaire.
REQUEST OUR DUE-DILIGENCE PACK
Banks, EMIs, and licensed payment partners can request our full security questionnaire responses, SOC 2 report, and penetration test summary under NDA.
REPORT A VULNERABILITY
We welcome responsible disclosure. Email security@scalmoney.com with details and we will respond within 48 hours.