Security

Treated as infrastructure, from the first line of code

Every merchant is verified before their first payout. Every action is logged. Nothing about how money moves is left to trust alone.

Controls built into the way payments work

Tiered verification

Every merchant starts with phone verification and grows into full KYC, with transaction limits and settlement speed tied to trust. Higher tiers unlock higher limits and faster settlement.

Immutable ledger

Every transaction is recorded in an append-only ledger. Nothing is edited or deleted after the fact, giving every collection and settlement a permanent, auditable trail.

Data isolation

Each merchant's data is isolated at the database level, not just enforced in application code, so one merchant's data is never reachable from another's account.

Verified counterparties

The registered mobile money name behind every number is confirmed before money moves, for both the merchant's protection and the customer's.

API & infrastructure

Security at every connection

  • Encrypted credentials
  • Hashed API keys
  • Signed and verifiable webhooks
  • Rate-limited endpoints
  • Provider-agnostic architecture

A provider-agnostic architecture helps reduce dependence on any single processor, so one processor outage or change is less likely to disrupt merchant operations.

Responsible disclosure

Report a vulnerability

If you've found a security issue, we want to know. Please email security@kawrie.com with the details so our team can review it.