Security
Built so your money lands where you meant it to
Security here is mostly unglamorous: confirm who you are paying, authorise it properly, and write down what happened. Everything on this page is behaviour the product has today.
A PIN on every payment
Nothing leaves your balance without a transaction PIN only you know — separate from the password you sign in with.
Second factor on large amounts
Past a set threshold, a payment asks for a one-time code sent to your registered email before it goes anywhere.
Verified once, properly
Accounts are identity-checked a single time. That is what lets a dedicated account number be issued in your own name.
Unlock the way you already do
Sign in with your phone’s own biometrics, and idle sessions lock themselves rather than sitting open on a table.
Told the moment someone signs in
A new sign-in emails you straight away, with a one-tap way to lock the account if it was not you.
A complete trail
Every payment, credit and reversal is recorded against your account with a reference you can quote to support.
What we ask of you
- Keep your PIN to yourself. No one from Mdiho will ever ask for it — not by phone, email or chat.
- Check the name before you pay. We show you the registered meter or decoder name for a reason. If it looks wrong, stop there.
- Act on sign-in alerts. If you get one you did not expect, lock the account from the email and tell us.
Reporting something
If you believe your account has been accessed by someone else, or you have found a vulnerability, email us and we will act on it. Include the transaction reference from your receipt where one applies — every payment has one, and it lets us trace exactly what happened rather than guessing.
Something looks wrong?
Get in touch with the reference from your receipt and we will trace it end to end.