On this page
FRAUD & SECURITY POLICY
This Fraud & Security Policy explains how KereX Technologies L.L.C-FZ (“KereX”, “we”, “us” or “our”) protects its website, platform, APIs and technical integrations, identifies suspicious activity and responds to fraud and security incidents.
It also explains how clients, partners and authorised users should protect their access and report suspicious activity.
KereX is a technology provider. Regulated payment, banking, safeguarding and settlement services are provided by the relevant authorised financial institutions and service partners.
1. Purpose and Scope
This Policy applies to:
• the KereX website;
• KereX dashboards, portals and APIs;
• sandbox and production environments;
• technical integrations and routing infrastructure;
• transaction instructions and metadata processed through supported integrations;
• clients and their authorised users;
• prospective clients and business partners; and
• technology, banking and payment service partners supporting connected routes.
This Policy should be read together with the KereX Terms of Use, Privacy Policy and any applicable services agreement, order form or service schedule.
No security system can prevent every fraud attempt, unauthorised action or cyber incident. KereX applies risk-based controls but does not guarantee that every incident will be prevented.
2. Security and Fraud Prevention Framework
KereX maintains a risk-based security and fraud-prevention framework designed to protect the platform, clients, integrations, transaction information and KereX operations.
Controls may include:
• business and identity verification;
• sanctions and watchlist screening;
• user access and authorisation controls;
• transaction and API activity monitoring;
• fraud-risk indicators;
• value and velocity checks;
• device, network and session analysis;
• beneficiary and payment-detail verification;
• manual compliance or fraud review;
• system and security logging;
• vulnerability and patch management;
• incident response procedures;
• service-provider oversight; and
• record retention.
The controls applied may vary depending on:
• the client’s risk profile;
• transaction type and value;
• currency and jurisdiction;
• payment route;
• device and access information;
• transaction history;
• beneficiary information;
• service-partner requirements; and
• applicable legal or regulatory obligations.
KereX does not publicly disclose internal detection rules, security configurations, review thresholds or investigation methods where disclosure could weaken their effectiveness.
3. Business Verification and Access Controls
During onboarding and periodic review, KereX or a relevant service partner may verify:
• the client’s legal existence;
• licences and registrations;
• shareholders and ultimate beneficial owners;
• directors and authorised representatives;
• business activity and operating model;
• source of funds and expected transaction activity;
• websites, applications and customer channels; and
• documents supporting specific transactions or routes.
Enhanced due diligence or additional verification may be required for higher-risk clients, activities, jurisdictions, routes or transactions.
Verification may be repeated where:
• client information changes;
• ownership or control changes;
• unusual activity is identified;
• a service partner requests additional information;
• documents expire;
• credentials may have been compromised; or
• periodic review is required.
Access controls may include:
• individual user accounts;
• passwords and authentication credentials;
• multi-factor authentication where supported;
• role-based permissions;
• approval levels;
• session controls;
• access logging; and
• restrictions on sensitive administrative actions.
Clients must provide access only to properly authorised personnel and must promptly remove or update access when a user changes role or leaves the organisation.
4. Monitoring and Protective Measures
KereX and relevant service partners may monitor platform access, API activity, transaction instructions and related metadata to identify possible fraud, abuse, unauthorised access, sanctions exposure or activity inconsistent with the approved business profile.
Monitoring may consider:
• unusual transaction values or frequency;
• rapid movement of funds through connected routes;
• repeated failed requests or authentication attempts;
• unusual beneficiary changes;
• new or higher-risk counterparties;
• unusual device, IP address or location information;
• access from unexpected jurisdictions;
• activity inconsistent with previous behaviour;
• duplicated or altered payment information;
• unusual refund or reversal patterns;
• attempts to avoid limits or controls; and
• information received from service partners or authorities.
Where a concern is identified, KereX or a relevant service partner may:
• request additional verification;
• request invoices, agreements or supporting records;
• delay or reject a technical instruction;
• restrict a route or payment method;
• apply or recommend transaction limits;
• require additional approval;
• temporarily restrict platform access;
• pause processing or forwarding of an instruction;
• notify or consult a service partner;
• preserve relevant records; or
• take another action permitted under the applicable agreement and law.
A delay, review or restriction does not by itself confirm that fraud or unlawful conduct has occurred.
5. Platform and Service Partner Security
KereX applies reasonable technical and organisational measures appropriate to the nature of its platform and the information processed.
Measures may include:
• encrypted transmission of information;
• authentication and access controls;
• role-based permissions;
• system and security logging;
• network and application protection;
• monitoring for malicious or automated activity;
• vulnerability management;
• software updates and security patching;
• secure development practices;
• backup and recovery procedures;
• incident response procedures;
• vendor and service-partner reviews; and
• staff confidentiality requirements.
KereX may use cloud, communications, cybersecurity, identity-verification, compliance and infrastructure providers to deliver and protect its technology services.
Banks, payment institutions, PSPs and other service partners remain independently responsible for the security of the systems and regulated services they separately provide.
KereX may exchange relevant fraud and security information with service partners where reasonably required to:
• provide an approved integration;
• investigate suspicious activity;
• protect systems and users;
• prevent fraud;
• comply with legal obligations; or
• respond to a competent authority.
6. Common Fraud and Cyber Threats
Phishing
Fraudulent emails, websites, messages or calls may imitate KereX, a bank, a client, a supplier or another legitimate organisation to obtain credentials or confidential information.
Social Engineering
Fraudsters may create urgency, impersonate managers, employees, regulators, banks or technical support and pressure a person to disclose information or approve an instruction.
