Double-entry accounting
Every movement is recorded in an internal ledger that is permanently balanced and reconciled daily.
ChariPay is built like a financial system: every dirham is accounted for in double entry, every sensitive action is controlled, every access is traced.
Every movement is recorded in an internal ledger that is permanently balanced and reconciled daily.
Sensitive actions — payouts, adjustments, account freezes — require a distinct requester and approver.
The audit log is cryptographically chained: history cannot be rewritten.
Two-factor authentication, re-authentication before every sensitive action, secured sessions.
Card numbers are never written to the database, and card payments rely on 3-D Secure.
The platform is monitored around the clock, with automatic alerts on any financial anomaly.
Replaying a call after a network cut returns the existing operation: never a double debit, never a double refund.
One-time code validation on portal transfers — as soon as you enable it —, a 24-hour security hold on any new beneficiary, and separate roles for viewing and acting.
Every webhook is HMAC-signed and timestamped, with an anti-replay window and mandatory HTTPS: your server knows it is us.
Every business is verified before collecting in production: identity documents and trade register, with dual human review. ChariPay is a Chari Money solution — a payment institution licensed by Bank Al-Maghrib — and the platform is PCI DSS Level 1 certified, renewed every year. Personal data processing falls under law 09-08. The money you collect is credited to a payment account held by Chari Money, with a RIB in your company's name.
Every payment leaves a trace: reconciliation gaps, risk alerts, failed webhooks and pending compliance cases are tracked continuously.

Our team will address your compliance and security requirements.