Security & trust

We hold the truth about your money. That is a responsibility, not a footnote.

These controls are day-one, not 'when we're bigger'. A breach here would end the company - so trust is built into how RakamHQ works, by construction.

API keys only, never passwords

We accept provider API secret keys - never dashboard logins. Your credentials are held as an authorized data processor, the standard practice, and nothing else.

Encrypted at rest

Credentials are encrypted with per-org data keys. Plaintext exists only in-memory during a connector call - never logged, never echoed to the UI (last-4 only).

One-click revoke

Revoke any credential instantly. The connector goes amber, the ledger keeps serving your last-known truth, and we prompt you to reconnect - we never store 'for later'.

A transparent audit trail

Every credential use, refund action and export is logged in an append-only audit spine you can read yourself. Seeing everything RakamHQ did with your access is a feature.

We never hold your funds

RakamHQ is read-only on your world. We prove where money went; we never move or hold it. The only money-touching action is a gated, capped refund you confirm.

Your data is never sold

No selling or sharing of merchant data, ever - written into our terms from day one. Aggregate benchmarks only ever with your explicit opt-in.

The one unforgivable error is a wrong daily close. Every number traces to a source row, every close is versioned and audited, and if the math cannot prove something it becomes an exception - never a guess.

Get your free reconciliation.

Send us last month's eSewa report, Khalti export, bank statement and orders sheet. Within 48 hours we send back a one-page close - every payment matched, every fee computed, every settlement decomposed.

Files only · private upload link · nothing to install