Private beta — transfers activate after account and corridor approval.

Security

Last updated February 2026

What we have in place today to protect your account and data, and how to reach us if you find a problem.

Account protection

Accounts are protected by a password checked against known breach datasets at sign-up and at every change, and by email confirmation. Two-factor authentication using an authenticator app can be enabled from Settings and is required before sensitive actions once it is switched on.

Data access controls

Every customer table enforces row-level access policies in the database, so an account can only read and write its own records. Staff review access is a separate, explicitly granted role. Privileged helper functions are not executable by anonymous callers.

Record integrity

Balances are derived from an append-only double-entry ledger: entries cannot be edited or deleted after they are written. Administrative actions are written to an append-only audit log.

Payment data

Card and subscription payment details are collected and stored by our payment processor, not by Sendarapay. Recipient bank details are stored to attempt payouts and are shown only in truncated form in the interface.

Reporting a vulnerability

Report suspected vulnerabilities through the Support page with "security" in the subject. Please include enough detail to reproduce the issue, avoid accessing or modifying other people's data, and give us a reasonable opportunity to respond before disclosing publicly. We will acknowledge your report and keep you updated on the outcome.