Security by design
Use layered account controls, transaction authorisation and server-side validation appropriate to the risk of each action.
This page explains the internal principles KeduTrust uses to guide product design, financial safety, provider integration, customer communication and continuous improvement.
These principles describe how KeduTrust aims to operate. They are not a substitute for product-specific terms, provider rules or legal requirements that apply to a particular service.
Use layered account controls, transaction authorisation and server-side validation appropriate to the risk of each action.
Keep authoritative financial states on the server, protect against duplicate execution and reconcile uncertain provider outcomes before finalising value movement.
Collect and use information needed to provide, secure, support and improve the service, with access and sharing limited to legitimate operational needs.
Show recipients, amounts, fees, rates, statuses and important product rules as clearly as possible before customers make sensitive decisions.
External processors are infrastructure. KeduTrust should independently verify provider results and preserve local transaction records, references and audit trails.
Review reliability, security, customer feedback and product operations so controls and experiences can improve as KeduTrust evolves.
If an external provider may have accepted a transaction but the result is unclear, KeduTrust's safer operating principle is to retain a controlled pending state and reconcile the original reference rather than blindly retrying, double-crediting or refunding.
Recipient checks, balance controls, exchange quotes, bills and withdrawals should be validated server-side.
Shopping prices, inventory, protected payments, delivery and settlement should follow auditable server-side rules.
Eligibility, offers, pricing and repayment obligations should come from current KeduTrust policy and accepted server records.
Merchant approvals, payment integrations and settlement controls should remain distinct from provider branding or browser state.