• Solutions
  • Platform
  • Compliance
  • Company
Talk to our team
LEGAL

Fraud & Security Policy

This Policy explains how BORQR protects its Platform, detects and responds to fraud, and how Business Customers and authorised users can protect their access and report suspicious activity.

Document Code
BOREAN-LEGAL-FSP
Version
1.1
Effective Date
27 July 2026
Last Updated
13 August 2026
Applicable Entity
BOREAN SERVICES FZCO
Jurisdiction
Dubai, United Arab Emirates
Table of Contents
1. Purpose and Scope2. Security and Fraud Prevention Framework3. Business Verification and Access Controls4. Transaction Monitoring and Protective Measures5. Platform and Service Partner Security6. Common Fraud and Cyber Threats7. Customer Security Responsibilities8. Reporting Suspicious Activity9. Incident Management and Cooperation10. Liability, Changes and ContactVersion History

1. Purpose and Scope

This Fraud & Security Policy explains the measures BOREAN SERVICES FZCO uses to prevent, detect, investigate and respond to fraud, unauthorised activity, cyber threats and security incidents.

This Policy also explains how Business Customers and authorised users can protect their access and report suspicious activity.

BORQR provides the technology and operational layer supporting partner-enabled payment workflows. Where a Transaction is financially executed by a bank, payment institution, payment service provider or other authorised financial institution, that Service Partner remains responsible for the financial-crime, transaction-monitoring and other regulatory obligations applicable to the financial service it provides.

The Policy applies to:

• the BORQR website;

• the BORQR Platform;

• dashboards, portals and APIs;

• payment instructions submitted through the Services;

• Business Customers and their authorised users;

• prospective customers and business partners; and

• Service Partners supporting the Services.

This Policy should be read together with the Business Payment Services Terms, Privacy & Cookies Policy and any applicable Order Form or Service Schedule.

No security system can prevent every fraud attempt or cyber incident. BORQR applies risk-based controls but does not guarantee that every fraudulent or unauthorised action will be prevented.

2. Security and Fraud Prevention Framework

BORQR maintains a risk-based security and fraud-prevention framework designed to protect the Platform, Business Customers, Transaction information and BORQR’s operations.

Controls may include:

• business and identity verification;

• sanctions and watchlist screening;

• access and authorisation controls;

• transaction monitoring;

• fraud-risk indicators;

• velocity and value checks;

• device, network and session analysis;

• beneficiary and payment-detail verification;

• manual compliance or fraud review;

• system and security logging;

• incident response procedures;

• vulnerability and patch management;

• Service Partner oversight; and

• record retention.

BORQR applies these controls primarily for Platform security, business verification, fraud prevention, technical risk and operational oversight. Relevant Service Partners may apply additional sanctions, AML/CFT, transaction-monitoring and regulatory controls independently in accordance with their own obligations.

The controls applied may vary depending on:

• the Business Customer’s risk profile;

• transaction type and value;

• currency and jurisdiction;

• payment route;

• device and access information;

• transaction history;

• beneficiary information;

• Service Partner requirements; and

• applicable legal or regulatory obligations.

BORQR does not publicly disclose internal detection rules, security configurations, review thresholds or investigation methods where doing so could weaken their effectiveness.

3. Business Verification and Access Controls

BORQR may verify:

• the Business Customer’s legal existence;

• licences and registrations;

• shareholders and ultimate beneficial owners;

• directors and authorised representatives;

• business activity and operating model;

• source of funds and expected transaction activity;

• websites, applications and customer channels; and

• documents supporting individual Transactions.

Enhanced due diligence or additional verification may be required for higher-risk customers, activities, jurisdictions or Transactions.

Verification performed by BORQR does not replace any customer due diligence or verification independently required by a relevant regulated Service Partner.

BORQR may repeat or update verification where:

• customer information changes;

• ownership or control changes;

• unusual activity is identified;

• a Service Partner requests additional information;

• documents expire;

• access credentials may have been compromised; or

• periodic review is required.

Access controls may include:

• individual user accounts;

• passwords or other authentication credentials;

• multi-factor authentication where supported;

• role-based permissions;

• approval levels;

• session controls;

• access logging; and

• restrictions on sensitive administrative actions.

Business Customers must provide access only to properly authorised personnel and must remove or update access promptly when an employee, contractor or representative changes role or leaves the organisation.

4. Transaction Monitoring and Protective Measures

BORQR and relevant Service Partners may monitor Transactions and related activity to identify possible fraud, abuse, unauthorised access, sanctions exposure or activity inconsistent with the approved business profile.

