Moneyout Application Portfolio
Complete inventory of all applications and payment service systems — including application name, purpose, in-house vs. outsourced classification, operating system, database, and primary/secondary system information. Prepared in response to auditor inquiry under Law No. 6493.
Executive Summary
Purpose, scope, and document control
Purpose
This document provides auditors with a complete, structured inventory of all applications and systems operated by Moneyout Electronic Money and Payment Services Inc. in connection with its licensed payment services and electronic money activities. It is prepared in direct response to the audit inquiry: "Portfolio of products related to the application and payment services provided — including application name, purpose of use, whether in-house or outsourced, operating system and database information, and primary and secondary system information."
System Landscape
The Moneyout platform is organized into four categories covering 13 systems in total:
- AApplications — Customer-facing mobile wallet app (React Native) and the Admin Dashboard — the core management system for Money Transfer, Wallet, and POS modules (Angular 18).
- BCore Payment & Backend Systems — Laravel-based REST API (payment engine), AML/compliance (Fineksus PayGate Inspector), accounting (Tiger 3 / Logo), and POS (Magicpay).
- CSupport & Operations Systems — Help Center / ticketing system, Orchestra task management, and VDR (Virtual Data Room).
- DInfrastructure & Security Systems — Fortinet Firewall, SSL VPN, SIEM (Crypttech/Arrtech), Active Directory (IAM), and Turkcell Cloud hosting/backup.
Document Control
| Field | Value |
|---|---|
| Document Title | Moneyout — Application & Payment Services Portfolio · Auditor Response |
| Version | 1.0 |
| Date | February 20, 2026 |
| Classification | Confidential — For Audit Use Only |
| Legal Framework | Law No. 6493 on Payment and Security Settlement Systems, Payment Services, and Electronic Money Institutions |
| Company Code | 00917 |
| Owner | Risk and Compliance Unit |
| Audience | External Auditors, TCMB, Compliance Officers, Internal Control |
Application Overview
All 13 systems at a glance
A.1 — MoneyOut Wallet (Mobile Application)
Customer-facing digital wallet — iOS & Android
| Application Name | MoneyOut Wallet |
| Purpose of Use | Digital wallet enabling customers to: load/withdraw balance, perform domestic transfers (FAST/EFT), send international money transfers, pay bills via Paycell, make wallet-to-wallet transfers, and manage their electronic money account |
| In-House / Outsourced | In-House — Developed, maintained, and operated entirely by Moneyout internal information systems team |
| Platform | iOS (Apple App Store) & Android (Google Play Store) |
| Technology / Framework | React Native Expo (cross-platform mobile framework) |
| Operating System | iOS (Apple) / Android (Google) — client side. Server-side: Ubuntu Server (Linux) |
| Database | Shares the core system databases: MS SQL Server 2022 (primary) · MySQL (analytics) · Redis (caching/queues) |
| Key Features | Multi-language support (TR/EN/AR) · Biometric authentication (Face ID / fingerprint) · NFC Turkish ID (TCKN) verification · Real-time push notifications (FCM) · FAST/EFT domestic transfers · International money transfer · Bill payment |
| Primary System | Production — Tekirdağ Data Center (Turkcell Cloud / Superonline) |
| Secondary / DR System | Disaster Recovery — Ankara Data Center (Turkcell Cloud) |
A.2 — Admin Dashboard (Core Management System)
Central management platform for money transfer, wallet & POS modules
| Application Name | MoneyOut Admin Dashboard (Core Management System) |
| Purpose of Use | Core management system for the entire Moneyout platform. Provides full operational control over: the Money Transfer module (domestic & international transfers, EFT, cash pickup, approval pool), the Wallet module (wallet accounts, deposits/withdrawals, wallet-to-wallet transfers, KYC, customer management), and the POS module (merchants, terminals, payment profiles, 3D-secure transactions). Also covers AML/risk monitoring, financial reporting, agent management, commission configuration, and system settings. |
| In-House / Outsourced | In-House — Developed, maintained, and operated entirely by Moneyout internal information systems team |
| Platform | Web-based (browser-agnostic) — accessed via HTTPS |
| Technology / Framework | Angular 18 (frontend) · NgRx (state management) · Angular Material · ngx-translate |
