Trust

FinVeil does not hold customer funds.

We are an orchestration and intelligence layer. Funds remain with the customer, their bank, or their licensed provider.

How funds flow

Customer System

FinVeil API

Provider Router

Stitch

Paystack

PayShap

EFT

Banks

Beneficiary

FinVeil records (no funds held)

Transaction Log

Routing Decision

Ledger

Audit Log

Security overview

Enterprise-grade security at every layer.

  • AES-256-GCM per-field encryption at rest
  • JWT authentication with short-lived access tokens
  • Role-based access control (RBAC)
  • Append-only audit logs on every data access
  • Tenant isolation — no employer can read another's data
  • No raw credentials stored — all secrets hashed or encrypted

POPIA position

FinVeil is the responsible party under the Protection of Personal Information Act, 2013 (POPIA) for all personal information processed through the platform. We process data lawfully, minimally, and with full consent tracking. Our privacy programme is under ongoing legal review.

Read our Privacy Policy →

Need more detail?

Compliance pack available under NDA. Includes architecture diagrams, security questionnaire responses, and POPIA impact assessment.

Contact info@finveil.money