Schema-per-tenant isolation
Each MFI has its own PostgreSQL schema. No shared tables, no cross-tenant leakage. Isolation enforced at app and DB level.
Security & compliance
Qredon is built to satisfy the requirements of regulators, auditors and MFI executives responsible for sensitive financial data.
Each addressing a concrete risk a modern MFI is exposed to.
Each MFI has its own PostgreSQL schema. No shared tables, no cross-tenant leakage. Isolation enforced at app and DB level.
Three distinct JWT systems (Admin, MFI, Borrower). OTP for borrowers, hashed passwords for the rest. Strict rate limiting.
TLS 1.3 on all connections. AES-256 encryption of sensitive data at rest. Secrets managed via dedicated vault.
Every action is tracked: who, when, what, before/after values. 10-year retention, CSV export for regulatory audits.
Right to be forgotten, data export, anonymization. Configurable data retention. Traced consent. Internal DPO reachable.
Pre-configured regulatory settings for the Central Bank of Tunisia. Ready-to-file PAR reports.
We can provide detailed architecture documentation, a security test plan and our audit results.