KeynoBite
Restaurant Operating Ecosystem
Legal & Compliance

Fraud Prevention, Transaction Security & AML Policy

This Fraud Prevention, Transaction Security & AML Policy (“Policy”) outlines the operational, technical, and procedural safeguards implemented within the KeynoBite platform ecosystem to support fraud prevention, trans...

This Fraud Prevention, Transaction Security & AML Policy (“Policy”) outlines the operational, technical, and procedural safeguards implemented within the KeynoBite platform ecosystem to support fraud prevention, trans...

Primary intent: Fraud Prevention, Transaction Security & AML Policy policy Entity: fraud-prevention-transaction-security-aml-policy
Operated by: Keynoverse FZC
Platform: KeynoBite
Contact: info@keynobite.com · onboarding@keynobite.com


Related Policies

Document Purpose
Merchant Onboarding & Compliance Policy KYB, acceptable use, prohibited categories, merchant lifecycle
Audit, Record-Keeping & Compliance Governance Policy Audit trails, retention, compliance framework
Merchant Risk & Escalation Framework Escalation tiers and enforcement procedures

1. Introduction

This Fraud Prevention, Transaction Security & AML Policy (“Policy”) outlines the operational, technical, and procedural safeguards implemented within the KeynoBite platform ecosystem to support fraud prevention, transaction integrity, anti-money laundering (AML) awareness, platform security, and operational risk management.

KeynoBite is a restaurant commerce and operational technology platform operated by Keynoverse FZC.

1.1 Who This Policy Applies To

This Policy applies to:

  • Customers using KeynoBite ordering channels
  • Restaurant partners, merchants, and vendors
  • Platform users, agency partners, and authorized administrators
  • Operational integrations, including PSP and payment workflows
  • Related platform activities conducted through the KeynoBite ecosystem

By using the platform, all users acknowledge and agree to the security and fraud prevention practices described in this Policy.

1.2 Platform Positioning

KeynoBite is a technology platform only. It is not a licensed financial institution, PSP, wallet operator, remittance provider, or custodian of funds. Controls in this Policy are platform governance and risk management measures that complement — but do not replace — regulated AML and fraud programs operated by licensed PSP partners.


2. Nature of the Platform

KeynoBite operates solely as:

  • A SaaS platform provider
  • Operational workflow system
  • Restaurant commerce infrastructure provider
  • Technology integration layer

KeynoBite does not operate as:

  • A payment service provider (PSP)
  • Financial institution or wallet operator
  • Remittance provider or regulated payment intermediary

Where payment functionality is enabled, payment processing, authorization, and settlement activities occur through licensed third-party PSPs directly with merchants. KeynoBite does not hold customer transaction funds or operate settlement systems.


3. Security & Fraud Prevention Objectives

KeynoBite maintains operational and technical controls designed to:

  • Reduce fraud risk and detect suspicious activity
  • Protect platform integrity and secure operational workflows
  • Minimize abuse and safeguard user accounts
  • Support lawful platform usage and PSP partner expectations
  • Enable cooperation with competent authorities where required

Fraud prevention measures help protect customers, merchants, operational systems, payment integrations, and platform infrastructure.

3.1 AML & CTF Governance Principles

Where merchant onboarding and payment enablement are involved, KeynoBite maintains an AML-aware posture aligned with UAE expectations for technology platforms supporting commerce:

  1. Risk-based approach scaled to merchant risk tier
  2. Know Your Business verification before payment enablement
  3. Sanctions awareness and restricted-party screening
  4. Ongoing monitoring beyond initial onboarding
  5. Escalation, documentation, and PSP coordination
  6. No custodial activity — KeynoBite does not hold or transmit customer funds

4. Operational Security Measures

KeynoBite may implement operational security controls including:

  • Account verification and authentication safeguards
  • Session monitoring and access restrictions
  • IP/device monitoring and rate limiting
  • Operational logging and workflow monitoring
  • Anomaly detection and suspicious activity review

Security measures may be updated periodically based on operational requirements, emerging threats, and infrastructure improvements.


