Skip to content

Security

Your money,behind more thana password.

Access to a Paydoly account is bound to a device you have proven you hold. Everything that moves money is approved in the app, logged, and visible to you afterwards.

  • Device-bound sessions
  • PIN or biometric approval
  • Full transaction log

01

How access is protected

The controls that sit between someone else and your balance.

Device binding
A session belongs to one device. Signing in on a new device requires re-verification, and you can see and revoke every active device from the app.
PIN or biometric
Every payment, request approval and exchange needs a PIN or biometric confirmation, even inside an already-open session.
Session expiry
Sessions end after inactivity and on sensitive changes — a new device, a changed phone number, a password reset.
Limits
Per-transaction, daily and monthly limits are tied to your verification level, so an unverified account cannot be used to move large sums.
Change confirmation
Changes to your phone number, email or payout destination are confirmed out of band and hold for a cooling-off period before they take effect.

02

How the money is protected

Controls on our side of the account rather than yours.

01Segregation

Customer funds held apart

Balances are held in segregated accounts, separate from operating funds, and reconciled daily against the ledger.

02Monitoring

Patterns, not just rules

Transaction monitoring flags unusual behaviour for review — new destinations, unusual amounts, velocity that does not match the account's history.

03Least privilege

Staff cannot move your money

No employee can initiate a transfer from a customer account. Support actions are role-scoped, individually logged and reviewed.

04Encryption

In transit and at rest

Traffic is encrypted end to end, sensitive fields are encrypted at rest, and card and credential material is never stored in plain form.

03

If your phone is lost or stolen

Do this first. It takes about a minute and does not require the device.

  1. 01Freeze the accountEmail security@paydoly.com or call support and say 'lost device'. We freeze it on request, before any verification questions.
  2. 02Revoke the sessionFrom any other device, sign in and remove the lost device. That ends its session immediately, even if the phone is still on.
  3. 03Check the logReview the transaction and device history for anything you do not recognise, and tell us about each item you dispute.
  4. 04Re-verify and resumeOn your new device, re-verify to restore access. Your balance and history are unaffected by the freeze.
If a control only works when the customer behaves perfectly, it is not a control. It is a warning label.
Paydoly security principles

04

Reporting a vulnerability

If you believe you have found a security flaw in a Paydoly product, write to security@paydoly.com with enough detail to reproduce it. We acknowledge reports within two business days and tell you what we intend to do about the finding.

We will not pursue legal action against anyone who reports a genuine issue in good faith, provided they do not access, modify or retain other people's data, do not degrade the service for others, and give us reasonable time to fix the issue before disclosing it publicly.

We do not currently run a paid bounty programme. We do credit reporters who want to be named once a fix has shipped.

Money already moves through your life.Now it moves together.

Explore Paydoly

Get started

Open a Paydoly account

A wallet, a PayMe handle and your first payment request are ready in your first session. Verification raises your limits from there.

Account opening isn't available on this website yet. For help getting started, write to help@paydoly.com or message us on WhatsApp.