The short version
Remitz is software. Your firm holds the authorisation, the provider relationships and the customer funds. Our role is to supply the technology; your reviewers assess whether the proposed deployment meets your requirements.
Use this page to scope a technical review. Request deployment-specific evidence and written answers to your due-diligence questionnaire before approval.
How the platform is built
Remitz provides customer-facing web, back-office and mobile capability according to the implementation. Request the architecture and data-flow documentation for your proposed deployment, including its software stack and dependencies. Marketing descriptions alone are not technical acceptance evidence.
Where it runs, and where your data sits
Hosting and data-processing locations are agreed for your deployment. Confirm primary storage, backups, subprocessors and support access as part of due diligence. Enterprise infrastructure and isolation requirements are scoped in the agreement.
Security controls to verify
Security requirements are assessed for the proposed deployment. Ask for evidence of encryption, administrative MFA, role permissions, audit coverage and retention, data locations, monitoring and recovery tests. Confirm supported controls and service levels in writing rather than assuming every deployment has the same configuration.
- Encryption in transit and at rest, with evidence for relevant endpoints and storage.
- Administrative MFA, role permissions and separation of operational responsibilities.
- Audit events, export formats and retention settings matched to your requirements.
- Backup scope, restore tests, recovery objectives and incident escalation.
- Monitoring coverage. A public status page is not proof of every product component or an uptime commitment.
What Remitz does not do
Every item below is a question that surfaces eventually. We would rather you had the answer now than during a procurement review.
- We do not hold customer funds. Your provider and safeguarding arrangements remain your responsibility. Software failure can still disrupt operations.
- No ISO 27001 certification is claimed here. Request current assessment evidence and confirm any gaps.
- We do not provide safeguarding reconciliation. Do not assume a ledger or a provider balance is a safeguarding reconciliation service. Confirm available records, reports and exports during product validation. Your finance and compliance teams remain responsible for safeguarding requirements.
- We do not supply banking, payout, KYC, payment gateway or licensing services. You hold each of those relationships directly. See how the integrations work.
Supporting your regulatory obligations
Your firm remains responsible for its regulatory obligations and oversight of providers. Request access-control evidence, backup and recovery arrangements, sample audit exports and written exit provisions for your assessment.
Where an obligation is yours rather than ours — safeguarding, transaction monitoring policy, customer due diligence standards — the platform is built to help you discharge it, not to take it on. That distinction matters to your regulator and it should matter in your vendor assessment.
Business continuity and exit
- Backups and recovery: agree scope, frequency, restore testing and responsibilities for your deployment.
- Data portability: agree records, formats, retention, timing and any exit-assistance fees in writing.
- Source-code and self-hosting requests: subject to feasibility, licensing and a separate written agreement; ownership is not implied by a software licence.
Frequently Asked Questions
Send this to your reviewer
If your security or compliance team needs something this page does not cover, ask directly. A written answer is faster than a meeting and it is what your file needs anyway.