FeesPaymentsPricingDevelopersAbout
Get early access
  • Fees
  • Payments
  • Pricing
  • Developers
  • About
Get early access

Security

Built to hold other people’s money.

How we protect money and data, what is designed into the platform, and what will be in place before we take live payments.

Today we hold no customer money and no card data.

Card data

By design
  • Card numbers are collected in fields hosted by a PCI DSS certified vault provider and go straight to them. They never pass through or rest on our servers.
  • We only ever handle tokens that stand in for a card. Our logs are scrubbed and tested so card data, ID numbers and secrets can’t end up in them.
  • 3D Secure on every online card payment.

Where your data lives

By design
  • Live payment and merchant data will be hosted in South African data centres.
  • Where a provider we rely on stores data outside South Africa, we assess the transfer under POPIA before using them, and list them in our privacy policy.
  • Test and live run as separate systems with separate databases, so test activity can never touch real money or real customer data.

Money and records

By design
  • A double-entry, append-only ledger. Every movement is a balanced pair of entries; corrections are new entries, never edits.
  • The ledger is reconciled every day against the bank’s records, and any difference is investigated by a person.
  • Merchant funds are held in a dedicated account at a South African bank, separate from rano’s own money.

Accounts and access

By design
  • Two-factor authentication is required for every merchant account user.
  • Staff use single sign-on with hardware security keys, and only get the access their role needs.
  • Every staff action that touches money, settings or personal data is written to an audit log. Higher-risk actions need a second person to approve.

Engineering

By design
  • Encryption in transit and at rest, with extra field-level encryption for ID numbers and bank account numbers.
  • Secrets and keys are kept in a managed key store, never in code.
  • Every change is reviewed before it ships. Dependencies and code are scanned automatically.

Certification and testing

Before live payments
  • We are not PCI DSS certified today. We will complete PCI DSS validation as a service provider before we process live card payments.
  • An independent penetration test before live payments, then at least twice a year, plus regular external vulnerability scans.
  • A tested disaster recovery plan with written recovery targets.

Regulation

Before live payments
  • We will register as a third-party payment provider through a South African sponsor bank, as the Reserve Bank requires, and with the Financial Intelligence Centre.
  • Our PAIA manual is published, and we will register our Information Officer with the Information Regulator.
  • We won’t process real payments until these registrations are in place.

Report a vulnerability

Found something? Tell us first.

If you think you’ve found a security issue in rano, email security@rano.co.za with enough detail for us to reproduce it. Please give us a reasonable chance to fix it before telling anyone else, and don’t access data that isn’t yours.

We’ll acknowledge your report, keep you updated, and credit you if you’d like. Questions about how we handle personal information are covered in our privacy policy.

Payments for South African businesses, with the fee on the receipt.

Get early access

Product

How fees workPayment methodsPricingCalculator

Developers

API docsTest modeWebhooksErrors

Company

AboutSecurityContactEarly access

Legal

Terms of usePrivacyCookiesPAIA manualAcceptable useMerchant terms

rano is in early access and is not yet processing live payments. The fees for your business are confirmed in your merchant agreement.

© 2026 rano · Built in South Africa