Skip to content

SECURITY

Bank-grade controls, without claiming to be a bank.

Security is the architecture here, not a feature we bolt on. Users keep control of their own funds, every entry balances, and each movement is screened, logged and reversible in the ledger before anyone sees it.

CONTROLS

Defense in depth, by design

Layered controls across custody, accounting and compliance mean no single failure can move funds it should not.

Non-custodial custody

Users keep control of their funds; no movement happens without their approval.

Double-entry ledger

Every movement is recorded as balanced debits and credits, so books reconcile continuously and discrepancies are impossible to hide.

Step-up approvals

High-value movements require an extra confirmation from the user before they execute, so no transfer happens unnoticed.

KYC/AML & travel rule

Identity, sanctions and counterparty screening run at onboarding and on every transfer, with travel-rule data exchanged where required.

Segregation & monitoring

Customer funds are held separately from operating capital and watched by real-time monitoring that flags anomalies as they happen.

Encryption & audit trail

Data is encrypted in transit and at rest, and every action is written to an immutable, timestamped audit trail.

ASSURANCES

What already holds today

Concrete, in-force controls and registrations, not roadmap items.

  • Registered MSB · Montana, USA
  • Non-custodial custody
  • KYC / AML
  • Travel rule
  • Immutable audit trail
  • End-to-end encryption

STANDARDS & COMPLIANCE

Certification-ready by design

Every client’s compliance needs are different. The platform is built to the security controls and measures behind these standards, so you can certify your product to the ones your market requires.

OWASP ASVS L2/L3

Control-ready

Application security verification across code, API and security controls.

PCI DSS (SAQ / Level 1)

Control-ready

Card-data security for card issuing and payments.

SOC 2 Type I / II

Control-ready

Security, availability and confidentiality of the service.

ISO/IEC 27001

Control-ready

Information security management system (ISMS).

CSA STAR

Control-ready

Cloud-specific security assurance.

FIDO / WebAuthn

Control-ready

Phishing-resistant passkeys and biometric sign-in.

GDPR

Control-ready

EU data protection and privacy (Regulation 2016/679).

CCPA / CPRA

Control-ready

California consumer privacy (US), the GDPR equivalent for California residents.

AML/CFT

Control-ready

Anti-money-laundering and counter-terrorist-financing program.

PSD2 SCA

Control-ready

Strong Customer Authentication for EU payments.

NIST CSF

Control-ready

U.S. NIST Cybersecurity Framework controls.

Penetration testing

Control-ready

Independent offensive testing against the live platform.

Tokelia is not a bank. Money services are provided by Tokelia LLC, a Delaware company (registered office: 8 The Green, Suite B, Dover, DE 19901) registered as a Money Services Business with FinCEN (MSB reg. no. 31000337250402), with its declared place of business in the State of Montana; regulated banking services are provided by licensed financial institutions, and availability varies by jurisdiction. Certification of a specific deployment is completed with a formal, independent audit; Tokelia is also pursuing its own ISO/IEC 27001 and SOC 2.

Ready to build with Tokelia?

Tell us your use case and we’ll point you to the right layer: infrastructure, tokenization or Yakopay.