RemitBot.ai

Security

Controls, data handling, and compliance status. Only what is true.

RemitBot is designed as a control layer for agent payments. It is not a bank and it does not hold client funds.

Approvals

Designed so a payment does not settle until the policy disposition is Approve.

Limits and intent

Spending limits and intent checks are designed to run before release.

Dual control

A second approver can be required on the path for payments that exceed policy.

Audit trail

Designed to retain who requested, what was checked, the disposition, and the rail used.

Production data handling — retention, residency, and subprocessors — is scoped in the enterprise agreement. [PENDING] A public data-processing summary is not published on this site yet.

[PENDING] Specific encryption standards and key-management details are provided in the security package, not claimed here.

Designed for named enterprise roles (payments, risk, security, engineering) with separation between request and approval. [PENDING] SSO and SCIM details are confirmed per deployment.

Funds custody

Confirmed

RemitBot does not hold client funds. It is a control layer in front of your rails.

SOC 2

Internal readiness

Internal readiness program. A SOC 2 report is not completed — not claimed as certified.

ISO 27001

Not certified

[PENDING] No ISO 27001 certification is claimed.

Penetration test

By request

[PENDING] A current pen-test summary is not published here. Qualified teams may request the security package under NDA.

Request security package (under NDA)