Skip to main content
PlaitrBlog

Security.

This page describes how Plaitr is put together and what actually stands between your money and a bad day. It is deliberately short on badges. Where a control is a matter of structure — who holds the funds, who is regulated, who can open an account — we say so precisely. Where it is a matter of practice, we point you at the document that governs it rather than a logo.

Plaitr is a non-custodial financial technology company, not a bank. Read that sentence as an architectural statement, not a disclaimer: it determines where your balance sits and what happens to it if we are not here.

Custody

Where your money sits

Plaitr does not hold customer funds, digital assets or private keys. There is no Plaitr account holding your balance on your behalf and no Plaitr wallet signing your transactions. Plaitr is the software layer that businesses use to run accounts, payments, cards and accounting in one place.

Banking services — account opening, deposits and outbound transfers — are delivered by licensed partner institutions in each jurisdiction where Plaitr is available. Balances held with those institutions are held under the terms of that institution and its home regulator. Payins and payouts on local rails are made available through third-party payment partners, and cards, when available, are issued by regulated card partners.

Deposit protection is not ours to promise. Availability of deposit protection schemes varies by partner and by jurisdiction, and the answer for a US-incorporated company is not the answer for an Indian or Singaporean one. Before you fund an account, ask which institution serves your country and what that institution’s home regime provides. We would rather tell you it is thin than let you assume it is thick.

If Plaitr disappeared tomorrow

The account and the balance are with the partner institution, not with us, and that relationship is governed by that institution’s terms and its home regulator. It does not depend on Plaitr’s software continuing to run. What happens next would be determined by that institution and by applicable law — not by Plaitr, and not by anything written on this page.

Access

Who can open an account

Every Plaitr customer goes through business verification, identity verification and ongoing compliance monitoring. In practice that means checks on the entity, on the people who own and direct it, and sanctions screening — run directly or through third-party providers — before an account opens and repeatedly after it does. Monitoring is not a one-time gate at signup.

Plaitr may decline or pause services where required by law or by a partner institution. Access also depends on successful onboarding and on continuing to meet eligibility and compliance requirements. Product availability, pricing and service levels vary by country and may change without notice, so the fact that a rail or a corridor works for one customer does not mean it is open to every business in every market.

What you use the account for is in scope too. Our Prohibited Use Policy sets out what cannot run through Plaitr, and you are responsible for ensuring your use complies with the laws and tax rules that apply to your business locally. Compliance is part of the product, not a step bolted on at the end of the month — see business compliance.

Data

Your data

Running a regulated payment flow means collecting more than an email address: company records, ownership and director information, identity documents, transaction detail, and the logs that make fraud and abuse detectable. The Privacy Policy is the authoritative account of what is collected, why, and on what legal basis.

The platform is designed around the ordinary categories of technical and organisational protection — measures intended to protect information from loss, misuse, unauthorised access, disclosure, alteration and destruction. We are not going to publish a configuration, a key length or a vendor list on a marketing page; if a vendor questionnaire needs specifics, ask and we will answer it directly. And no system is completely secure. We cannot guarantee absolute security, and where a breach affects your personal information we will notify you and the relevant authorities as required by applicable law.

Transaction data is shared with partner institutions and compliance vendors where that is necessary to screen and settle a payment. Personal data is kept only as long as it is needed, except where AML, accounting or other legal obligations require longer retention — which they routinely do in this industry.

Some of it is on you. Keep credentials and API keys confidential, turn on multi-factor authentication where it is available, and email support@plaitr.com immediately if you suspect someone else has been in your account. An attacker with a valid key looks a lot like a user.

Limits

What we do not do

  • Hold your funds. Balances sit with licensed partner institutions, under their terms and their home regulator.
  • Hold your private keys. Stablecoin movement is non-custodial; Plaitr never takes custody of the assets.
  • Act as a bank, a money services business or a card issuer. Regulated banking, custody and card issuance come from licensed partners.
  • Provide deposit insurance. Whether a deposit protection scheme applies depends on the partner and the jurisdiction.
  • Claim certifications we have not earned. You will not find an audit badge on this page, because we are not going to put one here until there is one to put.
  • Guarantee availability. Product availability, pricing and service levels vary by country and may change without notice, and screenshots shown across this site are illustrative.

If a procurement or security review needs an attestation we do not have, the honest answer is that we do not have it yet, and you should get that answer from us before you sign, not after.

Disclosure

Report a vulnerability

If you believe you have found a vulnerability in Plaitr, report it to support@plaitr.com. That is the address named in our Terms of Service for exactly this.

Useful reports say what you found, how to reproduce it, and what an attacker could actually do with it. Test against your own account and your own data. Do not run anything that degrades the service for other customers, and do not access, modify or retain data that is not yours.

We are not advertising a bounty or a response window, because we would rather promise nothing than promise a number we cannot hold to. If the issue affects your own account right now, say so in the subject line so it is not read as a research note.

Frequently asked

Is Plaitr a bank?

No. Plaitr is a non-custodial financial technology company, not a bank, money services business or card issuer. Banking services — account opening, deposits, outbound transfers — are delivered by licensed partner institutions in each jurisdiction where Plaitr is available. Plaitr provides the software layer that ties accounts, payments and books together.

Who holds my money?

A licensed partner institution does. Plaitr does not hold customer funds, digital assets or private keys. Balances sit with the partner institution under that institution's terms and its home regulator. Payins and payouts on local rails are made available through third-party payment partners in each corridor.

Is my balance protected?

It depends on the partner institution and the jurisdiction. Balances are held under that institution's terms and its home regulator, and the availability of deposit protection schemes varies by partner and by country. Plaitr does not offer deposit insurance of its own. Ask us which partner serves your country before you fund the account.

What happens if Plaitr shuts down?

Plaitr is the software layer, not the account. Your balance sits with a licensed partner institution and is governed by that institution's terms and its home regulator, so it does not depend on Plaitr's software continuing to run. What follows in that situation is determined by the partner institution and applicable law.

How do I report a security issue?

Email support@plaitr.com with what you found, how to reproduce it and anything that shows the impact. That is the address in our Terms for reporting a vulnerability. We are not advertising a bounty or a response window we cannot hold to. If you think your own account was accessed, say so in the subject line.

Ask us the awkward question.

Which institution serves your country, what protection applies to your balance, what happens to a payment mid-flight. If you are weighing a move, the switching guide covers what moving over actually involves.