Skip to content
TotalRemit

Security

Built to survive an audit — and an attacker.

Controls designed with regulated banking partners, tested independently and monitored continuously.

Controls

What protects every transaction.

Encryption everywhere

TLS 1.3 in transit, AES-256 at rest, and hardware-backed key management with strict rotation policies.

Identity verification

Document, biometric and database checks orchestrated across providers, tuned per market and risk tier.

Transaction monitoring

Real-time rules and behavioural models flag structuring, velocity anomalies and sanctioned counterparties.

Access control

Role-based permissions, SSO, SCIM provisioning and enforceable WebAuthn keys for payout roles.

Resilience

Multi-region active-active infrastructure, tested failover and a published 99.99% uptime objective.

Segregated funds

Customer funds are held in safeguarding accounts at licensed partner institutions, never commingled.

Assurance

Independent validation.

PCI DSS

Cardholder data flows through tokenised, PCI DSS-aligned infrastructure; we never store raw PANs in application databases.

SOC 2 Type II

Annual audit of security, availability and confidentiality controls. Reports available under NDA.

ISO 27001 aligned

Information security management modelled on ISO 27001 domains with documented risk treatment.

Independent testing

Third-party penetration tests twice yearly plus a continuous responsible disclosure programme.

Disclosure

Report a vulnerability.

We welcome reports from security researchers. Email security@totalremit.com with reproduction steps and impact. We acknowledge within one business day and will not pursue legal action against good-faith research that avoids privacy violations, data destruction and service degradation.

Finance without borders, built for what you do next.

Open a TotalRemit account in minutes, or talk with our team about embedded payment programmes.