Platform

Platform Architecture and Security

How the platform is built, where it runs, what protects it, and what Remitz deliberately does not do — written for the technical and compliance reviewers who have to sign this off.

The short version

Remitz is software. Your firm holds the authorisation, the provider relationships and the customer funds. Our job is to give you a platform that withstands your regulator's scrutiny and your own security review — and to be straightforward about where its limits are.

This page exists so a technical or compliance reviewer can assess the platform without booking a call. If your due-diligence questionnaire needs something that is not here, ask and we will answer it in writing.

How the platform is built

The backend is a Java service built on Spring Boot, running against a relational database. The customer web portal and the branded mobile applications are built on Angular and Ionic, packaged with Capacitor so that iOS and Android builds are produced from one codebase rather than two.

Deployments are containerised, which is what makes a dedicated tenant or a fully separate deployment practical for enterprise customers rather than a bespoke engineering project.

We do not publish component version numbers. Version disclosure helps an attacker more than it helps a reviewer, and the information is available under NDA during an enterprise evaluation.

Where it runs, and where your data sits

  • UK data residency by default. Processing is governed by UK GDPR and the Data Protection Act 2018.
  • Managed infrastructure. Remitz applies security patches, runs monitoring and takes backups. Your team never maintains a server.
  • Deployment options. Standard plans run on shared multi-tenant infrastructure. Enterprise customers can take a dedicated tenant (logically isolated) or a fully dedicated deployment where regulatory separation is required.

Security controls in operation today

This list is deliberately limited to what is actually running. Nothing aspirational appears here.

  • Encryption in transit — TLS 1.3 across the platform
  • Multi-factor authentication on administrative access
  • JWT-based authentication with role-based permissions and segregation of duties between operations, compliance and finance
  • Full audit trail of every transaction, customer interaction and compliance decision, retained for your regulatory retention period and exportable
  • Independent uptime monitoring with a public status page hosted by a third party, which you can check at any time without asking us

What Remitz does not do

Every item below is a question that surfaces eventually. We would rather you had the answer now than during a procurement review.

  • We never hold client money. Remitz does not hold, receive or control customer funds. No customer money sits with us, and none is at risk if we fail.
  • We are not ISO 27001 certified and do not currently commission third-party penetration testing.
  • We do not provide safeguarding reconciliation. The platform gives you the ledger, nostro-account balances reconciled against your payout partners, settlement records and an exportable audit trail — but there is no purpose-built safeguarding reconciliation module or automated attestation reporting. If your permission requires daily safeguarding reconciliation, that process sits with your finance function.
  • We do not supply banking, payout, KYC, payment gateway or licensing services. You hold each of those relationships directly. See how the integrations work.

Supporting your regulatory obligations

Under FCA outsourcing and operational resilience expectations, your firm remains accountable for functions it outsources. Remitz provides what you need to evidence that oversight: access control documentation, backup and recovery arrangements, audit trail exports, and written exit provisions.

Where an obligation is yours rather than ours — safeguarding, transaction monitoring policy, customer due diligence standards — the platform is built to help you discharge it, not to take it on. That distinction matters to your regulator and it should matter in your vendor assessment.

Business continuity and exit

  • Backups are taken as part of managed infrastructure, with recovery arrangements documented during enterprise onboarding.
  • Data portability is included in the standard contract. Transaction records, customer records and the audit trail are exportable.
  • Source-code licensing is available for operators who need ownership rather than a subscription — the honest answer to “what happens to us if Remitz stops trading”.

Frequently Asked Questions

Where is Remitz hosted and where is customer data stored?
The platform runs on managed UK infrastructure, with data residency in the United Kingdom by default and processing governed by UK GDPR and the Data Protection Act 2018. Enterprise customers can opt for a dedicated tenant or a fully dedicated deployment where regulatory separation is required.
What is the Remitz platform built on?
The backend is a Java service built on Spring Boot with a relational database. The customer web portal and the branded mobile apps are built on Angular and Ionic, packaged with Capacitor so iOS and Android are produced from a single codebase. Deployments are containerised. We do not publish component version numbers.
Can Remitz see or move my customers’ money?
No. Remitz is software and never holds, receives or controls client money. Funds move between your own accounts and your own payout partners under your own permission and your own credentials. No customer funds sit with Remitz and none are at risk if Remitz fails.
Can I self-host the Remitz platform?
Standard plans are managed SaaS on Remitz infrastructure. Enterprise deployments can run on dedicated infrastructure, and a source-code licence is available for operators who require full ownership. Self-hosting moves patching, monitoring, backup and availability responsibility to your team, which is the trade-off to weigh.
Does Remitz hold ISO 27001 certification?
No. Remitz is not ISO 27001 certified and does not currently commission third-party penetration testing. We state this openly rather than leave it to be discovered during due diligence. Control documentation is provided during enterprise evaluations so your team can assess the platform on evidence.
What happens to our data if we leave Remitz?
Data portability is included in the standard contract. Your transaction records, customer records and audit trail are exportable, and exit provisions are covered in the enterprise agreement. Your platform data belongs to you.

Send this to your reviewer

If your security or compliance team needs something this page does not cover, ask directly. A written answer is faster than a meeting and it is what your file needs anyway.

Book a 15-minute demo Enterprise deployment options
Get Started Today

Ready to Launch Your Remittance Business?

Book a demo and discover how Remitz can power your money transfer operations.