BORQR monitoring may include technical, behavioural, fraud, security and operational-risk indicators. Where a regulated financial institution or payment service provider executes a Transaction, regulatory transaction monitoring and financial-crime controls applicable to that service are performed within the relevant Service Partner's compliance framework.

BORQR's controls supplement and support partner controls and do not replace the regulatory responsibilities of the relevant authorised Service Partner.

Monitoring may consider:

• unusual transaction values or frequency;

• rapid movement of funds;

• repeated failed attempts;

• unusual beneficiary changes;

• new or higher-risk counterparties;

• unusual device, IP address or location information;

• access from unexpected jurisdictions;

• activity inconsistent with previous behaviour;

• duplicated or altered payment information;

• unusual refund or chargeback patterns;

• attempts to avoid limits or controls; and

• information received from Service Partners or authorities.

Where a concern is identified, BORQR may:

• request additional verification;

• request invoices, agreements or supporting records;

• delay or reject a payment instruction;

• apply a transaction limit;

• restrict a payment route;

• require additional approval;

• temporarily restrict Platform access;

• suspend transaction processing;

• notify or consult a Service Partner;

• preserve relevant records; or

• take another action permitted under the Agreement and applicable law.

In taking protective measures, BORQR may restrict Platform access, withhold or route an instruction for additional review, or request action by the relevant Service Partner, while any restriction, hold, rejection or release of funds is performed within the relevant partner infrastructure where that partner controls the funds.

A delay or restriction made for security, fraud-prevention or compliance purposes does not confirm that fraud or unlawful conduct has occurred.

5. Platform and Service Partner Security

BORQR applies reasonable technical and organisational measures appropriate to the nature of the Platform and the information processed.

Measures may include:

• encrypted transmission of information;

• access controls and authentication;

• role-based permissions;

• system and security logging;

• network and application protection;

• monitoring for malicious or automated activity;

• vulnerability management;

• software updates and security patching;

• secure development practices;

• backup and recovery procedures;

• incident response procedures;

• vendor and Service Partner reviews; and

• staff confidentiality requirements.

KereX Technologies L.L.C-FZ supports the BORQR Platform, API infrastructure and technical integrations as a Technology Provider.

BORQR may also use cloud, cybersecurity, communications, identity-verification, banking and payment Service Partners.

Each independent Service Partner remains responsible for the security, regulatory controls and financial services provided within its own systems and infrastructure.

BORQR may exchange relevant security and fraud information with Service Partners where reasonably required to:

• provide the Services;

• investigate suspicious activity;

• protect systems and users;

• prevent fraud;

• comply with legal obligations; or

• respond to a competent authority.

6. Common Fraud and Cyber Threats

Business Customers and authorised users should remain alert to common fraud and cyber threats.

Phishing

Fraudulent emails, websites, text messages or calls may imitate BORQR, a bank, a customer, a supplier or another legitimate organisation to obtain credentials or confidential information.

Social engineering

Fraudsters may create urgency, impersonate senior managers, employees, regulators, banks or technical support and pressure a person to disclose information or approve a Transaction.

Business email compromise

A fraudster may access or imitate a company email account and request changes to beneficiary, invoice or settlement details.

Invoice and beneficiary fraud

Fraudsters may submit false invoices or replace legitimate payment details with accounts or wallets under their control.

Account takeover

Unauthorised persons may attempt to access an account using stolen passwords, compromised email accounts, malware, credential reuse, SIM swapping or manipulated authentication.

Malware and remote-access fraud

A person may be persuaded to install software, share a screen or allow remote access to a device used for financial activity.

Impersonation and fake support

Fraudsters may claim to represent BORQR, a Banking Partner, KereX Technologies, a regulator or law-enforcement authority.

Authorised transfer fraud

A Business Customer or authorised user may be deceived into approving a Transaction to a fraudster, even though the instruction technically came from an authorised account.

BORQR will never ask a user to:

• disclose a password or complete authentication code;

• share a private cryptographic key;

• provide full payment-card credentials by email;

• install unknown remote-access software;

• transfer funds to a “safe” account; or

• approve a Transaction solely to protect an account.

7. Customer Security Responsibilities

Business Customers and authorised users must:

• use strong and unique passwords;

• enable multi-factor authentication where available;

• protect email accounts and devices;

• keep operating systems and software updated;

• restrict Platform access to authorised personnel;

• review access permissions regularly;

• verify beneficiary and settlement details independently;

• review Transactions and account activity;

• use secure networks for sensitive activity;

• avoid links and attachments from unexpected messages;

• confirm unusual requests through a separate trusted channel; and

• report suspected compromise without delay.

Passwords, authentication codes, API keys and other credentials must not be shared between users.