5. Transaction Monitoring

Where transaction-related workflows are enabled, KeynoBite may monitor operational indicators relating to:

  • Unusual order activity or abnormal transaction patterns
  • Repeated failed actions or excessive refund behavior
  • Suspicious onboarding activity or account abuse
  • Unauthorized access attempts and operational anomalies
  • Sustained volume exceeding declared merchant profiles
  • Chargeback spikes or PSP fraud alerts (via partner feedback)
  • Payment credential misuse or unauthorized gateway changes

Full payment fraud scoring remains with licensed PSPs. KeynoBite monitors platform-visible indicators and acts on PSP alerts and internal anomaly detection.


6. Sanctions Screening & AML Controls

6.1 Screening Scope

KeynoBite may screen merchant entities, UBOs, authorized representatives, and related parties against:

  • UAE local sanctions requirements
  • UN Security Council consolidated lists
  • Internationally recognized sanctions programs (where applicable)
  • Internal denied-party and prior-offboarded merchant lists
  • PSP partner-supplied restricted entity lists

Screening occurs at onboarding and may be re-performed upon trigger events.

6.2 Match Handling

Outcome Action
Clear Proceed per risk tier
Potential match Compliance review; additional documentation
Confirmed match Immediate rejection or termination
Sanctioned jurisdiction nexus Rejection or full EDD with senior approval

6.3 Politically Exposed Persons (PEPs)

Merchants must declare PEP status for UBOs at onboarding. PEP identification triggers Enhanced Due Diligence per the Merchant Onboarding & Compliance Policy.

6.4 Adverse Media Review

KeynoBite may conduct light adverse media review during onboarding and periodic reviews for fraud, financial crime, licensing enforcement, or deceptive business practice indicators.


7. Fraud Prevention Controls

7.1 Onboarding & Merchant Fraud

Control Description
Document authenticity review Detection of altered or inconsistent documents
Entity matching Cross-check license, bank account, and UBO names
Premises verification Lease, utility, and photographic evidence
Duplicate & velocity detection Repeated applications from same agency/IP/device
Shell merchant detection Rejection of entities lacking operational substance
API audit logging Programmatic onboarding actions timestamped and traceable

7.2 Customer-Facing Fraud Support

Where visible through platform tools, KeynoBite may monitor:

  • Phone/authentication verification anomalies
  • Repeated failed payment attempts (PSP callback metadata)
  • Account takeover indicators on customer or merchant accounts

8. Merchant & Vendor Responsibilities

Merchants and vendors using the platform are responsible for:

  • Maintaining lawful operations and safeguarding account credentials
  • Complying with PSP requirements and monitoring unauthorized activity
  • Ensuring accurate operational conduct and truthful onboarding information

Merchants must not:

  • Engage in fraudulent transactions or money laundering
  • Misuse payment infrastructure or facilitate unauthorized activity
  • Process payments for undisclosed third parties (transaction laundering)
  • Manipulate transaction volumes, refunds, or operational workflows
  • Violate applicable laws or platform policies

Merchants remain responsible for activities conducted through their accounts and integrations. Full prohibited categories are in Section 13 of the Merchant Onboarding & Compliance Policy.


9. Customer Account Protection

Customers are responsible for:

  • Maintaining confidentiality of login credentials
  • Protecting device access and monitoring account activity
  • Promptly reporting suspicious activity

Users should not share passwords, authentication codes, or account access with unauthorized parties.

KeynoBite may suspend accounts where unauthorized access or abuse is suspected.


10. Payment Security

Where payment functionality is available:

  • Payment processing occurs through licensed PSP infrastructure
  • Payment authorization occurs within PSP-managed environments
  • Sensitive payment data is handled by the PSP, not KeynoBite

KeynoBite does not:

  • Directly store customer card PANs, CVV, or wallet PINs
  • Operate payment settlement systems or custody customer transaction funds

Hosted payment pages, tokenization, and payment security controls are operated by the applicable PSP provider.


11. Infrastructure Security

KeynoBite may implement technical safeguards including:

  • SSL/TLS encryption and secure hosting environments
  • Infrastructure monitoring, access controls, and firewall protections
  • Authentication systems, secure APIs, and operational segmentation
  • System logging and backup procedures

Reasonable efforts are made to protect platform systems against unauthorized access, misuse, disruption, data compromise, and malicious activity.


