KubePay
HomeLog in

Security & Trust

Your payments. Protected.

Kube Pay is built on regulated open banking infrastructure. Every payment is protected by UK financial regulation, bank-grade security, and our commitment to your data.

FCA Regulated

Payment services delivered under FCA authorisation No. 964289

Open Banking

Powered by UK-regulated open banking infrastructure

Bank-Grade Security

TLS encryption and Strong Customer Authentication on every payment

No Stored Credentials

We never see or store your online banking username or password

How Kube Pay keeps your payment secure

  1. 1

    You authorise at your own bank

    When you make a payment through Kube Pay, you are redirected directly to your bank’s own secure app or website to approve the payment. We never handle your login details, PIN, or password at any point.

  2. 2

    Strong Customer Authentication (SCA)

    Your bank requires you to verify your identity using SCA — typically a combination of your biometric, a one-time code, or your banking app — before the payment is approved. This is a regulatory requirement under the Payment Services Regulations 2017.

  3. 3

    Payment goes straight to the merchant’s bank

    Once approved, your bank sends the funds directly to the merchant’s account via Faster Payments. Kube Pay never holds your money. There is no intermediary sitting between your bank and the merchant.

  4. 4

    Instant confirmation

    You receive an immediate confirmation once your bank accepts the payment instruction. Both you and the merchant can see the payment status in real time.

Regulated, authorised, and accountable

Kube Pay is a trading name of Kube Finance Limited. Payment initiation services are provided under the FCA authorisation of Wonderful Payments Ltd (trading as Asima). Kube Finance Limited acts as an agent of Wonderful Payments Ltd.

Regulated PrincipalWonderful Payments Ltd (trading as Asima)
FCA Registration Number964289
Authorisation TypeFCA-authorised Payment Institution — Payment Initiation Service Provider (PISP) and Account Information Service Provider (AISP)
Regulatory FrameworkPayment Services Regulations 2017 (PSR 2017)
AgentKube Finance Limited (trading as Kube Pay) — listed agent of Wonderful Payments Ltd on the FCA Register
FCA RegisterVerify at register.fca.org.uk — search “Wonderful Payments Ltd” or FCA No. 964289
Data ProtectionKube Finance Limited is registered with the Information Commissioner’s Office (ICO). ICO Registration: [Insert]
Company RegistrationKube Finance Limited, registered in England and Wales. Company No: [Insert]

Your data. Your control.

We never see your bank login

When you approve a payment, you do so directly within your bank’s own app or website. Kube Pay has no access to your username, password, or PIN at any point.

No ongoing account access

Each payment is a one-time instruction. We do not have standing access to your bank account, balance, or transaction history.

Encrypted in transit and at rest

All data transmitted to and from the Kube Pay platform is encrypted using TLS. Stored data is encrypted at rest using industry-standard protocols.

UK GDPR compliant

We process personal data in accordance with the UK General Data Protection Regulation and the Data Protection Act 2018. You have full rights over your data.

Minimal data retention

We only retain personal data for as long as required by law or our regulatory obligations. Payment data is retained for 6 years in line with HMRC and AML requirements.

Breach notification

In the unlikely event of a personal data breach, we will notify the ICO within 72 hours and affected individuals where required by law.

Built on bank-grade infrastructure

  • checkTLS 1.2+ encryption on all data in transit
  • checkRole-based access controls on all internal systems
  • checkAES-256 encryption for data at rest
  • checkRegular penetration testing and vulnerability assessments
  • checkStrong Customer Authentication (SCA) on every payment
  • check24/7 automated transaction monitoring for fraud signals
  • checkFinancial-grade API (FAPI) open banking connectivity
  • checkIncident response and breach notification procedures
  • checkNo storage of payer bank credentials
  • checkVendor security due diligence for all third-party processors
  • checkHosted on ISO 27001-certified cloud infrastructure [confirm with provider]
  • checkOWASP security principles applied in platform development

Why open banking is more secure than card payments

FeatureKube Pay (Open Banking)Card Payments
AuthenticationBank-level SCA — biometric or app approval by account holderCard details entered by payer — susceptible to theft
Credential exposureZero — Kube Pay never sees login detailsCard number, CVV, and expiry exposed at point of entry
Fraud chargebacksNot applicable — bank-authorised payment by account holderChargebacks possible — fraud and friendly fraud risk
PCI DSS scopeNot applicable — no card data handledRequired — adds cost and compliance overhead
Regulatory oversightFCA-regulated PISP under PSR 2017Card scheme rules (Visa/Mastercard) — separate framework

Spotted something? Tell us.

If you believe you have identified a security vulnerability in the Kube Pay platform, or if you suspect fraudulent activity on your account, please contact our security team immediately.

  • Security issues: security@kubepay.co.uk
  • Fraud or suspicious activity: fraud@kubepay.co.uk
  • General complaints: complaints@kubepay.co.uk

We take all security reports seriously and will acknowledge receipt within 24 hours. Responsible disclosure reports are welcomed and we commit to investigating all reports in good faith.

Learn more about how we protect you

Privacy PolicyHow we collect, use, and protect your personal dataCookie PolicyHow we use cookies and tracking technologiesComplaints PolicyHow to raise a concern and your rights under FCA rulesPayment Services T&CsThe terms governing use of our payment servicesFCA RegisterVerify our regulated status — search FCA No. 964289