Trust & Safety

Security & Compliance

How NectPay protects data, money movement, and the businesses that rely on us โ€” and where we are on the path to full regulatory authorisation.

FCA Authorisation
Not yet applied
Data Encryption
TLS 1.3 / AES-256
SOC 2 Type II
Planned, Year 2
On this page
  1. Regulatory status & approach
  2. Data protection & encryption
  3. How the compliance engine works
  4. Money movement & safeguarding
  5. Access control & infrastructure
  6. Incident response
  7. Sub-processors & partners
  8. Reporting a concern

Regulatory status & approach

NectPay Ltd intends to seek authorisation as a Payment Institution with the UK Financial Conduct Authority (FCA); this application has not yet been submitted. Until authorisation is granted, NectPay does not hold client funds at any point and operates exclusively through regulated partner institutions for all money movement. NectPay functions as a technology and compliance layer only โ€” the regulated partner institution (not NectPay) is the party of record for settlement.

We have chosen to pursue UK authorisation as our primary regulatory base because it gives enterprise clients in the UK and EU a familiar, well-understood compliance framework to evaluate us against, and because it is a prerequisite for the banking and payment partnerships NectPay depends on.

๐Ÿ‡ฌ๐Ÿ‡ง UK base

FCA Payment Institution authorisation intended โ€” application not yet submitted. NectPay does not hold client funds; all money movement is executed through regulated partner institutions. Registered entity: NectPay Ltd, Company No. 16134387, England & Wales.

๐ŸŒ Local licensing

In each African market, NectPay operates via licensed local partners (banks, mobile money operators, PSPs) until direct licensing is obtained.

As NectPay expands into individual African markets, we will pursue local licensing or regulated partnership arrangements (e.g. with a licensed Payment Service Provider) in each jurisdiction, consistent with that country's central bank requirements. We do not claim authorisation we do not yet hold, in any jurisdiction.

Data protection & encryption

NectPay is designed around the principle that recipient and transaction data should be encrypted at every stage โ€” in transit and at rest โ€” and accessible only to the systems and people who need it to process a payment.

How the compliance engine works

Every payout NectPay processes passes through jurisdiction-specific compliance checks before any payment rail is contacted. This is a deliberate architectural choice: compliance failures are caught at initiation, not mid-transfer.

You can see this logic running (against simulated data) in the live developer demo on our homepage.

Money movement & safeguarding

NectPay does not hold client funds at any stage. All funds are held and settled by regulated partner institutions (currently Thunes, pending integration). NectPay operates as a technology layer: it initiates and instructs payment flows but never takes custody of money in transit. This means:

Access control & infrastructure

Incident response

NectPay maintains an incident response plan covering detection, containment, client notification, and post-incident review for any security or data event. In the event of a data breach affecting client or recipient information, affected parties will be notified in line with UK GDPR requirements (without undue delay, and within 72 hours to the ICO where required).

A public status page tracking rail and system uptime is planned as part of our post-launch roadmap.

Sub-processors & partners

NectPay relies on a small number of sub-processors and regulated partners to deliver its service โ€” for example, cloud hosting providers, sanctions screening providers, and licensed payment institutions in each market. A current list of material sub-processors will be published here ahead of general availability, with advance notice of any additions.

Reporting a security concern

If you believe you've identified a security vulnerability in NectPay's systems, please report it to security@nectpay.com. We are committed to investigating credible reports promptly and will not pursue legal action against good-faith security researchers who report responsibly and do not access or exfiltrate client data.

Last updated: 15 July 2026.