Security
Built to survive an audit — and an attacker.
Controls designed with regulated banking partners, tested independently and monitored continuously.
What protects every transaction.
Encryption everywhere
TLS 1.3 in transit, AES-256 at rest, and hardware-backed key management with strict rotation policies.
Identity verification
Document, biometric and database checks orchestrated across providers, tuned per market and risk tier.
Transaction monitoring
Real-time rules and behavioural models flag structuring, velocity anomalies and sanctioned counterparties.
Access control
Role-based permissions, SSO, SCIM provisioning and enforceable WebAuthn keys for payout roles.
Resilience
Multi-region active-active infrastructure, tested failover and a published 99.99% uptime objective.
Segregated funds
Customer funds are held in safeguarding accounts at licensed partner institutions, never commingled.
Independent validation.
PCI DSS
Cardholder data flows through tokenised, PCI DSS-aligned infrastructure; we never store raw PANs in application databases.
SOC 2 Type II
Annual audit of security, availability and confidentiality controls. Reports available under NDA.
ISO 27001 aligned
Information security management modelled on ISO 27001 domains with documented risk treatment.
Independent testing
Third-party penetration tests twice yearly plus a continuous responsible disclosure programme.
Report a vulnerability.
We welcome reports from security researchers. Email security@totalremit.com with reproduction steps and impact. We acknowledge within one business day and will not pursue legal action against good-faith research that avoids privacy violations, data destruction and service degradation.
Finance without borders, built for what you do next.
Open a TotalRemit account in minutes, or talk with our team about embedded payment programmes.