Security at TrillioniPay: what is certified, by whom, and what each one covers
Most payments companies publish a security page listing certification badges without saying which entity holds them. That is the first question a compliance officer reviewing a new provider asks, so this page answers it first and explains the rest afterwards.
Key takeaways
| Question | Short answer |
|---|---|
| Who holds the ISO 27001 certificate? | TrillioniPay's platform provider, SDK.finance, certified to ISO/IEC 27001:2022 on 21 August 2025 by DNV Business Assurance. |
| Who holds PCI DSS? | The same platform provider, at Level 1 under version 4.0.1, assessed by the QSA 7Security GmbH in late 2025. |
| Does TrillioniPay hold them? | No, and it does not claim to. The certifications belong to the platform provider and are attributed as such everywhere they appear. |
| Where is client money held? | In segregated accounts at Tier-1 banks, separate from TrillioniPay's own operating funds. |
| Is that deposit insurance? | No. Segregation is not deposit insurance, and TrillioniPay is not a bank. |
| What is TrillioniPay's own registration? | A money services business registered with FINTRAC in Canada under the PCMLTFA. |
Four parties, four different responsibilities
Security claims only mean something once you know which entity is making them. In a payment through TrillioniPay there are four parties, and each secures a different thing.
| Party | Role | What it is responsible for |
|---|---|---|
| Trillioni Pay Inc. | The customer-facing money services business, registered with FINTRAC in Canada | Onboarding decisions, sanctions screening, transaction monitoring, reporting, record keeping, customer data handling |
| The platform provider | Provides the core banking and payments software, white-labelled | The security of the software, its development lifecycle, its infrastructure controls and its certifications |
| The regulated financial partner | Issues the account details and executes payments in the European Union | Holding funds, executing transfers, and its own regulatory obligations under EU law |
| The safeguarding banks | Hold client funds in segregated accounts | Custody of the underlying cash |
A provider that blurs these four into one paragraph is hiding the answer to the question you are asking. The certifications below belong to the second party in that table.
The certifications, and who holds them
ISO/IEC 27001:2022
TrillioniPay's platform provider, SDK.finance, achieved ISO/IEC 27001:2022 certification on 21 August 2025, audited by DNV Business Assurance under UKAS accreditation. ISO 27001 is the international standard for an information security management system, and the 2022 revision organises controls into four domains: organisational, people, physical and technological. The certified scope covers the provider's software development processes and the safeguarding of financial data, including supplier management, encryption, incident response, vulnerability management and monitoring (SDK.finance, checked September 2026).
Read the announcement: SDK.finance achieves ISO 27001:2022 certification.
What the certificate means in practice: an accredited external body examined how the provider identifies, manages and reviews information security risk, and found the management system conformant. Certification is maintained through surveillance audits rather than granted once.
PCI DSS Level 1
The same platform provider holds PCI DSS Level 1 compliance under version 4.0.1, the most recent version of the standard. The assessment ran from 1 October to 2 December 2025 and was carried out by 7Security GmbH, an independent Qualified Security Assessor. All applicable requirements were assessed as either in place or not applicable, and the provider states that it does not store, process or transmit cardholder data. PCI DSS attestation is valid for one year and requires annual reassessment (SDK.finance, checked September 2026).
Read the announcement: SDK.finance PCI DSS compliance.
The scope covered secure software development, vulnerability and patch management, change management, information security governance, security training and background screening, internal audits and incident response.
The attribution rule
ISO/IEC 27001:2022 and PCI DSS Level 1 certifications are held by TrillioniPay's platform provider. TrillioniPay does not hold them and does not present them as its own. Wherever these certifications appear on this site, that attribution appears with them.
This matters more than it might seem. A certification held by the software provider tells you about the software you are using and about the discipline behind it. It tells you nothing about how the company operating that software makes onboarding decisions, screens payments or handles your documents. Those are separate questions, and they are answered in the next two sections.
Where client money sits
Client funds are held in segregated accounts at Tier-1 banks, separate from Trillioni Pay Inc.'s own operating funds. TrillioniPay does not lend client money, invest it or take positions with it.
Two limits belong in the same paragraph as that claim.
Segregation is not deposit insurance. Segregated client money is legally distinguishable from the company's own funds, which changes what happens to it if the company fails. It is not covered by the Canada Deposit Insurance Corporation, by a European deposit guarantee scheme, or by any equivalent, because TrillioniPay is not a bank and does not take deposits.
