Policy

Last updated 23 August 2026

Fraud and Security Policy

Not slogans about bank-grade encryption — the specific mechanisms, who holds what, and the things they do not cover.

1. Purpose and Scope

1.1 Purpose. This Policy describes the measures Nelvoi Ltd maintains to prevent fraud, protect accounts and secure the Platform, and what you can do to protect yourself.

1.2 Scope. It applies to every user of the Platform and covers fraud prevention, security controls, identity verification, incident management, and where responsibility sits between us and you.

1.3 A note on stage. NELVOI is pre-launch. The controls below describe the programme as it is being built and as it will operate; what is already in place today covers this website itself.

Separated Customer funds

Fiat balances sit with licensed issuing and banking partners, in accounts kept apart from the company's own operating money.

Tokenised Your card number

Apple Pay and Google Pay hand the merchant a one-time token. A shop that gets breached cannot leak your card.

None Deposit cover on crypto

Cryptocurrency is not covered by any deposit guarantee scheme, anywhere. We would rather write that here than let you assume otherwise.

2. How Your Balance Is Actually Held

«Your funds are safe» is the least useful sentence in this industry. What matters is who physically holds the money, whether it is mixed with the company's own, and what happens to it if the company disappears. Those are three different questions and they have three different answers depending on whether the balance is fiat or crypto.

Fiat balances. Money loaded onto a card sits with the licensed issuing and banking partners that run the card programme, in accounts that are segregated — kept separate from NELVOI's own operating money and identified as belonging to customers. Segregation is what makes those balances returnable to customers rather than available to the company's creditors. It is a different mechanism from deposit insurance, it protects against a different failure, and we will not blur the two: a bank deposit guarantee pays you back if the bank fails, segregation makes sure the money was never the company's to lose.

Crypto balances. Cryptocurrency you send is converted to a spendable fiat balance rather than held as an investment position — the card spends fiat, and the conversion happens on the way in. Any crypto held transiently during that process sits with a regulated custody partner rather than in keys held on our own laptops. No part of this is covered by a deposit guarantee scheme anywhere in the world, because no such scheme covers crypto. Anyone telling you otherwise is either confused or selling something.

What happens in insolvency. Segregated customer funds are not company assets, which is the entire point of segregating them. In an insolvency they are identified as customer money and returned through the process that applies in the issuer's jurisdiction. That process takes time — weeks or months, not hours — and we would rather you knew that now than discovered it at the worst moment.

The honest caveat. NELVOI is pre-launch, and the paragraphs above describe how the programme is structured, not a live service holding your money today. The specific issuing partner, the jurisdiction and the safeguarding arrangement will be named on this page and in the terms before accounts open.

3. Our Controls

Four layers. Each has a cost to us, which is how you can tell they are real.

Identity verification

A government-issued document checked for authenticity, a liveness check that the face matches it, confirmation of residence, and screening against sanctions and politically-exposed-person lists. Higher-risk relationships receive enhanced due diligence, and screening continues after onboarding, because lists change.

Account security

Two-factor authentication, required for withdrawals, security changes and adding a device. Encryption in transit and at rest. Automatic session expiry and a list of signed-in devices you can end remotely. Staff access is role-based, least-privilege and logged.

Transaction monitoring

Real-time screening, behavioural analytics for patterns inconsistent with an account's normal use, velocity checks and limits, sanctions screening of counterparties, and automated alerts reviewed by a person rather than closed automatically.

Infrastructure

Firewalls and intrusion detection, vulnerability management and patching, secure development practice, continuous monitoring, and independent penetration testing as part of the pre-launch programme alongside the issuing partner's own security review, which every card programme must pass before going live.

4. Account Security

The card and the balance matter less than the account they hang off. Most losses in consumer finance start with someone else getting into an account, not with a technical breach.

Two-factor authentication

Available on every account and required for sensitive actions: withdrawals, changing security settings, adding a new device. An attacker with your password alone gets nowhere.

Device and session control

Every signed-in device is listed with its last activity, and any of them can be signed out remotely. If a session looks wrong to you, you can end it without waiting for support.

Alerts on the actions that matter

A notification for every payment, and for changes to security settings, the registered email or the phone number. Silence is how account takeovers stay unnoticed for days.

A cooling-off on sensitive changes

Changing the email or phone number on an account temporarily restricts withdrawals. It is an inconvenience for you once and a serious obstacle for someone who has just stolen your credentials.

5. Protecting Yourself from Fraud

These stop the attacks that actually succeed. None of them is technical.

A unique password, and two-factor authentication

Unique, so a breach of another site is not a breach of this one. Two-factor, so a stolen password alone is not enough. Prefer an authenticator app to SMS: a SIM can be swapped.

Never share a code

Your password, a two-factor code, your full card number and any recovery phrase are never needed by us and never asked for by us. Anyone requesting one is not us, whatever the sender address looks like.

Reach us by typing the address

Do not follow links in unexpected messages. Open nelvoi.com yourself. A link that looks right in an email is the cheapest part of a phishing kit.

Distrust urgency

Pressure to act immediately is the common feature of nearly every successful scam. A legitimate request survives you taking an hour to check it.

Secure the device and the email account

Your email is the reset route for everything else; secure it at least as well as your money. Keep software updated and avoid financial actions on public networks.

Check before confirming

Recipient, network, amount, currency. On a blockchain an error here is final — see Section 7.

6. If Something Goes Wrong

What to do, in order. The first two steps are yours and they are the ones that stop the bleeding.

Freeze the card

One tap in the dashboard, or from any device you can sign in on. New payments decline immediately and the balance stays where it is. Do this before anything else — it takes seconds and is reversible.