| Operating System | Runs on Ubuntu Server (Linux) — served via web server (production environment) |
| Database | Shares core system databases: MS SQL Server 2022 (primary) · MySQL (analytics/reporting) · Redis (caching) |
| Key Features | Multi-role access (Admin, Operator, SuperOperator, Teller, Agent, Risk Officer, Accountant, Internal Control) · Real-time analytics & reporting · Transaction monitoring dashboard · 59 active fraud/security rule management · Customer, agent, and representative management |
| Access Control | Laravel Sanctum token authentication · Checkip (IP allowlist) · Checkworktime (working hours restriction) · Role guards: Isoperator, IsAdmin |
| Primary System | Production — Tekirdağ Data Center (Turkcell Cloud / Superonline) |
| Secondary / DR System | Disaster Recovery — Ankara Data Center (Turkcell Cloud) |
B.1 — Core Payment Engine (Backend API)
Central processing engine for all payment & e-money operations
| Application Name | MoneyOut Core Payment System (Backend REST API) |
| Purpose of Use | Central business logic engine for all payment transactions and electronic money operations: FAST/EFT domestic transfers, international money transfers, digital wallet management, card management, KYC processing, AML/risk evaluation, accounting & settlement, commission calculation, and notification delivery |
| In-House / Outsourced | In-House — Developed, maintained, and operated entirely by Moneyout internal information systems team |
| Technology / Framework | Laravel 10 (PHP) — RESTful API architecture · Laravel Sanctum (API authentication) · WebSocket (real-time communication) |
| Operating System | Ubuntu Server (Linux) |
| Primary Database | Microsoft SQL Server 2022 — primary transactional database for all core operations |
| Secondary Database | MySQL — analytics and reporting database |
| Cache / Queue | Redis + Supervisor — high-performance caching and job queue processing |
| Containerization | Docker — container orchestration for deployment |
| Scheduled Tasks | CronJobs — automated task scheduling for batch processes |
| Key Modules | Wallet Engine · Transfer Engine (FAST/EFT/International) · Card Management · Compliance Engine · Accounting & GL · Notification Engine · Approval Pool · Commission Engine · KYC Engine |
| Encryption | AES-256 (data at rest) · TLS 1.3 (data in transit) · HSM (key management) |
| Primary System | Production — Tekirdağ Data Center (Turkcell Cloud / Superonline İletişim Hiz.A.Ş.) |
| Secondary / DR System | Disaster Recovery — Ankara Data Center (Turkcell Cloud) — activated in case of production failure, cyber attack, or disaster |
| Backup | Daily backups — stored securely in environment independent of main systems (Turkcell Dijital İş Servisleri A.Ş.) |
B.2 — AML / Compliance System (Fineksus PayGate Inspector)
Transaction monitoring, sanctions screening & risk scoring
| Application Name | PayGate Inspector (Fineksus) |
| Purpose of Use | Anti-money laundering (AML) transaction monitoring; sanctions and blacklist screening (domestic & international); automated customer risk scoring; generation of compliance alerts for review by the Compliance Unit. 59 active security and fraud prevention rules are enforced through this system. |
| In-House / Outsourced | Outsourced — Provided by Fineksus Bilişim ve Çözümleri Ticaret A.Ş. under a PayGate Inspector API + Annual Usage Service Agreement |
| Integration Method | REST API — integrated directly into the Core Payment Engine (Laravel backend) |
| Operating System | SaaS — vendor-managed infrastructure (not hosted by Moneyout) |
| Database | Vendor-managed — not applicable to Moneyout infrastructure |
| Key Features | 59 active fraud/security rules · Sanctions list matching (80%+ threshold triggers Compliance Unit approval) · Customer risk score calculation (high-risk triggers compliance review) · Real-time alert generation · Transaction flagging, holding, and blocking |
| Primary System | Fineksus-hosted infrastructure (vendor responsibility) |
| Secondary / DR System | Vendor responsibility — covered under the service agreement with Fineksus |
B.3 — Accounting System (Tiger 3 / Logo)
General ledger, financial reporting & e-Government integration
| Application Name | Tiger 3 (Logo Accounting Program / Logo ERP) |
| Purpose of Use | General accounting, double-entry bookkeeping, general ledger (GL) management, reconciliation, financial reporting, and e-Government product integration (e-Invoice, e-Archive) |
