Security & Trust

How Ultraner protects your money and your data.

Licensing & how funds are held

Today we operate through licensed local processing partners in each live market (AzamPay, Pesapal, MalipoPay, Stripe, PayPal), see how it works for the current roster. Funds move through those partners' own regulated rails; Ultraner does not custody funds outside of the wallet balances shown in your dashboard. Over time, our goal is to become the direct interoperability standard itself, the layer those partners and networks connect to, not just through.

Verification and access control, by design.

KYC verification required to go live

A live API key requires identity/business verification before it can process real money, a central-bank regulatory requirement in every live market, not just an Ultraner policy.

Domain-locked, scoped API keys

A live key only accepts requests from the domain(s) you authorize it for, and can be revoked instantly from your dashboard.

HMAC-signed webhooks

Every webhook event is signed, so you can verify it actually came from Ultraner before acting on it.

Checkable currency conversion

Every FX conversion gets its own public, checkable page at ultraner.com/fx/{transactionId}, not just a stated rate you have to trust.

Learn more →

Encrypted in transit

All API traffic runs over TLS. Sensitive account actions (like disbursements) require a separate backup PIN, not just a login session.

Role-based team access

A business can invite team members with a role that grants exactly the permissions they need, view-only, payouts, or full ownership, nothing more.

Learn more →

Found a security issue? Report it to support@ultraner.com and we'll respond directly, we don't yet run a public bug bounty program.

Questions before you go live?

UltranerUltraner · Hernatter Limited