Skip to content

Security and compliance

Controls the regulator recognises, data that stays where it must

neotra deploys in an in-country cloud region or a jurisdiction the regulator accepts, or on-premises in the institution's data centre, with the same software and upgrade path.

Deployment and design

Cloud deployment
Scales by adding capacity in an in-country region or a jurisdiction the regulator accepts.
On-premises
Installed in the institution's data centre, with the same software and upgrade path as cloud.
Headless design
The core has no fixed user interface, so the neotra app, the institution's own app or a partner's app can sit on top.
Open APIs
Every function the back office uses is available as a documented REST API with an OpenAPI definition.

Security controls

  • Encryption of data in transit with TLS and at rest at the database and storage layer.
  • Web application firewall and API gateway in front of every public endpoint.
  • Static and dependency scanning on every build, a software bill of materials with each release, and an external penetration test before each go-live.
  • Security patches applied within a defined window agreed in the service contract.
  • Card numbers never enter neotra; card data stays with the processor, which keeps neotra outside PCI DSS cardholder data scope.

Pilot exit tests

  • Each pilot product launches by configuration in under one working day.
  • The neotra trial balance reconciles to the incumbent general ledger to the last unit of currency for every day of the pilot.
  • Islamic products pass the Shariah supervisory board's review of configuration, documents and postings.
  • The close of business run completes inside the overnight window at the projected account volume.
  • The penetration test finds no critical or high vulnerability open at go-live.

Regulatory alignment

FrameworkHow neotra supports the institution
Central bank cybersecurity frameworksControl mapping, incident response plan and evidence pack for the regulator's requirements
Cloud and outsourcing instructionsData residency confirmation and outsourcing assessment pack for the central bank
AML/CFT laws and instructionsScreening at onboarding and payment, events to the monitoring system, full audit trail
Personal data protection lawsData inventory, access logging, retention settings and export on request
Regulatory reportingReturn extracts mapped to the central bank's templates per engagement

Volume and performance

Every engagement includes a load test at the institution's three-year projected account count before go-live: peak-hour API traffic and a full close of business run inside the overnight window.

What the platform is built on

neotra runs on a hardened, commercially supported distribution of the Apache Fineract ledger engine, extended with proprietary neotra modules.

Start with a two-hour discovery session

With your business, finance, IT and Shariah teams, we select the modules, the first product line and the pilot's exit tests.

Book a discovery session