Payment and Data Security
How we protect your money and your information · Version 1.0 · Effective 27 July 2026
Your money and your information are handled carefully
CapVerge is a registered credit provider (NCRCP23705). We are regulated by the National Credit Regulator, and we handle your personal and financial information under the Protection of Personal Information Act. This page sets out, plainly, what we do to keep your data and your payments safe.
1. How we secure this website
- Encrypted connection. Every page on capverge.co.za is served over HTTPS using TLS. Your browser will show a padlock. Information you type into an application form is encrypted before it leaves your device.
- No credentials in plain text. Passwords are stored using a one-way cryptographic hash. Nobody at CapVerge can read your password.
- Session protection. Accounts time out after a period of inactivity, and sessions are invalidated on logout.
- Platform maintenance. The website and its components are kept patched and updated, and are monitored for malicious activity.
2. How we handle payments
2.1 Money coming to you
Approved loans are paid by electronic funds transfer into a South African bank account held in your own name. We do not pay funds into a third party’s account, and we do not pay out in cash.
2.2 Money coming back to us
Repayments are collected by debit order under a mandate you authorise when you sign your credit agreement. Under the DebiCheck system, you confirm that mandate directly with your own bank — which means:
- no debit order can be loaded against your account without your bank confirming it with you;
- the amount and date are fixed by the mandate you approved; and
- you can see and query the mandate through your own bank.
2.3 What we never do
- We never ask for your online banking PIN, password or one-time password. Nobody from CapVerge will ever request these.
- We do not store full payment card numbers or card security codes on our systems.
- We do not ask for payment of any “advance fee”, “clearance fee” or “insurance deposit” before releasing a loan. Any request of this kind in our name is fraud.
3. How we protect your personal information
Control | What it means in practice |
Encryption | Data encrypted in transit using TLS, and sensitive data encrypted at rest. |
Access control | Staff can access only the records their role requires. Access is logged and reviewed. |
Multi-factor authentication | Required for administrative and system-level access. |
Segregation of duties | The person who assesses an application is not the person who releases the funds. |
Vendor controls | Every service provider that touches customer data is bound by a written agreement with data-protection obligations. |
Backup and recovery | Documented backup, business continuity and disaster recovery arrangements, tested periodically. |
Staff training | All staff are trained on POPIA, information security and fraud awareness. |
4. Fraud prevention
We operate documented fraud prevention and AML/KYC controls, which include:
- identity verification against official records before any loan is granted;
- bank account verification to confirm the account belongs to the applicant;
- screening against sanctions and politically exposed persons lists as required by FICA;
- monitoring for unusual application and repayment patterns; and
- a defined process for investigating and reporting suspected fraud.
5. How to spot a fake CapVerge
Lending fraud is common in South Africa. Please check the following before you part with any information or money:
Check | What is genuine |
Website | capverge.co.za only. Look for the padlock and check the spelling of the address carefully. |
Correspondence comes from a @capverge.co.za address. We do not use free webmail addresses. | |
NCR registration | NCRCP23705. You can verify any credit provider on the NCR register at www.ncr.org.za. |
Upfront payments | We never require a payment before releasing a loan. |
Banking details | We never change our banking details by email. If you receive such a request, phone us before acting. |
6. What we ask of you
- Use a strong, unique password for your CapVerge account and do not reuse it elsewhere.
- Never share your login details, banking PIN or one-time passwords with anyone, including someone claiming to be from CapVerge.
- Access your account only from devices you trust, and log out on shared devices.
- Keep your contact details current so we can reach you about your account.
- Check your bank statements and tell us promptly about anything you do not recognise.
7. Reporting a security concern
If you believe your account has been compromised, if you receive a suspicious message in our name, or if you have found a security weakness in our systems, contact us immediately:
Channel | Detail |
info@capverge.co.za | |
Security reports | [security@capverge.co.za — mailbox to be created] |
Telephone | [official contact number to be confirmed] |
We investigate every report. If a breach affects your personal information, we will notify you and the Information Regulator in accordance with POPIA.
8. Regulatory standing
Registration | Detail |
Credit provider | Registered with the National Credit Regulator — NCRCP23705 |
Company | CapVerge (Pty) Ltd, registration number 2025/149059/07 |
Data protection | Registered responsible party in terms of POPIA — [Information Officer registration to be confirmed] |
Governing legislation | National Credit Act 34 of 2005; Protection of Personal Information Act 4 of 2013; Financial Intelligence Centre Act 38 of 2001; Consumer Protection Act 68 of 2008 |
Version 1.0 · Effective 27 July 2026 · Next review July 2027.