Security
Built to hold other people’s money.
How we protect money and data, what is designed into the platform, and what will be in place before we take live payments.
Today we hold no customer money and no card data.
Card data
By design- Card numbers are collected in fields hosted by a PCI DSS certified vault provider and go straight to them. They never pass through or rest on our servers.
- We only ever handle tokens that stand in for a card. Our logs are scrubbed and tested so card data, ID numbers and secrets can’t end up in them.
- 3D Secure on every online card payment.
Where your data lives
By design- Live payment and merchant data will be hosted in South African data centres.
- Where a provider we rely on stores data outside South Africa, we assess the transfer under POPIA before using them, and list them in our privacy policy.
- Test and live run as separate systems with separate databases, so test activity can never touch real money or real customer data.
Money and records
By design- A double-entry, append-only ledger. Every movement is a balanced pair of entries; corrections are new entries, never edits.
- The ledger is reconciled every day against the bank’s records, and any difference is investigated by a person.
- Merchant funds are held in a dedicated account at a South African bank, separate from rano’s own money.
Accounts and access
By design- Two-factor authentication is required for every merchant account user.
- Staff use single sign-on with hardware security keys, and only get the access their role needs.
- Every staff action that touches money, settings or personal data is written to an audit log. Higher-risk actions need a second person to approve.
Engineering
By design- Encryption in transit and at rest, with extra field-level encryption for ID numbers and bank account numbers.
- Secrets and keys are kept in a managed key store, never in code.
- Every change is reviewed before it ships. Dependencies and code are scanned automatically.
Certification and testing
Before live payments- We are not PCI DSS certified today. We will complete PCI DSS validation as a service provider before we process live card payments.
- An independent penetration test before live payments, then at least twice a year, plus regular external vulnerability scans.
- A tested disaster recovery plan with written recovery targets.
Regulation
Before live payments- We will register as a third-party payment provider through a South African sponsor bank, as the Reserve Bank requires, and with the Financial Intelligence Centre.
- Our PAIA manual is published, and we will register our Information Officer with the Information Regulator.
- We won’t process real payments until these registrations are in place.
Report a vulnerability
Found something? Tell us first.
If you think you’ve found a security issue in rano, email security@rano.co.za with enough detail for us to reproduce it. Please give us a reasonable chance to fix it before telling anyone else, and don’t access data that isn’t yours.
We’ll acknowledge your report, keep you updated, and credit you if you’d like. Questions about how we handle personal information are covered in our privacy policy.