Skip to content

Company · regulation and security

Who governs your payments, and what to check

Payments in India run on rails operated and supervised by regulators, through banks and providers they license. This page explains that structure, where Peneu sits in it, and what evidence to ask for before trusting any payments partner with your money and data.

Who regulates what

Several bodies shape how money moves. For a business, the practical point is that the entity holding and moving your money is licensed or authorised by one of them, and has obligations you benefit from.

Bodies that shape payments in India
BodyRole in paymentsExamples
Reserve Bank of IndiaRegulates banks and payment systems; authorises payment aggregators and prepaid instrument issuersPayment aggregator, PPI, card, digital lending and authentication directions
NPCIOperates retail payment systems under RBI's oversightUPI, IMPS, NACH, BBPS, NETC
Sector regulatorsRegulate their own industries' use of paymentsIRDAI for insurance, SEBI for securities
GovernmentLaws on data, tax, and specific sectorsDigital Personal Data Protection Act, 2023; Online Gaming Act, 2025

Where Peneu sits

Peneu is a payment orchestration platform: a layer in front of payment providers that routes payments and brings their results together. Regulated services are delivered through licensed partner banks and institutions. Details of Peneu's security controls, audits and certifications are shared during partner and merchant due diligence.

This site doesn't claim any licence or authorisation for Peneu itself. The guides describe which kind of regulated entity provides each product, so you know who is responsible for what.

Security principles

These are the principles Peneu applies to its platform. Evidence (how each is implemented, and any audits or certifications) is shared during due diligence, not asserted here.

  • Encryption of data in transit and at rest
  • Role-based access and multi-factor authentication for dashboard users
  • Least-privilege access to production systems and credentials
  • Audit trails for configuration, credential and payout changes
  • API keys and secrets issued per environment and never exposed client-side
  • Continuous monitoring of provider health and transaction anomalies

Payment data and personal data

RBI's circular on storage of payment system data (6 April 2018) requires payment system providers to store the entire data relating to the payment systems they operate in a system only in India, including full end-to-end transaction details; for the foreign leg of a transaction, the data can also be stored abroad.

Personal data in payments (names, phone numbers, account details) is also governed by the Digital Personal Data Protection Act, 2023. How these apply to your own business is a question for your adviser.

Data questions to settle with any payments partner
QuestionWhy
Where is payment data stored and processed?Storage rules for payment system data
Who can access our data, and how is access logged?Your customers' data is your responsibility too
How long is data kept, and how is it deleted?Retention obligations and data protection
How are incidents reported to us?You may have your own notification duties

A due-diligence checklist for any payments partner

Use this with any provider, including Peneu. Ask for evidence, not assurances.

Authorisation

Which regulated entity provides each service, and its authorisation, checkable on the regulator's own list.

Fund flow

Where your customers' money sits at every step, and who it's owed to.

Security evidence

Audit reports or certifications, current and in scope for the service you'll use.

Data handling

Storage location, access controls, retention and incident reporting.

Continuity

What happens in an outage, and how you're told.

Exit

How you'd move away, and what happens to data and funds if you do.

Regulation and security questions

Is Peneu regulated by RBI?

This page doesn't claim any licence or authorisation for Peneu. Regulated payment services (collecting and settling money, issuing instruments, lending) are provided by licensed banks and authorised payment providers. Which ones, and how responsibilities are split, is set out during onboarding.

Does Peneu have security certifications?

No certification is claimed on this site. Details of Peneu's security controls, audits and any certifications are shared during partner and merchant due diligence, where you can check the evidence yourself.

Where is payment data stored?

RBI requires payment system providers to store the entire data relating to the payment systems they operate in a system only in India, with the foreign leg of a transaction allowed to be stored abroad as well. Ask any provider how it complies.

Which data protection law applies?

India's Digital Personal Data Protection Act, 2023 governs personal data, alongside sector rules from regulators such as RBI. How they apply to your business is a question for your adviser.

How do I report a security issue?

Through the contact form, marked as a security issue, with enough detail to reproduce it. Please don't include personal or payment data belonging to anyone else.

Official sources

Last reviewed . Examples, amounts and screens marked illustrative are not Peneu figures.