12. Prohibited Financial Conduct

Users and merchants must not use KeynoBite or connected PSP infrastructure for:

  • Money laundering, terrorist financing, or sanctions evasion
  • Structuring, smurfing, or ghost/fake transaction generation
  • Unlicensed financial services, remittance, or wallet loading schemes
  • Cryptocurrency exchange or unregulated digital asset sales
  • Chargeback fraud or deceptive billing unrelated to declared business
  • Any activity illegal under UAE law or applicable jurisdiction

Violations may result in immediate suspension and notification to PSP partners or authorities where required.


13. Fraud Investigations, Escalation & Enforcement

KeynoBite reserves the right to investigate suspicious activity, operational abuse, fraud indicators, policy violations, or unlawful conduct.

13.1 Response Actions

Severity Typical Response
Low Enhanced monitoring, documentation request
Medium Temporary restriction, compliance review
High Suspension, PSP notification, investigation
Critical Termination, record preservation, authority/PSP notification

Detailed escalation tiers are in the Merchant Risk & Escalation Framework.

13.2 Enforcement Powers

Where reasonably necessary, KeynoBite may:

  • Restrict platform access or suspend accounts
  • Disable integrations or request additional verification
  • Report unlawful conduct to applicable authorities or PSP providers
  • Preserve audit records per the Audit & Compliance Governance Policy

Report suspected fraud: onboarding@keynobite.com


14. PSP & Regulatory Cooperation

KeynoBite cooperates with licensed PSP partners, acquirers, and competent UAE/international authorities on lawful fraud and compliance inquiries, subject to legal process and data protection requirements.


15. Third-Party Services & Integrations

KeynoBite interacts with third-party services including PSPs, cloud infrastructure, analytics, and communications providers. While reasonable care is taken in selecting providers, KeynoBite is not responsible for independent security practices or operational failures of third-party systems. Users are encouraged to review relevant third-party policies separately.


16. Training & Awareness

KeynoBite personnel with compliance or admin access receive orientation on fraud indicators, sanctions awareness, and escalation procedures. Agency partners are expected to report anomalies promptly.


17. Limitation of Liability

No platform can guarantee complete protection against fraud, unauthorized access, cyber threats, or operational abuse.

To the maximum extent permitted by applicable law, KeynoBite shall not be liable for:

  • Unauthorized account activity or fraud by third parties
  • Payment provider operational failures or cyber incidents
  • Service interruptions, indirect losses, or damages from unlawful third-party conduct

Users remain responsible for maintaining reasonable security practices for their own accounts and operations.


18. Changes to This Policy

KeynoBite may update this Policy periodically to reflect operational improvements, emerging security risks, platform enhancements, legal requirements, or compliance developments. Continued use of the platform constitutes acceptance of the updated Policy.

This Policy is reviewed at least annually.


19. Contact

Purpose Contact
General fraud & security inquiries info@keynobite.com
Merchant compliance & fraud reporting onboarding@keynobite.com
Operator Keynoverse FZC
Website KeynoBite

KeynoBite is a technology platform operated by Keynoverse FZC. Regulated AML and payment fraud obligations for customer transactions remain with licensed PSP partners.

The Challenge

What challenge does Fraud Prevention, Transaction Security & AML Policy address?

This Fraud Prevention, Transaction Security & AML Policy (“Policy”) outlines the operational, technical, and procedural safeguards implemented within the KeynoBite platform ecosystem to support fraud prevention, trans...

The KeynoBite Approach

How KeynoBite approaches Fraud Prevention, Transaction Security & AML Policy

This Fraud Prevention, Transaction Security & AML Policy (“Policy”) outlines the operational, technical, and procedural safeguards implemented within the KeynoBite platform ecosystem to support fraud prevention, trans...

Need a walkthrough?

Map Fraud Prevention, Transaction Security & AML Policy to your restaurant setup

Book a walkthrough with the KeynoBite team to see how this area fits your operating model.