1) Is the API limited to types of transactions or do you host configuration information? For example, I've often wished for a bank account that would look at my outgoings and some criteria that I've set, and then allocate some monies to savings or investments on a percentage basis rather than an absolute number. Are those calculations something I'd need to do at my end and then send you a bunch of API calls to make the transaction, or would they run as bots on your server? Sorry if that's not very clear
2) Will you impose tight or narrow restrictions on who can open accounts? For example in the USA many banks require an SSN to open an account and won't accept an ITIN (another kind of tax ID sometimes issued to immigrants), placing millions of people outside the banking system and thus making it that much more difficult for them to pay bills etc.
3) Will your service have access to the SWIFT network for international transfers or are you subject to restrictions while you prove some sort of banking bona fides? I don't know anything about banking relationships in South Africa or so but I've noticed the US is very aggressive about limiting transaction access for anything that looks like it could be remotely connected to crime of any kind, and I have sometimes had the impression that US banks are very 'suspicious' of anything that might coincidentally pose a threat to their business model.
I want to wish you a lot of luck and am very excited to see where this might go. I've never enjoyed dealing with money or finance, and get no more enjoyment out of being paid than I do out of paying bills. Financial chores are about as much fun as cleaning a toilet and the idea of being able to reduce the amount of time spent on dealing with money without putting myself at financial risk sounds heavenly.
(1) A mixture of the two. We do allow you to write code that we host for you, to make prototyping (or building small features) easier and quicker, and you can access it all through the API, so you could do everything through a few https calls. (All account transactions are available to you)
(2) We try our best to make everything as seamless as possible, but we still have to comply with local regulations. We're working hard to create the best user experience possible given the tightly controlled environment we're in.
(3) That's part of the plan, yes :)
I'm interested in two pieces of data we couldn't get there, but that I had really high hopes for.
1) Dynamic merchant-type filtering before auth. For example, if tom has spent 50$ on food this month, all merchants that identify as "food" will fail auth on further transaction attempts. I'm not sure if these are still called MCCs outside of the US, or "merchant codes".
2) Level 3/line item receipt data. For example, instead of showing I spent 5.00 at QuikEMart, it shows 2.50 on soda, 2.00 candy bar, 0.50 tax.
Will your platform offer that level of control/visibility?
- for the stack was there specific criteria why certain languages where chosen in your use cases?
are there any API rate limits for clients?
are there any current plans on mitigating DDOS or other malicious attacks?
2016 has been a hard year for banks and hacking specifically the story about Bangladesh. The trend seems that this will become more likely as we move towards a full online infrastructure. For banking this is another layer where vulnerabilities can come up are there are plans in place for this?
I'm not affiliated with Root, but the bank they are partnering with (Standard Bank of South Africa) was also hacked in 2016 and defrauded of R300 million ($16 million) via withdrawals from ATMs in Japan[1]. I'm sure they are acutely aware of the need for security.
1. http://city-press.news24.com/Business/standard-bank-r300m-fr...
Separately, looking to make this a platform for other vendors to issue cards? E.g., so another company can add logic for say, a teenager's card that the parents manage, and use your platform for this?
Our banking laws are favorable to startups; I could start my own bank, if I wanted to, for little more than the cost of a business license. Many merchants run their own little micro-banks, partly because of the aforementioned problem. Please help :)
- Do you have programmable virtual credit card numbers?
- Have you considered virtual bank account numbers as well? For example, I have had issues with organizations continuing to deduct from my account via ACH after stopping service. If I had a virtual bank account number that could be deleted, those rascals could be stopped in their tracks the moment I make the call saying "you are no longer authorized to deduct from my account". With the current system banks still let the unauthorized ACH transactions slide.
Marqueta can do this. You can issue CC's via api, and then fund them with Visa direct. It's amazing.
Unless things have changed recently, please watch out for the money laundering laws if you are in the USA. It is easier than you might think for absolutely innocent people to fall foul of them, making life miserable (speaking from experience).
https://edfine.io/blog/2015/12/20/how-bofa-froze-my-account-...
2) What are your plans for supporting other languages? (cough Ruby cough)
3) How would I make a script integrate with a 3rd service?
In all seriousness, I would be fairly worried running someone else's code on my bank account unless it was very straightforward. Even forgoing malice and incompetence, there's plenty of "wow, that's a crazy interaction between systems that wasn't obvious" to go around.
Can this interact with FNB or ABSA accounts? Is it international? In short, what are the limits?
Also, I just want to say this is really cool. I've wanted something like this for ages.
I think tech people vulnerable to buzzwordism have an instinctive response to respond to any mention of money with "blockchain!", even though it's really only useful in this context for decentralized payment systems (i.e. not for banks). The only place banks might want to use blockchains is for low-trust inter-bank settlement.
edit: if it is the case, I would be excited to see some docs
Seems legit. Also, I hope that CC number on your top background image is flagged to never be handed out to a real customer ;)
Otherwise this looks promising. I hope to see something like this in the USA soon!
Would that be possible with your API?
I'm not sure what Standard Bank is doing with regards to 3DS, but it would certainly be neat if its implementation were programmable as well.