NOMO Pay security
NOMO Pay holds no customer funds. Balances sit with a regulated banking partner, and NOMO Pay moves them only on an instruction you have signed from your own wallet. This page describes where the money is, how identity is checked, and what approval each action needs.
Where the money is held
Your balances are held by the licensed banking partner that issues the account, not by NOMO Pay, and not by the NOMO wallet. Basic accounts are issued in Singapore, where payment services are licensed under the Payment Services Act published by the Monetary Authority of Singapore; Premium accounts are issued in the EU and carry an EUR IBAN. NOMO Pay stores a mirror of your balances and transactions so the app can render them, and treats the partner's record as authoritative whenever the two differ.
Signing in and approving actions
There is no NOMO Pay password. You sign in by scanning a QR code with the NOMO wallet, which signs a one-time challenge with the key held on your device, as documented for the Nomo App. Sensitive actions ask for biometric approval in the wallet, and email verification is required before an account can transact. A signature covers one action and one set of parameters, so a captured request cannot be replayed as a different payment.
Identity verification
According to the limit schedule the banking partner applies, a Basic account opens after a short in-app check that collects name, date of birth and country, and carries a cap of US$1,000 equivalent per transaction until identity is verified. Full verification runs through Zenpass, a document-and-selfie check, and removes that in-app cap. Verification records are written as append-only snapshots, so a later change adds a row rather than overwriting the identity you were verified against.
Documents and uploads
Documents attached to a transaction are virus-scanned before they are stored, and the file type is re-checked against the file's actual contents rather than trusting the name it arrived with. According to the same upload policy, uploads are capped at 5 MB. Upload is gated behind a per-account permission and is requested only for transactions where the banking partner asks for supporting evidence.
Sanctions and compliance screening
Every payment passes the banking partner's compliance, anti-money-laundering and risk checks, which can restrict, delay or decline it regardless of account type or membership. NOMO Pay does not serve residents of comprehensively sanctioned countries, or persons named on applicable sanctions lists, including those published by the U.S. Department of the Treasury as Sanctions Programs and Country Information. The supported-country list is set by the banking partner and changes with those programmes.
What NOMO Pay can see
NOMO Pay reads the balances, transactions and beneficiaries the banking partner returns for your customer record, and refreshes them every 60 seconds. It never receives your wallet's private key, which stays on your device. Identity documents go to the verification provider through the banking partner, and NOMO Pay stores the resulting verification status rather than the documents.
Sources
- Payment Services Act, Monetary Authority of Singapore.
- Sanctions Programs and Country Information, U.S. Department of the Treasury, Office of Foreign Assets Control.
- Nomo App, Nomo Digital FlexCo.
Last updated
