Built to protect every dollar, every transaction.
Security is the foundation of ASHASH. We combine bank-grade controls with modern engineering so your business can move fast without compromise.
Encryption everywhere
All traffic is encrypted in transit with TLS 1.3. Sensitive fields are encrypted at rest with envelope encryption and per-tenant keys.
Strong authentication
Mandatory multi-factor authentication for every user. Passkeys, authenticator apps, and hardware keys (WebAuthn / FIDO2) supported.
Segregated client funds
Customer balances are held with regulated partner institutions in segregated safeguarding accounts — never used for lending.
24/7 fraud monitoring
Every payment and card authorisation is screened in real time by our risk engine — anomalies trigger step-up checks instantly.
Granular access controls
Role-based permissions, multi-approver payments, IP allow-lists, SSO (SAML / OIDC), and full audit trails on every action.
Continuous compliance
Embedded KYB / KYC, ongoing sanctions and PEP screening, and AML transaction monitoring aligned to FATF guidance.
Our security program
Defence in depth
Network segmentation, least-privilege access, encrypted backups, secret management with hardware-backed key storage, and continuous vulnerability scanning across the stack.
Incident response
A documented incident response plan, on-call security engineers, and customer notification procedures. Report a vulnerability or suspected incident to security@ashash.com.
This page is maintained by ASHASH to answer common security and privacy questions about our platform. It describes the controls we operate today and is not an independent attestation. Compliance certifications and audit reports are available under NDA on request.
