Security and compliance
Controls the regulator recognises, data that stays where it must
neotra deploys in an in-country cloud region or a jurisdiction the regulator accepts, or on-premises in the institution's data centre, with the same software and upgrade path.
Deployment and design
- Cloud deployment
- Scales by adding capacity in an in-country region or a jurisdiction the regulator accepts.
- On-premises
- Installed in the institution's data centre, with the same software and upgrade path as cloud.
- Headless design
- The core has no fixed user interface, so the neotra app, the institution's own app or a partner's app can sit on top.
- Open APIs
- Every function the back office uses is available as a documented REST API with an OpenAPI definition.
Security controls
- Encryption of data in transit with TLS and at rest at the database and storage layer.
- Web application firewall and API gateway in front of every public endpoint.
- Static and dependency scanning on every build, a software bill of materials with each release, and an external penetration test before each go-live.
- Security patches applied within a defined window agreed in the service contract.
- Card numbers never enter neotra; card data stays with the processor, which keeps neotra outside PCI DSS cardholder data scope.
Pilot exit tests
- Each pilot product launches by configuration in under one working day.
- The neotra trial balance reconciles to the incumbent general ledger to the last unit of currency for every day of the pilot.
- Islamic products pass the Shariah supervisory board's review of configuration, documents and postings.
- The close of business run completes inside the overnight window at the projected account volume.
- The penetration test finds no critical or high vulnerability open at go-live.
Regulatory alignment
| Framework | How neotra supports the institution |
|---|---|
| Central bank cybersecurity frameworks | Control mapping, incident response plan and evidence pack for the regulator's requirements |
| Cloud and outsourcing instructions | Data residency confirmation and outsourcing assessment pack for the central bank |
| AML/CFT laws and instructions | Screening at onboarding and payment, events to the monitoring system, full audit trail |
| Personal data protection laws | Data inventory, access logging, retention settings and export on request |
| Regulatory reporting | Return extracts mapped to the central bank's templates per engagement |
Volume and performance
Every engagement includes a load test at the institution's three-year projected account count before go-live: peak-hour API traffic and a full close of business run inside the overnight window.
What the platform is built on
neotra runs on a hardened, commercially supported distribution of the Apache Fineract ledger engine, extended with proprietary neotra modules.
Start with a two-hour discovery session
With your business, finance, IT and Shariah teams, we select the modules, the first product line and the pilot's exit tests.