
Dubai
OperationalUnited Arab Emirates · GCC headquarters
Treasury and GCC operations, alongside compliance and FX routing.
DIFC Gate Building · Level 14
Sun–Thu · 09:00–18:00 GST
Every payment, card, wallet and settlement runs through licensed entities, partner banks and national payment systems — screened in real time, scored continuously, and safeguarded at regulated credit institutions the whole way through.
3 markets
Each served by its own registered entity, named in your account agreement.
Licenses · Group entitiesSegregated
Customer funds at regulated credit institutions, reconciled every business day.
Licenses · SafeguardingRTO 4 hours
Maximum time to restore service, against a 15-minute recovery point.
Security · InfrastructureGlobal infrastructure
Money moves between the markets the group is licensed in, over partner banks and national payment systems. A market cannot appear here unless an entity backs it.
EgyptUnited Arab EmiratesUnited KingdomRiyadhPlannedSettlement network
Issuing, settlement and safeguarding each sit with a licensed institution. Knowing which one, and on what terms, is the point of this section.
Licensed issuing partners
Cards are issued by licensed issuing partners under scheme licences. Card transactions are subject to network rules, merchant authorisation holds and the daily limits shown in your card settings.
Partner banks and national payment systems
Settlement is executed through partner banks and national payment systems. Partner names appear in your product terms.
Destination network and cut-off times
Settlement times depend on the destination network, the receiving institution and applicable cut-off times. Expected timings are published in the application before you confirm.
Regulated credit institutions
Customer funds sit in segregated safeguarding accounts at regulated credit institutions, reconciled every business day and held separately from BINK’s own money.
Assessed before onboarding, reviewed annually
Every partner and processor is assessed before onboarding and reviewed annually, covering regulatory standing, security posture, resilience and data protection.
Read from Licenses & Regulation v3.0 and the Terms v2.4. Partner names appear in your product terms, not on a marketing page.
How money travels
Controls are easier to trust when you can see where each one sits. This is one payment, end to end, with the clause behind every leg.
You instruct a payment in the application. Fees are shown before you confirm, and expected timings are published at the same point.
Terms · Payments, FeesA payment instruction is treated as authorised once you have completed the required authentication — passkeys and hardware security keys on every account, with one-time codes for step-up verification. Authorised instructions are generally irrevocable; scheduled payments may be cancelled before execution begins.
Terms · Payments · Security · 2Customers, counterparties and payments are screened against applicable sanctions lists in real time. Matches are held for review, and confirmed matches are reported and blocked.
Compliance · 4Sessions, devices and payments are scored continuously. Unusual patterns trigger step-up verification, a temporary hold, or review by our fraud team, and alerts are investigated by trained analysts.
Security · 5 · Compliance · 5The instruction is routed to the destination network. Which network, and the cut-off times that apply to it, determine when it can settle.
Terms · PaymentsExecution runs through partner banks and national payment systems, under the scheme licences those partners hold. Throughout, your balance remains safeguarded at a regulated credit institution rather than on our balance sheet.
Licenses · 3, 4The receiving institution credits the beneficiary and the payment is confirmed in the application. If funds are credited in error, we may reverse the entry and will tell you why.
Terms · Payments“In the event of insolvency, safeguarded funds are distributed to customers ahead of general creditors.”
Licenses & Regulation · Safeguarding · v3.0
Operational health
4 hours
Recovery time objective
The maximum time to restore service after a failure, stated in the Security policy. Paired with a 15-minute recovery point objective — the largest window of data a failure can cost.
Recovery point objective — the maximum data-loss window.
Security · 4Traffic encrypted in transit, between your device and the platform.
Security · 3Data encrypted at rest, keys held in hardware modules under split control.
Security · 3Backups encrypted and restored on a schedule, not assumed.
Security · 4Independent penetration testing of the platform and its APIs.
Compliance · 2Sessions, devices and payments scored for anomalies.
Security · 5Detection and triage, at all times.
Security · 6Vulnerability reports acknowledged.
Security · 7Regional coverage
BINK is a group of companies. The entity you contract with depends on your country of residence and the product you use, and it is named in your account agreement.
BINK PAY
BINKPAY FINANCING BROKER L.L.C
BINK PAY LTD

United Arab Emirates · GCC headquarters
Treasury and GCC operations, alongside compliance and FX routing.
DIFC Gate Building · Level 14
Sun–Thu · 09:00–18:00 GST

United Kingdom · European operations
International banking and partnerships, reporting and the FX engine.
71–75 Shelton Street · Covent Garden · WC2H 9JQ
Mon–Fri · 09:00–18:00 GMT

