Security

Your money is always protected

We take security seriously. Here's everything we do to keep your funds and data safe.

PCI DSS Level 1
Highest standard for payment card data security, independently audited annually
ISO 27001 Certified
International standard for information security management systems
99.97% Uptime
Monitored 24/7. View status page →

How we protect you

256-bit AES encryption

All sensitive data — account numbers, card details, documents — is encrypted using AES-256, the same standard used by governments and the world's top financial institutions. Data in transit is protected by TLS 1.3.

Biometric & multi-factor authentication

Support for Face ID, fingerprint (WebAuthn), TOTP authenticator apps, and SMS/email OTP. Every sensitive action (transfers, PIN changes) requires re-authentication. We support hardware security keys (FIDO2).

AI-powered fraud detection

Every transaction is scored in real time by our ML fraud engine. Unusual patterns — new devices, unusual locations, atypical amounts — trigger additional verification. Suspicious transactions are automatically held for review.

Segregated client funds

Your money is held in segregated accounts at CBN-regulated partner banks, completely separate from MyroPay's operating funds. In the event of insolvency, your funds are protected and not available to creditors.

Regular penetration testing

We conduct independent penetration tests quarterly and run a private bug bounty programme. Our security team includes certified ethical hackers and former fintech security engineers.

Report a vulnerability

If you discover a security vulnerability in MyroPay, please report it responsibly to our security team. We investigate all reports and credit researchers appropriately.

security@myropay.com

PGP key available on request. Please do not test on production user accounts or data.

Security you can count on

Every transaction. Every account. Every day.

Get started free → Talk to sales