Skip to main content Meet Veengu at Seamless Fintech ME 2026 · Dubai · 22–24 Sep · Stand G62
Veengu
Home / Platform / Core banking security

Core banking security

Security is engineered into the Veengu platform — encryption, key management, access control, and a secure development lifecycle are part of how the platform is built, not controls bolted on after the first audit.

This page describes the technical measures Veengu implements. Regulatory compliance decisions remain the licensed operator’s responsibility.

01 02 03 01 Governance & people SDLC · pen-testing · DPAs 02 Network & infrastructure VPN · segmentation · allowlist 03 Application & API OAuth2 · rate limits · validation Sensitive data no PAN stored · tokenised
Security domains

Eight domains, one platform

Data, keys, access, code, vulnerabilities, network, monitoring and governance — the surfaces a regulated operator is asked about in every security review.

Data protection

TLS/SSL in transit. Highly sensitive data — payment tokens, cash-payout and remittance codes — is encrypted at rest. Any additional customer field can be configured for encryption at implementation time.

Key management

Managed cloud key management — AWS KMS on AWS, the equivalent managed service on Huawei Cloud, or an operator-managed service on-premise. Secure key creation and storage, IAM-controlled access, and logged key usage.

Access & identity

Role-based access control with granular, per-tenant roles and enforceable separation of duties. Multi-factor authentication for the back office; step-up authentication for end-users.

Secure development

A Secure Development Lifecycle with design approvals, code review, and automated plus manual testing. Regular penetration testing. Protection against common exploits such as XSS and SQL injection.

Vulnerability & patch management

Routine security scanning, severity-based prioritisation, and timely patching. Platform updates ship through the Support & Maintenance plan on every tier.

Network & API security

OAuth2/JWT or API keys, rate limiting, and input validation on the API surface. VPN for internal communications, IP whitelisting for partner links, and network segmentation isolating critical infrastructure.

Logging, monitoring & incident response

Three log streams — application, system, and business-event — with real-time monitoring and a defined incident-response plan. Business and security events are queryable from the operator dashboard.

Governance & people

Data Processing Agreements clarify third-party responsibilities. Employees receive recurring security training, and access is revoked immediately on departure. Data-centre security is provided by AWS or Huawei Cloud.

Encryption & key management

Sensitive data is protected in transit and at rest

Data moves over TLS. Sensitive fields are encrypted before they reach the database, using keys held in a managed key-management service — never in the application.

Managed KMS AWS · Huawei · on-prem 01 02 03 App / API TLS in transit Encrypt AES · field-level Encrypted at rest PostgreSQL
Access & identity

Two authentication paths, both stepped up

The operator back office and the end-user app are protected differently — RBAC plus MFA for staff, device-bound step-up authentication for customers.

Back office Operator user MFA / 2FA password + OTP RBAC role least privilege Back office End-user End-user Device key biometric Step-up 2FA 2nd factor · payment Authorise transaction
Secure development lifecycle

Security is built in at each stage

Five disciplines run from design to release, so vulnerabilities are caught before they reach production — not patched after an incident.

01

Design approval

Solution designs are reviewed and approved before implementation begins — security considerations are part of the design gate, not an afterthought.

02

Code review

Every change is peer-reviewed. Secure-coding practices are applied consistently across the engineering organisation.

03

Automated + manual testing

Automated test suites run on every change, complemented by manual testing that covers the edge cases beyond automated coverage. Applications are scanned for XSS, SQL injection and similar exploits.

04

Penetration testing

The platform undergoes regular penetration testing. Findings are prioritised by severity and remediated on a defined cadence.

05

Patch & release

Dependencies are kept current and vulnerabilities patched promptly. Updates are delivered through the Support & Maintenance plan.

Card data & compliance boundary

The platform is designed to minimise PCI DSS scope: sensitive card data is not stored by Veengu, and controlled API flows use encryption where sensitive data is passed. Certifications such as PCI DSS attach to the licensed operator that runs the regulated service — the platform is built to keep that perimeter as small as possible.

Veengu provides configurable KYC, AML-supporting workflows, audit trails, reporting tools, and integration capabilities. The licensed operator remains responsible for regulatory compliance decisions, monitoring policies, reporting obligations, and end-user outcomes.

FAQ

Frequently asked questions

How does Veengu protect data at rest and in transit?

All traffic uses TLS/SSL in transit. Highly sensitive data — payment tokens, cash-payout and money-remittance codes — is encrypted at rest by default, and any additional customer field can be configured for encryption during implementation.

How are encryption keys managed?

Veengu uses managed cloud key management — AWS KMS on AWS deployments, the equivalent managed service on Huawei Cloud, or an operator-managed service on-premise. Practices include secure key creation and storage, IAM-controlled access, and logged key usage.

Does Veengu follow a secure development lifecycle and run penetration tests?

Yes. Development follows a Secure Development Lifecycle with design approvals, code review, and automated plus manual testing. The platform undergoes regular penetration testing, and applications are scanned for common exploits such as XSS and SQL injection.

How does the platform handle authentication and access control?

Role-based access control provides granular, per-tenant roles with enforceable separation of duties. The back office supports multi-factor authentication; end-users are protected by step-up authentication — a device-bound key unlocked by biometrics, plus a second authentication factor to authorise a transaction.

Who is responsible for regulatory compliance?

Veengu provides configurable KYC, AML-supporting workflows, audit trails, reporting tools, and integration capabilities. The licensed operator remains responsible for regulatory compliance decisions, monitoring policies, reporting obligations, and end-user outcomes.

Is Veengu PCI DSS certified?

Certifications such as PCI DSS attach to the licensed operator that runs the regulated service, rather than to the software vendor. Veengu is built to keep that scope to a minimum — sensitive card data is not stored by Veengu, and controlled API flows use encryption where sensitive data is passed — so the operator’s certification perimeter stays as small as possible.

Send us your security requirements

Bring your regulatory licence, target geographies, and your security questionnaire. We respond within three business days.

Book a demo Send your scope