Business Email Compromise
A fraudster may access or imitate a company email account and request changes to beneficiary, invoice or settlement details.
Invoice and Beneficiary Fraud
Fraudsters may submit false invoices or replace legitimate payment details with accounts or wallets under their control.
Account Takeover
Unauthorised persons may attempt to access an account using stolen passwords, compromised email accounts, malware, credential reuse, SIM swapping or manipulated authentication.
Malware and Remote-Access Fraud
A person may be persuaded to install software, share a screen or allow remote access to a device used for business or financial activity.
Impersonation and Fake Support
Fraudsters may falsely claim to represent KereX, a service partner, a bank, a regulator or a law-enforcement authority.
Authorised Transfer Fraud
An authorised user may be deceived into approving a transaction or instruction to a fraudster even though the request technically came from an authorised account.
KereX will never ask a user to:
• disclose a password or complete authentication code;
• share a private cryptographic key;
• provide full payment-card credentials by email;
• install unknown remote-access software;
• transfer funds to a “safe” account; or
• approve a transaction solely to protect an account.
7. Client Security Responsibilities
Clients and authorised users must:
• use strong and unique passwords;
• enable multi-factor authentication where available;
• protect business email accounts and devices;
• keep operating systems and software updated;
• restrict platform access to authorised personnel;
• review access permissions regularly;
• protect API keys, tokens and other credentials;
• verify beneficiary and settlement details independently;
• review transaction and account activity;
• use secure networks for sensitive activity;
• avoid links and attachments from unexpected messages;
• confirm unusual requests through a separate trusted channel; and
• report suspected compromise without delay.
Passwords, authentication codes, API keys and other personal credentials must not be shared between users.
Clients must maintain appropriate internal:
• cybersecurity controls;
• fraud-prevention procedures;
• employee-access controls;
• transaction approval processes;
• incident-response procedures;
• customer and supplier verification procedures; and
• records supporting payment instructions.
Before approving an unusual or urgent transaction, the authorised user should independently verify:
• the identity of the requester;
• the beneficiary’s legal name;
• account or wallet details;
• the commercial purpose;
• the supporting invoice or agreement; and
• any recent change to payment instructions.
8. Reporting Suspicious Activity
Suspicious activity should be reported immediately where a client or authorised user identifies:
• an unauthorised transaction or instruction;
• an unknown login or access attempt;
• an unexpected password or security change;
• an unapproved user or permission;
• altered beneficiary or settlement information;
• a suspicious message claiming to be from KereX;
• a request for passwords or authentication codes;
• possible phishing, malware or remote access;
• loss or compromise of a device, API key or credential; or
• another unusual or concerning activity.
Email: legal@kerex.io
Recommended subject line: URGENT - Security or Fraud Report
The report should include:
• the client’s legal name;
• the authorised user’s name and business email;
• a description of the suspicious activity;
• the date and approximate time;
• the relevant transaction or reference number;
• affected user accounts, credentials or systems;
• screenshots or supporting records where available; and
• actions already taken.
Do not include passwords, authentication codes, full card details, private cryptographic keys or unnecessary identity documents in the email.
Where access may have been compromised, the client may request temporary restriction of platform access or processing.
KereX may require identity and authority verification before acting on an access-restriction or restoration request.
9. Incident Management and Cooperation
KereX maintains procedures for assessing and responding to reported fraud and security incidents.
Depending on the circumstances, KereX may:
• acknowledge and record the report;
• request additional information;
• restrict relevant access or activity;
• revoke or rotate affected credentials;
• preserve logs and supporting records;
• investigate affected transactions, instructions or systems;
• coordinate with infrastructure providers and service partners;
• contain or reduce the impact of an incident;
• restore access after appropriate verification;
• implement corrective or preventive measures;
• notify affected persons where required;
• report the matter to a competent authority; or
• cooperate with law-enforcement or regulatory investigations.
KereX may preserve information and evidence relating to suspected fraud, cybercrime, unauthorised activity or security incidents for legal, compliance, security and investigative purposes.
KereX may be unable to disclose:
• confidential detection rules;
• security configurations;
• information about another client;
• details of a suspicious activity report;
• information subject to legal restrictions; or
• information that could compromise an investigation.
Where a personal-data breach may affect the privacy, confidentiality or security of individuals, KereX will assess the incident and take the notification and response steps required by applicable data-protection law.
10. Liability, Updates and Contact
Security controls reduce risk but cannot eliminate every possibility of fraud, social engineering, unauthorised access, malware, system failure or cyberattack.
Clients remain responsible for:
• protecting their own systems and devices;
• safeguarding passwords, API keys and credentials;
• managing authorised users;
• verifying payment and beneficiary instructions;
• monitoring their activity;
• maintaining appropriate internal controls; and
• reporting suspicious activity promptly.
KereX is not responsible for funds held, safeguarded or settled by an independent bank, payment institution, PSP or other service partner.
Responsibility for unauthorised, fraudulent or disputed transactions is determined by the applicable agreement, the relevant service partner’s terms and applicable law.
KereX may update this Policy to reflect changes in:
• security practices;
• fraud and cyber threats;
• platform functionality;
• service providers;
• legal or regulatory requirements; or
• business operations.
The current version and last updated date will be displayed on this page.
Contact:
legal@kerex.io
KereX Technologies L.L.C-FZ
Meydan Free Zone
Dubai, United Arab Emirates
Important reminder
KereX will never ask you to disclose your password or authentication code, transfer funds to a “safe” account, share a private cryptographic key or install unknown remote-access software.