| In-House / Outsourced | Outsourced — Software provided by Logo Software; support and maintenance services provided by Antsoft Bilişim Hizmetleri Tic.Ltd.Şti. (Tiger 3 support + e-Government products support service) |
| Operating System | Windows Server |
| Database | Logo proprietary database (SQL Server-based — vendor managed) |
| Integration | Verified accounting vouchers from the Core Payment System are synced to Tiger 3 for official accounting records |
| Primary System | On-premise / internal network server |
| Secondary / DR System | Data backed up via Turkcell Cloud Backup Service (Turkcell Dijital İş Servisleri A.Ş.) — remote cloud backup over the internet |
B.4 — Virtual POS System (Magicpay)
Point-of-sale payment processing for merchants & agent representatives
| Application Name | MoneyOut POS (Magicpay POS Software) |
| Purpose of Use | Point-of-sale card and digital payment processing for merchants and agent representative locations; enables accepting payments from customers at physical points of service |
| In-House / Outsourced | Outsourced (Software) — POS software installation, integration, maintenance, update, and support services provided by Magicpay Teknoloji A.Ş. |
| Platform / Operating System | Android-based POS terminals |
| Database | Integrated with Core Payment System database (MS SQL Server 2022) — transaction data is stored centrally |
| Primary System | Integrated with Core Payment System — Production: Tekirdağ Data Center |
| Secondary / DR System | Via Core System Disaster Recovery — Ankara Data Center |
C.1 — Help Center / Ticketing System
Customer support & internal helpdesk
| Application Name | Moneyout Help Center / Ticketing System |
| Purpose of Use | Customer support ticketing and internal helpdesk management — enables tracking, routing, and resolution of customer inquiries, complaints, and internal operational requests |
| In-House / Outsourced | In-House — Developed and operated by Moneyout |
| Operating System | Ubuntu Server (Linux) — hosted on Turkcell Cloud infrastructure |
| Database | Integrated with core platform database infrastructure |
| Primary System | Production — Tekirdağ Data Center (Turkcell Cloud) |
| Secondary / DR System | Disaster Recovery — Ankara Data Center (Turkcell Cloud) |
C.2 — Orchestra (Task & Project Management)
Internal project tracking and operational task management
| Application Name | Orchestra |
| Purpose of Use | Internal project and task management system used by Moneyout teams for operational task tracking, project milestone management, development sprints, and compliance task assignments — functionally equivalent to Jira |
| In-House / Outsourced | In-House — Developed and operated by Moneyout |
| Users | Internal staff — Information Systems, Operations, Risk & Compliance, Internal Control departments |
| Operating System | Ubuntu Server (Linux) |
| Database | Integrated with core platform database infrastructure |
| Primary System | Production — Tekirdağ Data Center (Turkcell Cloud) |
| Secondary / DR System | Disaster Recovery — Ankara Data Center (Turkcell Cloud) |
C.3 — VDR — Virtual Data Room
Secure document repository for auditors, regulators & investors
| Application Name | Moneyout VDR (Virtual Data Room) |
| Purpose of Use | Secure, access-controlled document repository for sharing confidential company documents with authorized external parties (auditors, TCMB, investors) and for internal document management. Provides organized, traceable access to audit documents, financial statements, compliance records, and due-diligence materials. |
| In-House / Outsourced | In-House — Developed and operated by Moneyout |
| Operating System | Ubuntu Server (Linux) |
| Database | Integrated with core platform database infrastructure |
| Access Control | Role-based access — Authorized internal staff, external auditors, and regulators only. Access is tracked and logged. |
| Primary System | Production — Tekirdağ Data Center (Turkcell Cloud) |
| Secondary / DR System | Disaster Recovery — Ankara Data Center (Turkcell Cloud) |
D.1 — Firewall System (Fortinet)
Network perimeter protection, segmentation & intrusion prevention
| Application Name | Fortinet Firewall (Next-Generation Firewall — NGFW) |
| Purpose of Use | Network perimeter protection, VLAN segmentation, IDS/IPS intrusion detection and prevention, deep packet inspection, and controlled internal/external traffic management |
