Skip to main content

Security

Wallet data sits at the centre of your business.
Here is how we hold it.

Encryption-at-rest. Tokenised PAN storage. Single-tenant database per operator on Enterprise. Sub-processor disclosure on this page, updated when it changes. Disclosure address below.

01 · Encryption

Data at rest, data in transit.

At rest

Database storage is encrypted with AES-256-GCM via the cloud provider's managed key service. Customer PII fields (phone, name, address) are additionally encrypted at the application layer with per-tenant data keys, derived from envelope encryption against a hardware-backed root key. Backups inherit the at-rest encryption posture.

In transit

All external traffic terminates at TLS 1.3 with modern cipher suites (TLS_AES_256_GCM_SHA384 preferred). HSTS preload is shipped. Internal service-to-service traffic uses mutual TLS with short-lived workload identities. The operator dashboard ships strict-transport-security, content-security-policy, x-content-type-options: nosniff, and referrer-policy: strict-origin-when-cross-origin by default.

Cardholder data

Feddi does not store raw PANs. Card details flow directly to the acquirer's tokenisation endpoint; we hold only the resulting network token plus brand + last-four for display. PCI DSS scope is minimised to the operator-dashboard browser + acquirer-redirect surfaces.

02 · Access control

Who can read what, and how we know.

Operator dashboard

Role-based access with three default roles (Owner, Operator, Read-only) plus custom roles on Enterprise. Single sign-on via SAML 2.0 + SCIM provisioning on Operator and Enterprise tiers. Hardware-token-backed MFA enforceable per role. Per-branch scoping limits operators to the data and surfaces for their branches.

Audit log

Every read of customer-level data and every write that creates or modifies a wallet, customer record, or incentive rule emits a structured audit event. Logs include actor, source IP, action, target IDs, and outcome. Audit log is append-only, exportable to the operator's SIEM via webhook or scheduled export.

Internal access

Feddi engineering does not access operator customer data as a default. Production access requires explicit JIT escalation through a change ticket, two-engineer review, and is automatically logged. Background workers run with workload identities scoped to the minimum required dataset.

03 · Compliance posture

Where we are with attestations.

  • PCI DSS Scope minimised, controls implemented Certification level pending; see acquirer integration scope.
  • SOC 2 Type II Audit in progress Auditor and audit-window dates available under NDA on request.
  • KSA PDPL Implemented Data subject rights, retention windows, cross-border transfer controls per the Personal Data Protection Law (KSA, 2023).
  • GDPR Implemented DSR processing, lawful basis surfacing, processor agreements for sub-processors. DPO contact on this page.
  • ISO 27001 On roadmap Scoped for the year following SOC 2 closure.

Every status above reflects where we are today. We will not claim a certification we do not hold. When status changes, this page changes the same day.

04 · Sub-processors

Every third party that touches operator data.

Sub-processor Purpose Data scope Region
Amazon Web ServicesCore compute, storage, networkingAll operator datame-central-1 (UAE), me-south-1 (Bahrain)
CloudflareEdge, DNS, DDoS, WAFRequest metadata, no customer payloadGlobal edge, KSA + UAE PoPs primary
Stripe / acquirer-of-recordCard tokenisation, wallet top-up railsCard BIN + last4, network tokenPer acquirer agreement
ResendTransactional email (receipts, password resets)Email + transactional contextEU + US data centres
Twilio (Programmable Messaging)SMS receipts, wallet pass install linksPhone + message bodyPer Twilio region; GCC routing via local carriers
SentryApplication error monitoringStack traces, scrubbed of PIIEU data centre

Operators on Enterprise can request data-residency commitments and sub-processor opt-out for specific surfaces. Notice of any change to this list ships 30 days before activation by default; faster notice is configurable per agreement.

05 · Disclosure

Found something. Tell us.

If you believe you have found a security vulnerability affecting Feddi, report it to security@feddi.com. We acknowledge reports within one business day. We do not pursue legal action against good-faith researchers acting under standard responsible-disclosure expectations.

In scope

  • feddi.com and all subdomains we operate
  • The operator dashboard at app.feddi.com
  • Public APIs documented at docs.feddi.com
  • Wallet pass surfaces in Apple Wallet and Google Wallet

Out of scope

  • Findings requiring physical access to operator devices
  • Social-engineering of Feddi staff or operator employees
  • Denial-of-service findings that depend on traffic volume rather than a logic flaw
  • Third-party services not operated by Feddi (sub-processor surfaces, report to the sub-processor)

A formal bug bounty programme is on the roadmap. Until it ships we coordinate disclosure case-by-case with a thank-you and a public acknowledgement (with your consent) once the fix is live.

Built for the future. Available today.

A deeper security review packet is available under NDA. Ask for it from your sales contact.