Doc 06

Security statement

This statement describes how MMFintech Ltd. protects the information and the funds entrusted to it. It is a summary written for clients and prospective partners. Detailed control documentation, including our information security policy and the results of independent testing, is available to providers and auditors under a confidentiality agreement.

How the programme is structured

Client funds are held in accounts operated by licensed payment providers. Payment identifiers, cards and wallets are issued on that infrastructure. MMFintech Ltd. operates the client relationship, the record of individual balances, and the compliance controls described elsewhere on this page. Security responsibilities are allocated between MMFintech Ltd. and each provider in a written agreement.

Protecting information

  • Data is encrypted in transit using current transport layer security, and encrypted at rest.
  • Cryptographic keys are managed in a dedicated key management service, with restricted access and periodic rotation.
  • Access follows the principle of least privilege. Rights are granted by role, reviewed periodically, and removed promptly when someone changes role or leaves.
  • Multi-factor authentication is required for administrative and privileged access.
  • Actions on client records and on systems are written to an audit log that cannot be altered by the person who generated the entry.
  • Production data is not used in development or test environments unless it has been masked.
  • We minimise what we hold. Full card numbers are not stored, processed or transmitted on our systems; card data is handled by certified providers using hosted components and tokenisation.

Protecting accounts

  • Strong authentication is required for client access, with additional verification for sensitive actions such as changing a registered destination.
  • Withdrawal destinations must be registered and verified before they can be used.
  • Session controls, device recognition and rate limiting are applied to reduce the risk of account takeover.
  • Clients are notified of security-relevant events on their account.

Building and running systems securely

  • Changes follow a controlled process with peer review, segregation of duties between development and deployment, and the ability to roll back.
  • Dependencies and infrastructure are monitored for known vulnerabilities, and patches are applied on a risk-prioritised schedule.
  • Independent penetration testing is carried out at least annually and after significant change, with findings tracked to closure.
  • Systems are monitored continuously for anomalous activity, with alerting to a named responder.

Suppliers

Providers and technology suppliers are assessed before engagement and reviewed periodically. Assessment covers their regulatory standing, security certifications, incident history, subcontracting arrangements and the location of data processing. Security and confidentiality obligations are set out contractually.

Continuity and resilience

Business continuity and disaster recovery plans are documented, with defined recovery time and recovery point objectives, and are tested periodically. Backups are taken regularly, encrypted, held separately from production systems, and restoration is tested.

Incident response

We maintain a documented incident response plan covering detection, containment, investigation, remediation and communication. Where an incident creates a real risk of significant harm to an individual, we report it to the Office of the Privacy Commissioner of Canada and notify the affected individuals as soon as feasible, in line with our obligations under PIPEDA, and we keep a record of every breach of security safeguards. Providers and regulators are notified as required by contract and by law.

People

Background checks are carried out on personnel in line with their role. Security and confidentiality obligations are set out in contracts of employment and engagement, and all personnel complete security awareness training on joining and periodically thereafter.

Reporting a vulnerability

If you believe you have found a security vulnerability in our website or services, please tell us at support@mmfintechgroup.com. Include enough detail for us to reproduce the issue. We acknowledge reports within 5 business days and will keep you informed while we investigate.

Please give us a reasonable opportunity to fix the issue before disclosing it publicly, and do not access, modify or delete data belonging to anyone else, degrade our services, or use social engineering or physical intrusion in your testing. We will not pursue action against researchers who report in good faith and within these limits.