🔐 Platform Security · Trust & Safety

How We Protect Your Money

Every account, every transaction, every session — protected by multiple layers of security designed to keep your funds and data safe.

🔒

🛡️ Security First

Send2Bank is built with security at every layer — from encryption and authentication to monitoring and incident response. Your funds and personal data are protected by multiple independent safeguards. If you ever suspect a security issue, contact [email protected] immediately.

01Our Security Philosophy

At Send2Bank, security is not an afterthought — it is foundational to everything we build. We operate on the principle of defense in depth, meaning we implement multiple layers of independent security controls so that if one layer fails, others remain to protect your account and funds. Our approach combines technical safeguards, operational procedures, and continuous monitoring to create a security posture that evolves with emerging threats.

We believe in transparency about our security practices. This page describes the measures we take to protect your data and funds. While no system can guarantee absolute security, we are committed to implementing industry best practices, regularly testing our defenses, and responding rapidly to any security incident. Our security team includes experienced professionals who stay current with the evolving threat landscape and continuously improve our defenses.

Security at Send2Bank is everyone's responsibility — from our engineering team writing secure code to our customer support team verifying identities before making account changes, to you practicing good account hygiene. We provide the tools and protections; you provide the vigilance.

02Encryption & Data Protection

All data transmitted between your device and Send2Bank servers is encrypted using Transport Layer Security version 1.3 with 256-bit encryption keys. This is the same encryption standard used by banks and financial institutions worldwide. Our TLS configuration is regularly tested against industry benchmarks including the Qualys SSL Labs assessment, and we disable older, less secure protocol versions and cipher suites.

🔒

Data in Transit

TLS 1.3 with 256-bit encryption protects all communications between your browser or app and our servers.

🗄️

Data at Rest

All stored data including databases, backups, and logs are encrypted using AES-256 encryption.

🔑

PIN Protection

Your PIN is hashed using bcrypt with a unique per-user salt. It is never stored in plain text or in any recoverable format.

🔐

API Token Security

API tokens are short-lived Bearer tokens, hashed before storage, and automatically invalidated on logout.

Encryption keys are managed through a secure key management system with strict access controls. Keys are rotated on a regular schedule and immediately upon any suspected compromise. All production database backups are encrypted using separate keys from those used for live data, ensuring that even backup media is protected.

03Authentication & Access Control

Send2Bank employs multiple layers of authentication and authorization to ensure that only you can access your account. Your primary authentication factor is your registered phone number combined with a 4-digit PIN. The PIN is transmitted only over encrypted connections and is verified against a bcrypt hash on our servers — we never have access to your actual PIN. After multiple failed PIN attempts, your account is temporarily locked to prevent brute-force attacks.

All login attempts and sensitive operations are rate-limited to prevent automated attacks. Session tokens are short-lived and automatically expire after periods of inactivity. When you log out — or when your session expires — all tokens associated with that session are immediately invalidated and cannot be reused. We also employ device fingerprinting and behavioral analysis to detect and block suspicious login attempts, such as those originating from unusual locations or devices.

Internal access to production systems and customer data is strictly controlled through role-based access control. All access requires multi-factor authentication. Every access to customer data is logged and auditable. Access privileges are reviewed quarterly, and access is immediately revoked when an employee changes roles or leaves the company. The principle of least privilege is strictly enforced — personnel only have access to the specific data and systems required for their role.

04Infrastructure Security

Our platform infrastructure is built and maintained with security as a core design requirement. We operate in secure data center facilities with physical access controls including 24/7 security personnel, biometric access systems, video surveillance, and environmental monitoring. Network security includes firewall protection at multiple layers, intrusion detection and prevention systems, and distributed denial-of-service mitigation.

  • Web Application Firewall protecting all public-facing endpoints against common attack vectors including SQL injection, cross-site scripting, and request forgery
  • Automated vulnerability scanning of all infrastructure components on a continuous basis, with critical vulnerabilities patched within 24 hours
  • Network segmentation isolating production systems from development and corporate environments
  • Regular third-party penetration testing performed at least annually by independent security firms
  • Automated configuration management ensuring all systems conform to our security baseline
  • Immutable infrastructure practices — servers are replaced rather than patched in place, ensuring clean, known-good states

05Application Security

Security is integrated into every stage of our software development lifecycle. Our developers follow secure coding practices and all code changes undergo peer review before being merged. Automated security testing is integrated into our continuous integration pipeline, including static application security testing to identify vulnerabilities in source code, dependency scanning to detect known vulnerabilities in third-party libraries, and dynamic application security testing against running applications.

Our web application implements multiple browser-side security controls. Content Security Policy headers restrict which resources can be loaded and executed, preventing cross-site scripting attacks. HTTP Strict Transport Security ensures browsers only connect over encrypted connections. Cross-Site Request Forgery tokens protect all state-changing requests against forgery attacks. Webhook endpoints implement idempotency keys ensuring duplicate payment attempts are automatically detected and rejected.

