Trust & Safety

How Yaqeen keeps
your money safe.

Zero trust is earned, not assumed. Every mechanism on this platform exists because we started by assuming everyone is a scammer — and built defences accordingly.

CNIC Verification — how it works

Every seller on Yaqeen must verify their identity before a single listing goes live. We use NADRA's official Ijazat Aap Ki system — the same system banks use.

What Yaqeen stores
  • Verification token (hash)
  • Last 4 digits of CNIC
  • Name (from NADRA record)
  • Phone number
  • City
What Yaqeen NEVER stores
  • Your full CNIC number
  • CNIC photos
  • Selfie photos
  • Biometric data
  • Financial history
  • NADRA database data

How NADRA consent works

When you verify on Yaqeen, you grant one-time consent via NADRA's Ijazat Aap Ki system. NADRA confirms your identity and returns a verification token to us. We store only that token — not your CNIC data. You can revoke consent at any time via NADRA's portal.

Escrow — your money's journey

When you pay on Yaqeen, your money doesn't go to the seller. It goes into a regulated escrow account, held by NayaPay — an SBP-licensed Electronic Money Institution.

01

Buyer pays

Payment goes directly into NayaPay escrow account — NOT to the seller.

02

Escrow holds

Funds locked. Seller is notified. Seller cannot access funds at this stage.

03

Delivery & confirmation

Buyer receives item and inspects. 48-hour window to raise a dispute.

04

Buyer confirms

Buyer taps 'Confirm Receipt'. Funds instantly released to seller via Raast.

Alt

Dispute raised

Escrow frozen. Evidence collected. Yaqeen trust team resolves in 72h.

Auto-release protection

If you don't confirm or dispute within 72 hours of delivery, funds auto-release to the seller. You'll receive 3 reminders before this happens — via WhatsApp, SMS, and push notification.

Technical security

🔐

TLS 1.3 encryption

All data in transit encrypted end-to-end.

🗄️

AES-256 at rest

All stored data encrypted at rest on AWS.

📵

Phone OTP auth

No passwords. OTP via WhatsApp + SMS, rate-limited.

🕵️

Device fingerprinting

Unusual login patterns trigger reverification.

📋

SOC 2 Type II

Audit in progress. Expected Q3 2026.

🛡️

Cyber insurance

₨ 10M breach coverage with UBL Insurance.

Breach Notification Policy

In the event of a confirmed data breach, Yaqeen will notify all affected users within 72 hours via WhatsApp and email. We will disclose the nature of exposed data, steps taken, and recommended actions. We maintain a dedicated security@yaqeen.pk address. This policy is binding regardless of breach severity.

Fraud we block — and how

Non-PTA devices

Every IMEI checked against PTA DIRBS live database before listing

Identity fraud

CNIC liveness check + NADRA verification blocks fake identities

Item-not-received

Escrow never releases until buyer confirms — no money moves first

Fake product photos

AI photo quality scoring + pre-dispatch video required before payout

Stolen phones

IMEI flagged in stolen device database — listing blocked

OTP bypass attempts

Rate limiting + device fingerprinting detects repeated fake OTPs

Read this month's fraud report

Built on regulated infrastructure

NA

NADRA

Pakistan's national ID authority. Powers CNIC liveness verification via Ijazat Aap Ki.

Sh

Shufti Pro

ISO 27001 certified KYC platform. Handles document verification and biometric matching.

Na

NayaPay

SBP Licensed Electronic Money Institution (EMI). Holds all escrow funds.

Sa

Safepay

PCI-DSS compliant payment gateway for card transactions.

PT

PTA DIRBS

Pakistan Telecommunications Authority device verification system. Checks every IMEI.