Security architecture
Threat modelling, trust boundaries and control design agreed before development begins.
Every control below is decided before development begins and proven before release. Security is part of the architecture, not a layer added at the end.
Threat modelling, trust boundaries and control design agreed before development begins.
Role based permissions, multi factor authentication, segregation of duties and delegated authority.
Protection of data in transit and at rest, with managed keys and certificate lifecycles.
Vulnerability assessment, penetration testing, code review and a prioritised fix plan.
Centralised logging, alerting, audit trails and a rehearsed incident response process.
POPIA and GDPR readiness, retention policy, backup, disaster recovery and recovery testing.


Findings fixed before go live, not logged for a later sprint
The maker of a transaction cannot be its checker or its payer, enforced in the platform
Every decision and payment traceable to a user, a rule and a timestamp
POPIA and GDPR, with evidence packs an auditor will accept
Disaster recovery designed and then actually tested, not assumed
Third party penetration testing arranged on request


We deliver all three together, because the application, the data it holds and the network it travels on have to be designed against the same requirements.

