SECURITY

Boring on purpose.

We move money for South African businesses. Our job is to be calm, accurate, and predictable — and the security of your data and funds is the first line of that promise.

LAST UPDATED · 7 MAY 2026

Data protection

All data in transit is encrypted using TLS 1.2 or higher. Sensitive data at rest — including bank account numbers, identification documents, and card credentials — is encrypted using industry-standard algorithms with keys managed in a hardware-backed key management service.

We minimise the data we hold. If we don't need it to operate the service or meet a regulatory obligation, we don't keep it.

Access control

Infrastructure

PanPay's services run on top-tier cloud infrastructure with data residency in South Africa where possible. We follow defence-in-depth principles: segmented networks, isolated environments for production and non-production, immutable infrastructure, and continuous vulnerability scanning.

We monitor for security events 24/7 and run regular third-party penetration tests against our applications and infrastructure.

Customer funds

Customer funds are held in segregated accounts at regulated South African banking partners. PanPay does not commingle customer funds with operating funds. All movement of customer money is logged on an immutable internal ledger and reconciled daily against bank records.

People & process

Responsible disclosure

If you believe you've found a security issue affecting PanPay, please email hello@usepanpay.org. We commit to:

Please do not test against live customer accounts, perform denial-of-service testing, or access data that does not belong to you.