Trust
How money moves through FinVeil.
Payments are processed by Paystack. Where money settles depends on the payment type, and we set that out plainly below.
How funds flow
Customer System
FinVeil API
Provider Router
Paystack
Banks
Beneficiary
FinVeil records
Transaction Log
Routing Decision
Ledger
Audit Log
- Split payments: Paystack settles each party's share directly to that party's Paystack subaccount.
- Other collections (payment links without a split, API collections) settle into FinVeil's Paystack merchant balance. Payouts, when enabled, are funded from that balance.
- Refunds and chargebacks are debited by Paystack from FinVeil's balance.
Security overview
The controls in place today.
- AES-256-GCM field-level encryption for user, employer, employee and payroll personal data
- JWT authentication with short-lived access tokens
- Role-based access control (RBAC)
- Audit log of key actions (not yet hash-chained or write-once)
- Application-layer tenant isolation, with automated cross-tenant tests
- Passwords hashed with BCrypt; API keys stored only as SHA-256 hashes
POPIA position
For employee and payroll data an employer uploads, the employer is the responsible party under the Protection of Personal Information Act, 2013 (POPIA) and FinVeil processes it as an operator. FinVeil is the responsible party for its own customers' account data. Our production systems are hosted in the United States (Railway, US West). Our privacy programme is under legal review.
Read our Privacy Policy →Need more detail?
Ask us about our architecture, security controls and open items. We will tell you what is built, what is tested and what is not.
Contact info@finveil.money