Business Customers must maintain their own:

• cybersecurity controls;

• fraud-prevention procedures;

• employee-access controls;

• approval processes;

• incident-response procedures;

• customer and supplier verification procedures; and

• records supporting payment instructions.

Before approving an unusual or urgent Transaction, the authorised user should independently verify:

• the identity of the requester;

• the beneficiary’s legal name;

• account or wallet details;

• the commercial purpose;

• the supporting invoice or agreement; and

• any recent change to payment instructions.

8. Reporting Suspicious Activity

Suspicious activity should be reported immediately where a Business Customer or authorised user notices:

• an unauthorised Transaction;

• an unknown login or access attempt;

• an unexpected password or security change;

• a new user or permission that was not approved;

• altered beneficiary or settlement information;

• a suspicious message claiming to be from BORQR;

• a request for passwords or authentication codes;

• possible phishing, malware or remote access;

• loss or compromise of a device or credential; or

• another unusual or concerning activity.

Reports must be sent to:
legal@borqr.com

Recommended subject line:
URGENT - Security/Fraud Report

The report should include:

• the Business Customer’s legal name;

• the authorised user’s name and business email;

• a description of the suspicious activity;

• the date and approximate time;

• the relevant Transaction or reference number;

• affected user accounts or systems;

• screenshots or supporting records where available; and

• actions already taken.

Do not include passwords, authentication codes, full card details, private cryptographic keys or unnecessary identity documents in the email.

Where access may have been compromised, the Business Customer may request temporary restriction of Platform access or Transaction processing.

BORQR may require identity and authority verification before acting on a restriction or access-restoration request.

9. Incident Management and Cooperation

BORQR maintains procedures for assessing and responding to reported fraud and security incidents.

Depending on the circumstances, BORQR may:

• acknowledge and record the report;

• request additional information;

• restrict relevant access or activity;

• preserve logs and supporting records;

• investigate affected Transactions or systems;

• coordinate with Technology Providers, Banking Partners and other Service Partners;

• contain or reduce the impact of an incident;

• restore access after appropriate verification;

• implement corrective or preventive measures;

• notify affected persons where required;

• submit a report to a competent authority; or

• cooperate with law-enforcement or regulatory investigations.

BORQR may preserve information and evidence relating to suspected fraud, cybercrime, unauthorised activity or security incidents for legal, compliance and investigative purposes.

BORQR's incident management actions relate to Platform access, API infrastructure, credentials and technical workflows. BORQR does not control and cannot independently reverse, freeze or release funds held within the infrastructure of an independent financial institution.

BORQR may be unable to disclose:

• confidential detection rules;

• security configurations;

• information about another customer;

• details of a suspicious activity report;

• information subject to legal restrictions; or

• information that could compromise an investigation.

Where a personal-data breach may prejudice the privacy, confidentiality or security of individuals, BOREAN SERVICES FZCO will take the notification and response steps required by applicable data-protection law.

10. Liability, Changes and Contact

Security controls reduce risk but cannot eliminate every possibility of fraud, social engineering, unauthorised access, malware, system failure or cyberattack.

Business Customers remain responsible for:

• protecting their own systems and devices;

• safeguarding credentials and API keys;

• managing authorised users;

• verifying payment instructions;

• monitoring their activity;

• maintaining appropriate internal controls; and

• reporting suspicious activity promptly.

Liability for unauthorised, fraudulent or disputed Transactions is governed by the Business Payment Services Terms, applicable Order Form, Service Schedule and applicable law.

BOREAN SERVICES FZCO may update this Policy to reflect changes in:

• security practices;

• fraud threats;

• Platform functionality;

• Service Partners;

• legal or regulatory requirements; or

• business operations.

The current version and effective date will be displayed on this page.

Contact details:
BOREAN SERVICES FZCO
Unit 4501-010-D59
Mazaya Business Avenue BB2
Jumeirah Lakes Towers
Dubai, United Arab Emirates

Fraud, security, legal and compliance enquiries:
legal@borqr.com

Important reminder:
BORQR will never ask you to disclose your password or authentication code, transfer funds to a “safe” account, or install unknown remote-access software.

Version History

Version
Effective Date
Last Updated
Summary
1.1
13 August 2026
13 August 2026
Clarified BORQR and Service Partner security and transaction-monitoring responsibilities.
1.0
27 July 2026
27 July 2026
Initial publication

API infrastructure for corporate clients.

BOREAN SERVICES FZCO
DMCC Registration No. DMCC204977

Navigation

ServicesAPIComplianceCompany

Legal & Contact

Privacy & Cookies PolicyTerms of UseFraud & Security PolicyContact

© 2026 BOREAN SERVICES FZCO

Dubai, United Arab Emirates