The short version
Remitz is software. Your firm holds the authorisation, the provider relationships and the customer funds. Our job is to give you a platform that withstands your regulator's scrutiny and your own security review — and to be straightforward about where its limits are.
This page exists so a technical or compliance reviewer can assess the platform without booking a call. If your due-diligence questionnaire needs something that is not here, ask and we will answer it in writing.
How the platform is built
The backend is a Java service built on Spring Boot, running against a relational database. The customer web portal and the branded mobile applications are built on Angular and Ionic, packaged with Capacitor so that iOS and Android builds are produced from one codebase rather than two.
Deployments are containerised, which is what makes a dedicated tenant or a fully separate deployment practical for enterprise customers rather than a bespoke engineering project.
We do not publish component version numbers. Version disclosure helps an attacker more than it helps a reviewer, and the information is available under NDA during an enterprise evaluation.
Where it runs, and where your data sits
- UK data residency by default. Processing is governed by UK GDPR and the Data Protection Act 2018.
- Managed infrastructure. Remitz applies security patches, runs monitoring and takes backups. Your team never maintains a server.
- Deployment options. Standard plans run on shared multi-tenant infrastructure. Enterprise customers can take a dedicated tenant (logically isolated) or a fully dedicated deployment where regulatory separation is required.
Security controls in operation today
This list is deliberately limited to what is actually running. Nothing aspirational appears here.
- Encryption in transit — TLS 1.3 across the platform
- Multi-factor authentication on administrative access
- JWT-based authentication with role-based permissions and segregation of duties between operations, compliance and finance
- Full audit trail of every transaction, customer interaction and compliance decision, retained for your regulatory retention period and exportable
- Independent uptime monitoring with a public status page hosted by a third party, which you can check at any time without asking us
What Remitz does not do
Every item below is a question that surfaces eventually. We would rather you had the answer now than during a procurement review.
- We never hold client money. Remitz does not hold, receive or control customer funds. No customer money sits with us, and none is at risk if we fail.
- We are not ISO 27001 certified and do not currently commission third-party penetration testing.
- We do not provide safeguarding reconciliation. The platform gives you the ledger, nostro-account balances reconciled against your payout partners, settlement records and an exportable audit trail — but there is no purpose-built safeguarding reconciliation module or automated attestation reporting. If your permission requires daily safeguarding reconciliation, that process sits with your finance function.
- We do not supply banking, payout, KYC, payment gateway or licensing services. You hold each of those relationships directly. See how the integrations work.
Supporting your regulatory obligations
Under FCA outsourcing and operational resilience expectations, your firm remains accountable for functions it outsources. Remitz provides what you need to evidence that oversight: access control documentation, backup and recovery arrangements, audit trail exports, and written exit provisions.
Where an obligation is yours rather than ours — safeguarding, transaction monitoring policy, customer due diligence standards — the platform is built to help you discharge it, not to take it on. That distinction matters to your regulator and it should matter in your vendor assessment.
Business continuity and exit
- Backups are taken as part of managed infrastructure, with recovery arrangements documented during enterprise onboarding.
- Data portability is included in the standard contract. Transaction records, customer records and the audit trail are exportable.
- Source-code licensing is available for operators who need ownership rather than a subscription — the honest answer to “what happens to us if Remitz stops trading”.
Frequently Asked Questions
Send this to your reviewer
If your security or compliance team needs something this page does not cover, ask directly. A written answer is faster than a meeting and it is what your file needs anyway.