Trust
Security and compliance, built in.
Moving money is a responsibility. Here's how we protect your payments and your data, and how to reach the people accountable for it.
Security programme
- Encryption everywhereTLS 1.2+ in transit, AES-256 at rest, and card data tokenised in a dedicated cardholder data environment.
- Least-privilege accessHardware-backed single sign-on, just-in-time production access, and every privileged action logged.
- Strong authentication3-D Secure 2 with automatic exemptions, so authentication appears only where it is needed.
- Resilient by designMulti-region infrastructure with automatic failover, designed for 99.99% availability.
- Continuous monitoring24/7 security monitoring, alerting and an on-call incident response team.
- Tested and disclosedContinuous vulnerability scanning and a public responsible disclosure programme.
Licensing
HansaPay provides payment services through regulated entities and licensed banking partners in each market we serve. The entity you contract with depends on where your business is based and is shown in your agreement and in the dashboard.
Financial crime
- Know your customerEvery business and its beneficial owners are verified before they can receive payouts, and monitored throughout the relationship.
- Anti-money launderingTransaction monitoring, suspicious activity reporting and a dedicated financial crime team, led by a designated compliance officer.
Seen a merchant misusing HansaPay? Report it.
Data protection
We collect only what we need to provide our services and meet our legal obligations, and we never sell personal information.
Read the full privacy policy, or contact our data protection team at [email protected].
Responsible disclosure
We welcome reports from security researchers. If you believe you’ve found a security vulnerability in HansaPay, email [email protected] with a description, steps to reproduce and any proof of concept.
- We will acknowledge your report within two business days and keep you updated on our progress.
- Please give us reasonable time to fix the issue before disclosing it publicly.
- Don’t access, modify or delete data that isn’t yours, degrade our services, or use social engineering or physical attacks.
- Test only against your own accounts, preferably in test mode.
We won’t pursue legal action against researchers who act in good faith and follow these guidelines. Our security.txt has the same details in machine-readable form.
Complaints
We want to put things right. If you’re unhappy with our service, contact [email protected] with “Complaint” in the subject line and your account details.
Accessibility
We aim for our website, dashboard and hosted checkout to meet WCAG 2.2 level AA. If you find something that’s hard to use, email [email protected] and we’ll fix it.
Questions from your security team?
Send them our way and we’ll answer what we can.