Trust

How money moves through FinVeil.

Payments are processed by Paystack. Where money settles depends on the payment type, and we set that out plainly below.

How funds flow

Customer System

FinVeil API

Provider Router

Paystack

Banks

Beneficiary

FinVeil records

Transaction Log

Routing Decision

Ledger

Audit Log

  • Split payments: Paystack settles each party's share directly to that party's Paystack subaccount.
  • Other collections (payment links without a split, API collections) settle into FinVeil's Paystack merchant balance. Payouts, when enabled, are funded from that balance.
  • Refunds and chargebacks are debited by Paystack from FinVeil's balance.

Security overview

The controls in place today.

  • AES-256-GCM field-level encryption for user, employer, employee and payroll personal data
  • JWT authentication with short-lived access tokens
  • Role-based access control (RBAC)
  • Audit log of key actions (not yet hash-chained or write-once)
  • Application-layer tenant isolation, with automated cross-tenant tests
  • Passwords hashed with BCrypt; API keys stored only as SHA-256 hashes

POPIA position

For employee and payroll data an employer uploads, the employer is the responsible party under the Protection of Personal Information Act, 2013 (POPIA) and FinVeil processes it as an operator. FinVeil is the responsible party for its own customers' account data. Our production systems are hosted in the United States (Railway, US West). Our privacy programme is under legal review.

Read our Privacy Policy →

Need more detail?

Ask us about our architecture, security controls and open items. We will tell you what is built, what is tested and what is not.

Contact info@finveil.money