Our commitment to regulatory compliance and security standards
Last updated: December 5, 2024
Sunny Payments Limited is committed to maintaining the highest standards of regulatory compliance and security. As a licensed Payment Service Provider, we adhere to all applicable laws, regulations, and industry standards to protect our customers, merchants, and partners.
Our compliance program is designed to ensure the integrity of our payment systems, protect against financial crimes, and safeguard sensitive data. We continuously invest in compliance infrastructure and work closely with regulators to maintain trust in our platform.
Licensed by the Central Bank of Kenya under the National Payment System Act, 2011 and National Payment System Regulations, 2014.
Certified compliant with Payment Card Industry Data Security Standard (PCI DSS) Version 4.0 - the highest level of certification.
Certified for Information Security Management System (ISMS) demonstrating our commitment to protecting information assets.
Audited for Security, Availability, and Confidentiality principles under AICPA SOC 2 framework.
EU General Data Protection Regulation compliance for European customers
Payment Card Industry Data Security Standard for card data protection
Financial Action Task Force AML/CFT guidelines
Business Continuity Management System standards
Our comprehensive AML program is designed to detect, prevent, and report money laundering and terrorist financing activities:
Robust identity verification including document verification, biometric checks, and ongoing customer due diligence.
Real-time monitoring systems to detect suspicious transaction patterns and unusual activity across all payment channels.
Automated screening against global sanctions lists including UN, OFAC, EU, and Kenya-specific sanctions.
Timely filing of Suspicious Transaction Reports (STRs) to the Financial Reporting Centre (FRC) as required by law.
AES-256 encryption for data at rest, TLS 1.3 for data in transit
Card numbers replaced with secure tokens to minimize data exposure
Hardware Security Modules (HSM) for cryptographic key protection
Role-based access with multi-factor authentication
Web Application Firewall (WAF), DDoS protection, intrusion detection
Comprehensive logging of all access and transactions
We maintain a comprehensive incident response plan to handle security incidents and data breaches:
We maintain strict oversight of third-party vendors and service providers:
If you suspect any violation of our compliance policies or applicable laws, please report it through our confidential reporting channel:
All reports are handled confidentially. We prohibit retaliation against anyone who reports concerns in good faith.
For compliance-related inquiries or to request compliance documentation:
Chief Compliance Officer: Sunny Payments Limited
Email: compliance@sunnypay.com
Address: Westlands, Nairobi, Kenya