Company · regulation and security
Who governs your payments, and what to check
Payments in India run on rails operated and supervised by regulators, through banks and providers they license. This page explains that structure, where Peneu sits in it, and what evidence to ask for before trusting any payments partner with your money and data.
Who regulates what
Several bodies shape how money moves. For a business, the practical point is that the entity holding and moving your money is licensed or authorised by one of them, and has obligations you benefit from.
| Body | Role in payments | Examples |
|---|---|---|
| Reserve Bank of India | Regulates banks and payment systems; authorises payment aggregators and prepaid instrument issuers | Payment aggregator, PPI, card, digital lending and authentication directions |
| NPCI | Operates retail payment systems under RBI's oversight | UPI, IMPS, NACH, BBPS, NETC |
| Sector regulators | Regulate their own industries' use of payments | IRDAI for insurance, SEBI for securities |
| Government | Laws on data, tax, and specific sectors | Digital Personal Data Protection Act, 2023; Online Gaming Act, 2025 |
Where Peneu sits
Peneu is a payment orchestration platform: a layer in front of payment providers that routes payments and brings their results together. Regulated services are delivered through licensed partner banks and institutions. Details of Peneu's security controls, audits and certifications are shared during partner and merchant due diligence.
This site doesn't claim any licence or authorisation for Peneu itself. The guides describe which kind of regulated entity provides each product, so you know who is responsible for what.
Security principles
These are the principles Peneu applies to its platform. Evidence (how each is implemented, and any audits or certifications) is shared during due diligence, not asserted here.
- Encryption of data in transit and at rest
- Role-based access and multi-factor authentication for dashboard users
- Least-privilege access to production systems and credentials
- Audit trails for configuration, credential and payout changes
- API keys and secrets issued per environment and never exposed client-side
- Continuous monitoring of provider health and transaction anomalies
Payment data and personal data
RBI's circular on storage of payment system data (6 April 2018) requires payment system providers to store the entire data relating to the payment systems they operate in a system only in India, including full end-to-end transaction details; for the foreign leg of a transaction, the data can also be stored abroad.
Personal data in payments (names, phone numbers, account details) is also governed by the Digital Personal Data Protection Act, 2023. How these apply to your own business is a question for your adviser.
| Question | Why |
|---|---|
| Where is payment data stored and processed? | Storage rules for payment system data |
| Who can access our data, and how is access logged? | Your customers' data is your responsibility too |
| How long is data kept, and how is it deleted? | Retention obligations and data protection |
| How are incidents reported to us? | You may have your own notification duties |
A due-diligence checklist for any payments partner
Use this with any provider, including Peneu. Ask for evidence, not assurances.
Authorisation
Which regulated entity provides each service, and its authorisation, checkable on the regulator's own list.
Fund flow
Where your customers' money sits at every step, and who it's owed to.
Security evidence
Audit reports or certifications, current and in scope for the service you'll use.
Data handling
Storage location, access controls, retention and incident reporting.
Continuity
What happens in an outage, and how you're told.
Exit
How you'd move away, and what happens to data and funds if you do.
Regulation and security questions
Is Peneu regulated by RBI?
This page doesn't claim any licence or authorisation for Peneu. Regulated payment services (collecting and settling money, issuing instruments, lending) are provided by licensed banks and authorised payment providers. Which ones, and how responsibilities are split, is set out during onboarding.
Does Peneu have security certifications?
No certification is claimed on this site. Details of Peneu's security controls, audits and any certifications are shared during partner and merchant due diligence, where you can check the evidence yourself.
Where is payment data stored?
RBI requires payment system providers to store the entire data relating to the payment systems they operate in a system only in India, with the foreign leg of a transaction allowed to be stored abroad as well. Ask any provider how it complies.
Which data protection law applies?
India's Digital Personal Data Protection Act, 2023 governs personal data, alongside sector rules from regulators such as RBI. How they apply to your business is a question for your adviser.
How do I report a security issue?
Through the contact form, marked as a security issue, with enough detail to reproduce it. Please don't include personal or payment data belonging to anyone else.
Official sources
- RBI — Storage of Payment System Data (6 Apr 2018)Entire payment-system data to be stored in a system only in India; foreign leg may also be stored abroad.
Last reviewed . Examples, amounts and screens marked illustrative are not Peneu figures.
