Design approval
Solution designs are reviewed and approved before implementation begins — security considerations are part of the design gate, not an afterthought.
Security is engineered into the Veengu platform — encryption, key management, access control, and a secure development lifecycle are part of how the platform is built, not controls bolted on after the first audit.
This page describes the technical measures Veengu implements. Regulatory compliance decisions remain the licensed operator’s responsibility.
Data, keys, access, code, vulnerabilities, network, monitoring and governance — the surfaces a regulated operator is asked about in every security review.
TLS/SSL in transit. Highly sensitive data — payment tokens, cash-payout and remittance codes — is encrypted at rest. Any additional customer field can be configured for encryption at implementation time.
Managed cloud key management — AWS KMS on AWS, the equivalent managed service on Huawei Cloud, or an operator-managed service on-premise. Secure key creation and storage, IAM-controlled access, and logged key usage.
Role-based access control with granular, per-tenant roles and enforceable separation of duties. Multi-factor authentication for the back office; step-up authentication for end-users.
A Secure Development Lifecycle with design approvals, code review, and automated plus manual testing. Regular penetration testing. Protection against common exploits such as XSS and SQL injection.
Routine security scanning, severity-based prioritisation, and timely patching. Platform updates ship through the Support & Maintenance plan on every tier.
OAuth2/JWT or API keys, rate limiting, and input validation on the API surface. VPN for internal communications, IP whitelisting for partner links, and network segmentation isolating critical infrastructure.
Three log streams — application, system, and business-event — with real-time monitoring and a defined incident-response plan. Business and security events are queryable from the operator dashboard.
Data Processing Agreements clarify third-party responsibilities. Employees receive recurring security training, and access is revoked immediately on departure. Data-centre security is provided by AWS or Huawei Cloud.
Data moves over TLS. Sensitive fields are encrypted before they reach the database, using keys held in a managed key-management service — never in the application.
The operator back office and the end-user app are protected differently — RBAC plus MFA for staff, device-bound step-up authentication for customers.
Five disciplines run from design to release, so vulnerabilities are caught before they reach production — not patched after an incident.
Solution designs are reviewed and approved before implementation begins — security considerations are part of the design gate, not an afterthought.
Every change is peer-reviewed. Secure-coding practices are applied consistently across the engineering organisation.
Automated test suites run on every change, complemented by manual testing that covers the edge cases beyond automated coverage. Applications are scanned for XSS, SQL injection and similar exploits.
The platform undergoes regular penetration testing. Findings are prioritised by severity and remediated on a defined cadence.
Dependencies are kept current and vulnerabilities patched promptly. Updates are delivered through the Support & Maintenance plan.
The platform is designed to minimise PCI DSS scope: sensitive card data is not stored by Veengu, and controlled API flows use encryption where sensitive data is passed. Certifications such as PCI DSS attach to the licensed operator that runs the regulated service — the platform is built to keep that perimeter as small as possible.
Veengu provides configurable KYC, AML-supporting workflows, audit trails, reporting tools, and integration capabilities. The licensed operator remains responsible for regulatory compliance decisions, monitoring policies, reporting obligations, and end-user outcomes.
All traffic uses TLS/SSL in transit. Highly sensitive data — payment tokens, cash-payout and money-remittance codes — is encrypted at rest by default, and any additional customer field can be configured for encryption during implementation.
Veengu uses managed cloud key management — AWS KMS on AWS deployments, the equivalent managed service on Huawei Cloud, or an operator-managed service on-premise. Practices include secure key creation and storage, IAM-controlled access, and logged key usage.
Yes. Development follows a Secure Development Lifecycle with design approvals, code review, and automated plus manual testing. The platform undergoes regular penetration testing, and applications are scanned for common exploits such as XSS and SQL injection.
Role-based access control provides granular, per-tenant roles with enforceable separation of duties. The back office supports multi-factor authentication; end-users are protected by step-up authentication — a device-bound key unlocked by biometrics, plus a second authentication factor to authorise a transaction.
Veengu provides configurable KYC, AML-supporting workflows, audit trails, reporting tools, and integration capabilities. The licensed operator remains responsible for regulatory compliance decisions, monitoring policies, reporting obligations, and end-user outcomes.
Certifications such as PCI DSS attach to the licensed operator that runs the regulated service, rather than to the software vendor. Veengu is built to keep that scope to a minimum — sensitive card data is not stored by Veengu, and controlled API flows use encryption where sensitive data is passed — so the operator’s certification perimeter stays as small as possible.
Multi-zone by design; blue-green upgrades; point-in-time recovery.
ReadCompare deployment models and data-sovereignty posture.
ReadMulti-tier KYC, sanctions & PEP screening, audit trail.
ReadSeverity model, escalation matrix, and maintenance cadence.
ReadAPIs, sandbox, certification path, release policy.
ReadLedger, postings, settlement and end-of-day cycles.
ReadBring your regulatory licence, target geographies, and your security questionnaire. We respond within three business days.