The banks are not named publicly. TrillioniPay does not publish the names of its safeguarding banks or its financial partners. If your own compliance process requires that detail before you can onboard a provider, ask during your review and it will be handled under the appropriate confidentiality terms.
What TrillioniPay is responsible for itself
The controls that sit with TrillioniPay rather than with a vendor are these.
Screening. Every customer and every beneficial owner is screened at onboarding and re-screened on a schedule set by risk rating, against the United Nations consolidated list, Canada's Global Affairs sanctions listings, the OFAC Specially Designated Nationals list, the European Union consolidated list and the United Kingdom's OFSI list.
Transaction monitoring. Payments are monitored on an ongoing basis against expected activity, with escalation to a designated compliance officer who reports to the Board.
Reporting and retention. Suspicious transaction reports, large cash transaction reports and electronic funds transfer reports are filed to FINTRAC as required, and records are retained for at least five years.
Independent review. The AML and counter-terrorist-financing programme is reviewed independently on an annual cycle.
Access control on the customer side. Two-factor authentication on accounts, and role-based permissions so that the person who creates a payment and the person who approves it can be different people.
The verification technology behind onboarding is described in the KYC and KYB article, including the platform used and its own independent attestation.
What none of this covers
Publishing the gaps is part of the point of this page.
A certification held today can lapse. PCI DSS attestation in particular is valid for one year and has to be re-earned annually, so a badge without a date is not evidence of anything. The dates above are the assessment dates, and this page carries a re-verification schedule.
No certification prevents a payment from being delayed by a correspondent bank's own compliance check. That is a third party acting under its own obligations, and no provider controls it.
No security programme protects a customer against their own compromised email. Invoice redirection fraud, where a supplier's email is compromised and new account details are sent to a buyer, is the most common way businesses lose money in cross-border trade, and it is defeated by calling a known number to confirm changed details rather than by anything a provider certifies.
Frequently asked questions
Is TrillioniPay a bank? No. Trillioni Pay Inc. is a money services business registered with FINTRAC in Canada. It does not take deposits and does not hold a banking licence in any jurisdiction.
Are my funds insured? No. Client funds are held in segregated accounts at Tier-1 banks, which is a different protection from deposit insurance. There is no deposit guarantee scheme covering the balance.
Can I see the ISO 27001 certificate? The certification and its scope are published by the platform provider and linked above. If your compliance review requires the certificate document itself or a current statement of applicability, ask during your review.
Does the ISO 27001 certificate cover TrillioniPay's own operations? No. Its scope is the platform provider's software development and the security of its systems. TrillioniPay's own obligations run through its Canadian AML compliance programme and its agreements with its partners.
Why will you not name your banking partners? Partner arrangements are commercially confidential and naming them is a decision that has not been taken. Where a counterparty's own due diligence requires the detail, it is provided under confidentiality rather than published.
How do I know a payment instruction from TrillioniPay is genuine? TrillioniPay will not change your account details by email and will not ask for your credentials. Any message that does either is not from TrillioniPay, and the correct response is to call the published contact number before acting.
Sources
- SDK.finance achieves ISO 27001:2022 certification, 21 August 2025, audited by DNV Business Assurance under UKAS accreditation. Checked September 2026.
- SDK.finance PCI DSS compliance, Level 1 under version 4.0.1, assessed 1 October to 2 December 2025 by 7Security GmbH. Checked September 2026.
- FINTRAC, money services business obligations under the PCMLTFA. Checked September 2026.
- TrillioniPay AML/CFT Policy v1.0, August 2026.
Related reading
- KYC and KYB explained: what a provider checks, why, and what happens to your documents
- Who we can serve, and who we cannot
- Who does what when your business moves money: the four parties in a cross-border payment
- Glossary: safeguarding, money services business, PCI DSS
- Pillar: Who we can serve, and why
Reviewing TrillioniPay as a provider? Talk to a payments specialist and bring your compliance questionnaire.
Trillioni Pay Inc. is a Canadian FINTRAC-registered money services business (C100000813). TrillioniPay is not a bank. Account and payment infrastructure is provided through regulated financial partners.
ISO/IEC 27001:2022 and PCI DSS Level 1 certifications are held by our platform provider.
This is general information as at September 2026. It is not legal or compliance advice. Certification status changes. Verify with the certifying bodies or your own adviser.