Session & Device Security
Authenticated sessions are required today. Production device binding, trusted-device history, remote revocation and stronger step-up controls remain gated.
NoopalMoney is being designed with financial controls, server-side authorization, balance privacy, separation of duties, device security, notification controls, audit, reconciliation and production gates built into the platform from the beginning.
Authenticated sessions are required today. Production device binding, trusted-device history, remote revocation and stronger step-up controls remain gated.
Hide/show balance is standard across Personal and Business wallets and changes only the display, never the authoritative ledger balance.
Production contracts now require multi-factor authentication and transaction step-up authentication before sensitive financial actions can be enabled.
Payroll and governed business payments use separation of duties and approval limits rather than single-user execution.
A durable double-entry ledger schema, immutable posted-entry rules and provider reconciliation model are implemented as foundations but are not yet connected to real funds.
Velocity controls, device changes, unusual activity, beneficiary risk, suspicious QR use and case management are required before production money movement.
Money received/sent, failed payments, approvals, payroll, settlement, verification and security-alert preferences are defined. Push, email and SMS delivery remain disabled in the pilot.
A payment cannot produce an official success receipt until the transaction is Completed with authoritative ledger evidence, verified provider acknowledgement and reconciliation.
Identity and business verification will use approved providers and documented review controls. Pilot onboarding never makes a verification decision.
Authentication events, financial approvals, provider actions and sensitive administrative changes are designed to produce append-only or immutable evidence.
Production recovery must use verified identity, device/session controls and an auditable support process rather than bypassing account security.
No real-money activation until partner, compliance, security, reconciliation, operational and executive release conditions are satisfied.