Arab Republic of Egypt · Engineering
Engineering, customer operations and compliance teams.
Smart Village · B127
Sun–Thu · 09:00–18:00 EET

Kingdom of Saudi Arabia · Strategic expansion
Planned expansion. BINK holds no licensed entity in Saudi Arabia and offers no product under one.
Announced ahead of opening
Not yet operational
An office is not a licence. The licensed markets are the three above, read from Licenses & Regulation; the regulatory registers remain the authoritative source, and permission changes are published there within ten business days.
Infrastructure principles
Principle 01
Controls are layered across identity, application, network and data, and no single control is relied upon. A control that cannot fail is a control nobody has tested; these are arranged so the failure of any one is contained by the others.
Security · 1 Security modelPrinciple 02
Production runs in isolated environments with least-privilege access. Access to production data requires approval and is time-bound, so a credential that leaks is a credential that has already expired.
Security · 4 InfrastructurePrinciple 03
Every privileged action is logged and reviewed. Observability here is not dashboards for their own sake — it is the record that makes an incident reconstructable afterwards.
Security · 1, 4Principle 04
A running version is replaced, never edited in place, and every change carries mandatory peer review and automated checks before it ships. Rollback is therefore a deploy, not a repair.
Security · 4 InfrastructurePrinciple 05
Detection and triage are on call at all times, affected sessions or accounts are isolated before anything else happens, and affected customers and regulators are notified within required timeframes. A post-incident review is published in summary where material.
Security · 6 Incident responsePrinciple 06
Backups are encrypted and tested quarterly against a stated recovery point of 15 minutes and recovery time of 4 hours. A resilience claim without a figure attached to it is not a claim.
Security · 4 InfrastructureReliability
Every figure below is either a commitment in the Security policy or the scope of an assessment an independent auditor signs.
RPO 15m
Recovery point objective
The maximum window of data a failure can cost, with encrypted backups tested quarterly against it.
Security policy · 4RTO 4h
Recovery time objective
The maximum time to restore service. Stated in the policy rather than estimated for this page.
Security policy · 4SOC 2 Type II
Security and availability, assessed annually
Availability is in the scope of an independent annual attestation. That is the assurance BINK actually holds — this page does not print an uptime percentage no document supports.
Compliance policy · 2Twice yearly
Independent testing of platform and APIs
Penetration testing on a published cycle, on top of the annual assessments each certification carries.
Compliance policy · 2Questions
To the destination network for the instruction, through partner banks and national payment systems. Which network applies, and its cut-off times, determine when the payment can settle — expected timings are published in the application before you confirm.
Detection and triage are on call at all times. Affected sessions or accounts are isolated first, then affected customers and regulators are notified within required timeframes, and a post-incident review is published in summary where the incident was material.
Through stated recovery objectives rather than adjectives: a recovery point objective of 15 minutes and a recovery time objective of 4 hours, with encrypted backups tested quarterly against them. BINK does not publish a region topology or a failover mechanism, and this page does not describe one.
No. No approved policy states one, so this page does not print one. What is attested is that security and availability are in the scope of an annual SOC 2 Type II assessment by an independent auditor, and attestation reports are available to business customers under NDA.
Sessions, devices and payments are scored continuously, and customers, counterparties and payments are screened against applicable sanctions lists in real time. Alerts are investigated by trained analysts, and suspicious activity is reported to the relevant financial intelligence unit.
In segregated safeguarding accounts at regulated credit institutions, reconciled every business day and held separately from BINK’s own money. In the event of insolvency, safeguarded funds are distributed to customers ahead of general creditors.
Only the markets where the group holds a licensed entity — the three listed on this page. This section is generated from the licensing table, so it cannot list a market that is not in it. Riyadh appears as a planned office, not a market.
The regulatory registers. Entity names, reference numbers and any changes to permissions are published within ten business days; the registers are authoritative, not this page.
The layered controls behind identity, application, network and data.
Trust ComplianceCertifications, financial-crime controls and independent oversight.
Trust Help CenterSearch an answer, or reach the team that owns your question.
Support Licenses & RegulationEntities, permissions, safeguarding and partner arrangements.
v3.0 Security policyArchitecture, encryption, monitoring and recovery objectives.
v2.2 Privacy PolicyWhat we collect, why, and the rights you can exercise.
LegalOur compliance team answers diligence questionnaires and provides attestation reports to business customers under NDA.
Licensing v3.0 · Security v2.2 · Compliance v2.0 · Terms v2.4