Compliance & Security

Last updated: March 05, 2026

1. Regulatory Compliance

Billway Payment Services creates solutions that help businesses remain compliant with financial regulations. We partner with licensed financial institutions and payment service providers to ensure all transactions meet regulatory standards established by the Central Bank of Nigeria (CBN) and other relevant authorities.

2. KYC/KYB Requirements

To prevent financial crimes, we enforce strict Know Your Customer (KYC) and Know Your Business (KYB) protocols. All businesses using our platform must undergo verification, which may include submission of:

  • Certificate of Incorporation (CAC documents)
  • Directors' identification (NIN, BVN, Passport)
  • Proof of address
  • Tax Identification Number (TIN)

3. Anti-Money Laundering (AML)

We maintain a robust Anti-Money Laundering (AML) policy designed to prevent, detect, and report suspicious activities. Our systems monitor transactions in real-time to identify patterns indicative of money laundering or terrorist financing.

4. Data Protection

We are compliant with the Nigeria Data Protection Regulation (NDPR) and other applicable data privacy laws. We implement industry-standard security measures to protect user data from unauthorized access, alteration, disclosure, or destruction.

5. PCI DSS Compliance

As a connector platform, we ensure that card data handling meets the Payment Card Industry Data Security Standard (PCI DSS). We do not store sensitive cardholder data on our servers; instead, we utilize tokenization and secure payment gateways.

6. Audit & Reporting

We conduct regular internal and external audits to verify our compliance posture. We also maintain detailed transaction logs and provide reports to regulatory bodies as required by law.

7. Security Features

Encryption

All data in transit is encrypted using TLS 1.2+ protocols. Data at rest is secured using AES-256 encryption.

API Security

Our API uses HMAC signing, IP whitelisting, and rate limiting to prevent unauthorized access and abuse.