All application code dependencies are regularly scanned for known vulnerabilities using automated tooling. When vulnerabilities are identified, we assess the risk, apply patches, and deploy updated code through our standard deployment pipeline. Critical vulnerabilities are treated with the highest priority.

06Payment Security

Payment processing is the most security-sensitive function of our platform, and we have implemented specialized controls to protect every transaction. All payment requests are authenticated using your session token and verified against your account's authorization state. Double-entry ledger accounting ensures that every transaction is recorded with corresponding debit and credit entries — this means any discrepancy or unauthorized transaction is immediately detectable through our reconciliation processes.

For mobile money transactions, we integrate directly with MTN and Airtel payment APIs using secure, authenticated connections. Transaction references are cryptographically verified to prevent replay attacks. For Bitcoin and cryptocurrency transactions, we use BTCPay Server with additional verification layers to ensure payment confirmation before crediting accounts. All cryptocurrency private keys are stored in secure, isolated environments with multi-signature requirements for any withdrawal.

Payment links and invoices include unique, single-use tokens that prevent unauthorized reuse. QR codes generated by our platform are dynamically created and expire after use or after a configurable time period. All payment confirmations include tamper-evident references that allow both sender and receiver to independently verify transaction authenticity.

07Monitoring & Incident Response

Send2Bank maintains 24/7 security monitoring of all production systems. Our monitoring infrastructure aggregates logs from applications, databases, network devices, and security systems into a centralized security information and event management platform. Automated alerting notifies our on-call security team of potential security events based on predefined detection rules and behavioral anomaly detection.

We maintain a documented incident response plan that is tested at least annually through tabletop exercises and simulated incidents. The plan defines roles, responsibilities, communication protocols, and escalation procedures. In the event of a confirmed security incident affecting customer data or funds, we commit to notifying affected users within 72 hours of confirmation, providing details of the incident, the data or funds potentially affected, the measures we have taken to contain and remediate the incident, and recommended steps for affected users.

Post-incident, we conduct thorough root cause analysis and implement corrective actions to prevent recurrence. Lessons learned are incorporated into our security controls, monitoring rules, and developer training programmes.

08Protecting Your Account

While we provide robust security controls, account security is a shared responsibility. Here are steps you can take to protect your Send2Bank account. Never share your 4-digit PIN with anyone — not with friends, family, or anyone claiming to be from Send2Bank. Our staff will never ask for your PIN under any circumstances. Any message or call requesting your PIN is fraudulent and should be reported immediately.

Always log out of your account when using shared or public devices. Verify that you are on the authentic Send2Bank website by checking that the URL in your browser address bar shows send2bank.com with the padlock icon indicating a secure connection. Be cautious of phishing attempts — fraudulent emails or messages designed to look like they come from Send2Bank. We will never send you links asking you to enter your PIN or download software.

✅ Do

Use a unique PIN not used elsewhere, log out of shared devices, verify URLs before entering credentials, and report suspicious activity promptly.

❌ Don't

Share your PIN with anyone, use the same PIN across services, click on suspicious links claiming to be from Send2Bank, or ignore security alerts.

If you believe your account has been compromised, contact us immediately at [email protected]. We will lock your account to prevent further unauthorized activity, investigate the incident, verify your identity through our recovery process, and help you regain secure access to your funds and data.

09Responsible Disclosure

We welcome and encourage security researchers to responsibly investigate and report potential vulnerabilities in the Send2Bank platform. We value the contributions of the security research community and are committed to working collaboratively to address identified issues.

If you discover a security vulnerability, please report it to us by emailing [email protected] with a detailed description of the issue, including steps to reproduce, the potential impact, and any suggested remediation. Please allow us a reasonable period to investigate and address the issue before publicly disclosing any findings.

We commit to acknowledging receipt of your report within 48 hours, providing an initial assessment within 5 business days, keeping you informed of our progress throughout the remediation process, and not taking legal action against researchers who follow these responsible disclosure guidelines and act in good faith. We do not operate a public bug bounty programme at this time, but we acknowledge researchers who help improve our security.

10Compliance & Certifications

Send2Bank's security programme is aligned with industry standards and regulatory requirements applicable to financial technology platforms. We undergo regular security assessments and audits to verify the effectiveness of our controls. Our security practices are designed to meet or exceed the requirements of relevant data protection regulations, financial services regulations, and payment industry standards in the jurisdictions where we operate.

We maintain comprehensive documentation of our security policies, procedures, and controls. Our security programme is reviewed and updated at least annually, or more frequently in response to significant changes in our technology, operations, or threat landscape. Senior management reviews security metrics, incident reports, and programme status on a quarterly basis.

For enterprise customers requiring additional security assurances, we can provide security documentation, compliance reports, and completed security questionnaires under non-disclosure agreement. Please contact our security team at [email protected] for enterprise security inquiries.

Report a Security Issue

Found a vulnerability? Our security team responds within 48 hours.

[email protected]

Ready to Get Started?

Open your free Send2Bank account today and start collecting payments from anywhere.

Open Free Account →