| In-House / Outsourced | Outsourced (Hardware + Support) — Hardware and software provided by Fortinet; installation, maintenance, version upgrades, and security updates managed by Arrtech Teknoloji Yatırım A.Ş. (Crypttech/Arrtech products service agreement) |
| Operating System | FortiOS (Fortinet proprietary operating system) |
| Database | Not applicable — network security appliance |
| Primary System | Production — Tekirdağ Data Center |
| Secondary / DR System | Ankara Data Center (DR) |
D.2 — VPN System (SSL VPN / FortiClient)
Secure remote access with mandatory multi-factor authentication
| Application Name | SSL VPN (Fortinet FortiClient) |
| Purpose of Use | Secure encrypted remote access channel for authorized personnel connecting to internal systems and infrastructure from outside the office network |
| In-House / Outsourced | Outsourced (Hardware + Support) — Managed by Arrtech Teknoloji Yatırım A.Ş. |
| Authentication | Mandatory Multi-Factor Authentication (MFA): time-based OTP tokens + biometric verification + certificate-based authentication |
| Operating System | FortiOS (Fortinet proprietary) |
| Primary System | Tekirdağ Data Center |
| Secondary / DR System | Ankara Data Center (DR) |
D.3 — SIEM & Monitoring System
Centralized security event management & real-time threat detection
| Application Name | SIEM — Security Information and Event Management System |
| Purpose of Use | Centralized collection of all system, network, and security logs; real-time correlation and threat detection; automated alerts for suspicious activities; log integrity maintenance with timestamps; 24/7 security monitoring |
| In-House / Outsourced | Outsourced (Support) — Solution provided via Arrtech Teknoloji Yatırım A.Ş. (Crypttech/Arrtech products service agreement) |
| Operating System | Linux-based |
| Key Capabilities | All critical system/network/security logs collected centrally · Suspicious activities detected via alarm and correlation rules · Log integrity maintained with timestamps · Real-time alerts to security/compliance team |
| Primary System | Tekirdağ Data Center |
| Secondary / DR System | Ankara Data Center (DR) |
D.4 — Identity & Access Management (Active Directory)
Centralized user authentication, RBAC & Group Policy
| Application Name | Microsoft Active Directory (Identity & Access Management) |
| Purpose of Use | Centralized user authentication and authorization for all internal systems; role-based access control (RBAC); Group Policy management for security compliance; automated user provisioning and deprovisioning; least-privilege access principle enforcement |
| In-House / Outsourced | In-House (managed internally). On-demand technical support for system and network issues provided by Ldap Bilgi Teknolojileri Danışmanlık Ve Dış. Tic. Ltd.Şti. |
| Operating System | Windows Server |
| Database | Active Directory database (NTDS.dit) — Microsoft proprietary |
| Primary System | Tekirdağ Data Center |
| Secondary / DR System | Ankara Data Center (DR) |
D.5 — Cloud Infrastructure & Backup (Turkcell)
Production hosting, virtualization & cloud backup — Tekirdağ + Ankara
| Application Name | Turkcell Virtual Data Center (Production) + Turkcell Cloud Backup |
| Purpose of Use | (1) Virtual Data Center: Hosting of all production servers in an enterprise-grade virtualized cloud environment with automatic scaling and high availability. (2) Cloud Backup: Remote backup of all critical server data via software-based backup over the internet to Turkcell data center. |
| Hosting — In-House / Outsourced | Outsourced — Virtual data center provided by Superonline İletişim Hiz.A.Ş. (Turkcell group company). Servers physically located at Turkcell data center. |
| Backup — In-House / Outsourced | Outsourced — Cloud backup service provided by Turkcell Dijital İş Servisleri A.Ş. |
| Operating System | Hosted VMs run Ubuntu Server (Linux) |
| Backup Frequency | Daily — production system backups taken daily and stored securely independent of main systems |
| Primary System (Production) | Tekirdağ Data Center — all live systems hosted here |
| Secondary / DR System | Ankara Data Center — Disaster Recovery. Activated in case of failure, cyber attack, or disaster to quickly restore critical systems. |
Database Summary
All databases used across the Moneyout platform
| # | Database | Type | Purpose | Role | Location |
|---|---|---|---|---|---|
| 1 | MS SQL Server 2022 | Relational (RDBMS) | Core transactional data — wallets, transfers, customers, compliance, accounting | Primary | Tekirdağ (Prod) · Ankara (DR) |