Change your password and sign out other devices

If you think someone else has access to the account rather than just the card, this is the step that removes them. Both are in security settings.

Write to support

[email protected], from the address on the account if you can. Say what happened and when. We answer within one business day, and account-compromise reports jump the queue.

We investigate and act

We can freeze cards, block a device, reissue a card number and preserve the transaction record for a dispute. What we cannot do is reverse a completed blockchain transfer — nobody can.

7. Where Responsibility Sits

7.1 Ours. Maintaining the controls in Section 3; investigating reports promptly; freezing what needs freezing; preserving the transaction record; notifying you and the authorities where a breach requires it.

7.2 Yours. Keeping credentials and devices secure; enabling the security features we provide; reviewing transactions before confirming them; reporting anything unauthorised promptly.

7.3 What we cannot undo. As set out in the Terms and Conditions, we are not liable for losses arising from credentials you disclosed, from unauthorised access through compromised authentication, from phishing or social engineering where you provided the information, or from transactions you authorised — even where you were deceived into authorising them. This is not a disclaimer we hide: it is the reason Section 5 exists, and the reason authorised push payment fraud is the hardest kind to remedy anywhere in finance.

7.4 What nobody can undo. A completed blockchain transfer cannot be reversed by us, by our partners or by anyone else. Where recovery is technically possible we will attempt it and will not charge for the attempt.

8. Incident Management

8.1 Procedure. We maintain documented incident response procedures to detect and contain incidents, investigate root causes, implement corrective measures, and notify those affected.

8.2 Notification. Where an incident affects your personal information or your account we will notify you as and when applicable law requires, without undue delay, with what we know and what we recommend you do. We will not delay a notification in order to finish drafting a better-sounding one.

8.3 Law enforcement. We cooperate with law enforcement and regulators investigating fraud and cybercrime, and may report suspicious activity without notice to you where the law permits or requires — see the anti-money-laundering policy on why we sometimes cannot tell you.

What you control

9. The Controls Are Yours, Not Ours to Apply For

Most account damage happens in the hour before anyone reaches support. So the things that stop it are in the app, not behind a phone queue.

  • Freeze in one tap — new payments decline immediately, the balance stays put
  • Replace the number — free, and without moving the account or the money
  • Confirmation on your phone — 3-D Secure on higher-risk payments, so a stolen number is not enough
  • Details behind fresh authentication — the full number is shown only when you ask for it
See How Cards Work
Abstract render: three levers on a panel, the middle one thrown the other way

10. What This Does Not Cover

Being straightforward about the limits matters more than a longer list of reassurances.

Cryptocurrency is not covered by deposit protection. Government deposit guarantee schemes protect bank deposits, not crypto balances. Assets held in crypto carry market risk and are not insured against it.

Blockchain transfers are final. If you send funds to the wrong address or on the wrong network, nobody can reverse it. Always check the network before sending — this is the single most common way people lose money, and it has nothing to do with our security.

Nobody from NELVOI will ever ask for your password, your 2FA code or your full card number. Anyone who does is impersonating us. Our only support address is [email protected].

11. Questions About Security

Customer funds are held in segregated accounts at regulated partners, separate from company money, which is what allows them to be returned to customers rather than treated as company assets. This is not the same as deposit insurance, and we will not describe it as such.

They are submitted to a regulated verification provider that performs the check. We receive the result and the data required by law, not a copy of everything you uploaded.

Sign in from another device and freeze your cards, or write to [email protected] and we will freeze them for you. Your balance stays where it is — it is attached to your verified account, not to your device.

Independent penetration testing is part of the pre-launch programme, alongside our issuing partner's own security review, which every card programme must pass before going live.

No, and it is worth being precise about why. Deposit guarantee schemes — FSCS in the UK, FDIC in the United States, the EU deposit guarantee directives — cover deposits at licensed banks. A card balance held at a regulated e-money or issuing partner is safeguarded through segregation instead: your money is kept separate from the company's, so it remains yours rather than becoming an asset of the business. Crypto balances are covered by nothing at all, anywhere. Any provider claiming their crypto balances are insured is describing something other than deposit insurance.

We can freeze an account, and in some situations we are legally required to. Anti-money-laundering law obliges regulated firms and their partners to hold or refuse transactions in defined circumstances, and in some jurisdictions it also forbids telling you why at the time. We cannot take your money for our own use — segregated funds are not ours. The anti-money-laundering policy sets out what triggers a review and what we can and cannot tell you.

In most cases it is unrecoverable, and this is the single most common way people lose money in crypto — it has nothing to do with any provider's security. Sending USDT on the wrong chain, or to an address for a different asset, generally means the funds are gone. Check the network before you confirm. Where a recovery is technically possible we will try, but we cannot promise it and we will not charge you for the attempt.

We will never ask for your password, a two-factor code, your full card number or your recovery phrase — not by email, not by phone, not in chat, not ever. Our only support address is [email protected] and our only website is nelvoi.com. If a message asks for any of those things, it is not us, whatever the sender address looks like. Forward it to [email protected] and delete it.

We do not sell personal data. Data is shared with the parties that are necessary to run the service — the verification provider that performs identity checks, the issuing and banking partners that hold balances and process payments, and the card networks that route transactions — and with authorities where the law requires it. The privacy policy lists the categories and the reasons.

Independent penetration testing is part of the pre-launch programme, alongside our issuing partner's own security review, which every card programme must pass before going live. Card programmes also inherit the PCI DSS requirements that apply to handling card data, which is one reason full card numbers are handled by the issuing platform rather than stored by us.