Security
What protects an account, what protects a card, and what we ask you to do. Written to be checked, not admired.
Account security
Two-factor authentication
Time-based one-time codes as a second factor on login and on sensitive actions, so a compromised password alone is not enough.
Biometric login
Fingerprint and face recognition on supported devices, backed by the device's own secure enclave rather than a stored biometric template.
Device management
A list of authorised devices with the ability to review and revoke any of them, so a lost phone stops being a live session.
Real-time alerts
Notifications on login from a new device, on card authorisations, and on account changes, so anomalies are visible immediately rather than at statement time.
Card security
Instant freeze
Suspend a card immediately from the app without reissuing it, and reinstate it just as fast when the card turns up in a coat pocket.
Spending controls
Per-card limits and merchant category restrictions applied at authorisation, so a card can only be used where you intend it to be used.
Tokenisation
Virtual cards are tokenisation-ready for mobile wallets, so the underlying card number is not exposed to the merchant.
Transaction monitoring
Rule-based screening and anomaly detection at authorisation, with alerting configured to the issuing institution's policy.
What we ask of you
Use a unique password that you do not use anywhere else, and enable two-factor authentication. Review your authorised devices periodically and revoke any you do not recognise. Treat any message asking for your password, one-time code or full card number as fraudulent, regardless of who it claims to be from.
Responsible disclosure
If you believe you have found a security vulnerability, report it to info@otaropay.com with enough detail to reproduce the issue. Please give us a reasonable window to investigate and remediate before disclosing publicly, and do not access, modify or exfiltrate data belonging to other users while testing.
We will acknowledge reports, keep you updated on remediation, and credit researchers who ask to be credited.
Security questions from a diligence team?
We will provide the control documentation, data-processing terms and responsibility matrix on request.