| 2 | MySQL | Relational (RDBMS) | Analytics, reporting, secondary data storage | Secondary | Tekirdağ (Prod) · Ankara (DR) |
| 3 | Redis | In-memory / Key-Value | Queue processing, session caching, real-time operations | Supporting | Tekirdağ (Prod) · Ankara (DR) |
Full Infrastructure Summary Table
Complete inventory — all 13 systems in one view
| # | Application / System | Category | Technology | In-House / Outsourced | OS | Database | Primary Location | DR Location |
|---|---|---|---|---|---|---|---|---|
| 1 | 📱 MoneyOut Wallet Mobile App |
Customer App | React Native Expo |
In-House | iOS / Android (client) · Ubuntu Server | MS SQL Server 2022 · MySQL · Redis | Tekirdağ (Turkcell Cloud) | Ankara (Turkcell Cloud) |
| 2 | 🖥️ Admin Dashboard Core Management System |
Core System | Angular 18 |
In-House | Ubuntu Server (Linux) | MS SQL Server 2022 · MySQL · Redis | Tekirdağ (Turkcell Cloud) | Ankara (Turkcell Cloud) |
| 3 | ⚙️ Core Payment Engine Backend API |
Core System | Laravel 10 (PHP) |
In-House | Ubuntu Server (Linux) | MS SQL Server 2022 · MySQL · Redis | Tekirdağ (Turkcell Cloud) | Ankara (Turkcell Cloud) |
| 4 | 🔍 AML / Compliance PayGate Inspector |
Core System | REST API (Fineksus) | Outsourced — Fineksus | Vendor-managed (SaaS) | Vendor-managed | Fineksus Infrastructure | Vendor responsibility |
| 5 | 📒 Accounting System Tiger 3 / Logo |
Core System | Tiger 3 (Logo Software) | Outsourced — Logo / Antsoft | Windows Server | SQL Server (vendor-managed) | On-premise | Turkcell Cloud Backup |
| 6 | 🛒 Virtual POS Magicpay POS |
Core System | Magicpay POS Software | Outsourced — Magicpay | Android (POS terminals) | Via Core System (MS SQL Server) | Integrated with Tekirdağ | Via Core System DR (Ankara) |
| 7 | 🎫 Help Center / Ticketing Internal Operations |
Support & Ops | In-House Web App | In-House | Ubuntu Server (Linux) | Core platform DB | Tekirdağ (Turkcell Cloud) | Ankara (Turkcell Cloud) |
| 8 | 🎼 Orchestra Task Management |
Support & Ops | In-House Web App | In-House | Ubuntu Server (Linux) | Core platform DB | Tekirdağ (Turkcell Cloud) | Ankara (Turkcell Cloud) |
| 9 | 🗄️ VDR Virtual Data Room |
Support & Ops | In-House Web App | In-House | Ubuntu Server (Linux) | Core platform DB | Tekirdağ (Turkcell Cloud) | Ankara (Turkcell Cloud) |
| 10 | 🔥 Fortinet Firewall + VPN NGFW + SSL VPN |
Infrastructure | Fortinet / FortiOS | Outsourced — Arrtech | FortiOS (proprietary) | N/A | Tekirdağ | Ankara |
| 11 | 👁️ SIEM & Log Management Security Monitoring |
Infrastructure | Crypttech SIEM (Arrtech) | Outsourced — Arrtech / Crypttech | Linux-based | N/A | Tekirdağ Data Center | Ankara Data Center |
| 12 | 👤 Active Directory (IAM) Identity Management |
Infrastructure | Microsoft Active Directory | In-House (ext. support: Ldap Bilgi) | Windows Server | NTDS.dit (AD proprietary) | Tekirdağ Data Center | Ankara Data Center |
| 13 | ☁️ Turkcell Cloud + Backup Hosting + Backup |
Infrastructure | Turkcell Cloud / Superonline | Outsourced — Superonline / Turkcell | Ubuntu Server (Linux) — VMs | N/A | Tekirdağ Data Center | Ankara Data Center |
Notes & Declaration
Compliance declaration and document information
Notes
- All projects and systems are reviewed and approved at Board of Directors level.
- The Information Systems department (5 dedicated staff) is responsible for technical operation and maintenance of all in-house systems.
- Third-party (outsourced) systems are governed by formal service agreements. Vendor responsibilities for DR and backup are covered within respective contracts.
- All in-house applications share the production environment at Tekirdağ and the disaster recovery environment at Ankara, both hosted on Turkcell Cloud (Superonline İletişim Hiz.A.Ş.).
- Material changes to the application landscape will be reported to the Compliance Unit and to TCMB where required.
- The VDR (Virtual Data Room) is available for auditor access — credentials can be provided upon request.
Document Information
| Field | Value |
|---|---|
| Company | Moneyout Electronic Money and Payment Services Inc. |
| Company Code | 00917 |
| Tax No. | 622 175 8445 |
| Address | Eşentepe Mah. Büyükdere Cad. Metrocity No: 171 İç Kapı No: 15 Şişli/İstanbul, Turkey |
| Date | February 20, 2026 |
| Classification | Confidential — For Audit Use Only |
Confidential — For Audit Use Only · Moneyout Electronic Money and Payment Services Inc. · February 2026