Security
What actually protects your account.
Not a wall of badges. This page says how your password and your transfer PIN are stored, what you can switch off yourself and how quickly, what is written down about your sign-ins, and who to tell the moment something looks wrong. Where a fact belongs to this business rather than to the software it runs, our terms state it in full.
✓
Passwords hashed, never stored readably
✓
A transfer PIN nobody here can read back
✓
Freeze your card yourself, in about a second
How credentials are stored
Two secrets, and what becomes of them.
Both are put through a one-way function before they are written down, so what the database holds cannot be turned back into what you typed — by us, or by anyone who ever got hold of it.
Your password
Hashed before it is stored and never kept in a form anyone can read — including us. If you forget it we can only help you set a new one; nobody here can tell you the old one.
Your transfer PIN
You are asked for it every time you send money, and it is stored the same way. We cannot show you the old one, and neither can anybody else. Transfers are refused until you set one.
Getting back in
A password reset works by sending a link to the email address on your account, and that link stops working after an hour. Nobody reads your old password back to you, because nobody can.
No system is perfectly secure, so we also ask you to protect your own credentials — see the terms.
Read the terms→In your account
Four things you can do without asking us.
Every one of these takes effect when you press it. None of them needs a phone call, and none of them can be undone by anybody but you.
Freeze the card
Freeze it the second you cannot find it. It stops in about a second, nothing else about your account changes, and you can unfreeze it the moment it turns up in a coat pocket.
Change your password
From your account settings, using the password you have now. You will need the new one to sign back in, on this device and on every other.
Account settings→Check what a payment was
Every movement carries a reference, what it was, where it went and the balance it left behind. It is the quickest way to settle whether a payment you do not recognise is yours.
Your transactions→See what may leave your accounts
Two per-transfer limits apply — one for wire and crypto, one for bank and local transfers — alongside a switch that refuses every transfer before your PIN is even checked. Limits are set by us; ask if you need one raised.
Security settings→What is written down
The record kept about your account.
It is not there to profile you. It is kept so that unauthorised access can be detected and investigated, and so that we can answer you when you ask what happened and when.
Last sign-in
The time you last signed in
Password changes
The time your password was last changed
Email address
Whether it has been verified, and the tokens used to verify it or to reset a password
Two-factor
Whether it is switched on, and its recovery codes
Preferences
Your notification and communication settings
What you did here
The records created by what you do — transactions, requests and support messages
Signing in
The second factor on this account is your transfer PIN.
Your password gets you in to look. Moving money asks for a PIN that is separate from it, is never shown back to you, and is not stored anywhere it could be read — so somebody who has your password still cannot send a payment. Where a second sign-in factor is switched on for your account as well, the account screen shows it and says how to change it.
Your money
Held apart from ours.
Your money is held separately from the money that runs the business. It is not used to fund the company, and it does not sit in the same place as the money that pays its bills.
Authorisation
Who regulates this business.
This business is authorised and regulated by the authority named in our terms, and our terms carry its full name and the reference you can look us up under on its public register. If any page of this site ever names a different one, the terms are the document that governs.
Deposit protection
Which protection applies to your money.
Eligible deposits are covered by the applicable deposit-protection scheme, up to the limit that scheme sets per person. Which of your accounts are eligible, and the limit that applies to them, are set out in our terms and in the scheme's own published rules. Money held apart from ours, as described above, is not the same thing as protection — both matter, and this page says so rather than letting one stand in for the other.
Your part
Four things only you can do.
01
Use a password you use nowhere else.
It is hashed here and cannot be read back. But a password reused on a site that is breached is a password somebody already has, and no amount of care at this end changes that.
02
Keep your transfer PIN to yourself.
Nobody here can read it back — including us. So treat any message asking you to confirm it, from anyone, as a fake, however convincingly it is written.
03
Freeze first, ask second.
If a payment or a sign-in was not you, freeze the card before you write to us. Freezing takes about a second and you can undo it yourself; a conversation is neither of those things.
04
Read the receipt before you worry.
Most payments people do not recognise are simply named differently by the shop. The receipt says what it was, where it went and the balance it left behind.
If something is wrong
Tell us straight away.
A card gone, a payment you did not make, an email that does not look right — any of those, at any hour. Freeze the card yourself first if it is the card; it is faster than we are.
Chat
24/7
In the app, or the bubble on this page
Usually under a minute
Phone
24/7
+1 (512) 555-0192
Straight through, no menu
Mon–Fri
support@publicmonetra.live
Within one working day
If you are not satisfied with how we handle it, the complaints procedure sets out what happens next and by when.
Read the complaints procedure→Independent checks
Checked by people who do not work here.
Anyone can say their systems are secure. These are the three things that can be checked by somebody else — a certificate with a scope and a date, a test run by an outside party, and a way for a stranger to tell us we are wrong.
Certification
Certifications and audits.
Where this business holds a security certification, it is named here with its scope, the body that issued it and the date of the last audit, and the certificate itself is linked so you can read it rather than take our word for it. A certification covers what its scope says and nothing more, which is why the scope is published beside the name. We do not display a seal we cannot evidence.
Testing
Independent testing.
Where our systems are penetration-tested or reviewed by an outside party, we say who did it and how often, and what happened to what they found. “Regularly” is not an answer, so you will not find it here — a date and a name, or nothing at all.
Disclosure
Reporting a vulnerability.
If you have found a fault in this site, write to support@publicmonetra.live and mark it for the security team. We will confirm we have it and keep you told while it is being fixed, and we will not take action against anybody who reports a problem in good faith and gives us a reasonable chance to fix it before telling anyone else.
