Security

Users trust products that make their lives safe and easy. Every step of our product lifecycle is
protected by security technologies that detect, defend, and block cyber threats and fraudsters. 

a-security

Multi-Layered
Security

Every part of our ecosystem –
our perimeter, network, endpoint, application,
and data – has powerful built-in defenses.
This way, we can protect our customer’s
information and establish the transaction’s
authenticity at any given time.

Secure Product and
Software Development

Security is part of the whole software
development from as early as design stage to
production. The systems we deploy and the
subsequent changes we made should pass a
series of security and compliance tests before
they’re made available to our customers.

Centralized
Incident Response

We operate an in-house security
operations center to monitor, protect,
and defend our infrastructures and
systems from cyberattacks – 24/7.

Privacy

We protect and safeguard our user’s privacy. It’s our job to uphold our user’s right to privacy
by implementing industry best practices and by allowing them to choose privacy settings
that work for them.  

b-privacy

Culture of
Privacy

Valuing and respecting everyone’s
privacy starts from ourselves. That’s why
the way we live and the way things are
done in our organization are aligned with
our privacy commitments to our users.

Privacy-Centric
Products and Services

We build privacy by design and by default.
Everything that we create ensures our user’s
identity is private at the maximum degree
and protected from end to end. We only
capture information that’s most relevant
and use these for purposes our users
have given us permission.

Exercise of
Data Subject Rights

We’re always transparent about what
information we collect and how we use
them, and we make sure that our users
are empowered to exercise their rights
as provided by them by law. 

Compliance

We follow best practices and regulations not for compliance’s sake but we embrace these as our
own principles, which we know will help us gain our customer’s trust. That’s why we make sure
our platforms are certified by our peers and the way we do things are based on established rules.  

c-compliance

PCI Data Security
Standard (PCI DSS)

Every year, without fail, our platforms are
certified as compliant to the Payment
Card Industry DSS, the global standard
for card payments. What this means is
that the global industry is confident that
we maintain a secure network, protect
cardholder data, and implement strong
access and control measure.

BSP
Regulations

The Bangko Sentral ng Pilipinas, the country’s
financial system supervisor, regulates our
business. We fully believe that adhering
to their regulations that have guided our
innovation thinking will not only keep
everyone in our platform safe but also
advance our vision of financial inclusion.

Data Privacy 
Regulations

Our business is based on public’s trust. That’s
why we take every step to keep our users’
privacy secure and safe from cyberthreats
and fraudsters. Our data processing
standards are aligned with Philippines’ Data
Privacy Act of 2012. We’re also referring to
international regulations such as the General
Data Protection Regulation and California
Consumer Privacy Act.