Security

Built to protect every dollar, every transaction.

Security is the foundation of ASHASH. We combine bank-grade controls with modern engineering so your business can move fast without compromise.

Encryption everywhere

All traffic is encrypted in transit with TLS 1.3. Sensitive fields are encrypted at rest with envelope encryption and per-tenant keys.

Strong authentication

Mandatory multi-factor authentication for every user. Passkeys, authenticator apps, and hardware keys (WebAuthn / FIDO2) supported.

Segregated client funds

Customer balances are held with regulated partner institutions in segregated safeguarding accounts — never used for lending.

24/7 fraud monitoring

Every payment and card authorisation is screened in real time by our risk engine — anomalies trigger step-up checks instantly.

Granular access controls

Role-based permissions, multi-approver payments, IP allow-lists, SSO (SAML / OIDC), and full audit trails on every action.

Continuous compliance

Embedded KYB / KYC, ongoing sanctions and PEP screening, and AML transaction monitoring aligned to FATF guidance.

Our security program

Defence in depth

Network segmentation, least-privilege access, encrypted backups, secret management with hardware-backed key storage, and continuous vulnerability scanning across the stack.

Incident response

A documented incident response plan, on-call security engineers, and customer notification procedures. Report a vulnerability or suspected incident to security@ashash.com.

This page is maintained by ASHASH to answer common security and privacy questions about our platform. It describes the controls we operate today and is not an independent attestation. Compliance certifications and audit reports are available under NDA on request.