Skip to Content
Cross-cutting · Trust

Trust, built into the platform.

Real-time fraud, financial-crime controls, lawful intercept and privacy — engineered in, not bolted on. Secret material is encrypted at rest, webhooks fail closed, and the audit trail is tamper-evident by construction.

POPIA · GDPR · HIPAAISO 27001:2022ETSI · CALEA LIFernet · Vault · HSM
3
privacy regimes · POPIA · GDPR · HIPAA
ISO
27001:2022 ISMS
Real-time
AI fraud detection
Hash-chain
tamper-evident audit
HSM
Vault-backed key management
Defence in depth

Six lines of defence.

Security is layered across the platform — access, encryption, fraud, financial crime, lawful intercept and privacy each own a line, so a gap in one is caught by the next.

01 · Access

Who gets in

Centralised RBAC and GSMA Mobile Connect SIM-based 2FA gate every action.

security_access_controlmobile_connect_2fa
02 · Encrypt

Protect at rest

Fernet field encryption with HashiCorp Vault / HSM-backed master keys.

telecom_encrypted_fieldstelecom_vault
03 · Detect

Catch fraud live

AI network oversight and a Kafka streaming worker flag toll-fraud, simbox and IMSI patterns.

mobile_ai_oversightmobile_fraud_streaming
04 · Screen

Financial crime

Wallet AML screening, CDD profiling and SARB reporting.

mobile_wallet_aml
05 · Intercept

Lawful access

CALEA/ETSI/3GPP warrant and target lifecycle with a tamper-evident audit.

lawful_interceptli_mediation
06 · Comply

Privacy & audit

POPIA/GDPR/HIPAA data-subject workflows, ISO 27001 ISMS and generic audit logging.

security_popia_complianceaudit_logging
The controls

Security as a set of modules.

Each control is a focused module reused across every vertical — so a new module inherits the same guarantees.

Identity & Access 2 modules

Authenticate strongly; authorise precisely.

Access control (RBAC)

Centralised role and permission management.

security_access_control

Mobile Connect 2FA

GSMA Mobile Connect SIM-based two-factor authentication.

mobile_connect_2fa

Encryption & Secrets 2 modules

Nothing sensitive sits in plaintext.

Encrypted fields

Fernet encryption mixin for sensitive credential fields.

telecom_encrypted_fields

Vault & HSM

HashiCorp Vault master-key + Transit (HSM-backed) integration.

telecom_vault

Fraud Detection 3 modules

See attacks as they happen.

AI oversight

AI-powered real-time network oversight and fraud detection.

mobile_ai_oversight

Fraud streaming

Bridge to a Kafka-based real-time fraud worker.

mobile_fraud_streaming

Fraud mediation

MNO fraud detection and mediation with OCS integration.

mobile_core_fraud_med

Financial Crime 1 modules

Meet the money regulators.

Wallet AML

AML screening, CDD profiling and SARB reporting for the mobile wallet.

mobile_wallet_aml

Lawful Intercept 3 modules

Warranted access, provably controlled.

Warrant lifecycle

CALEA/ETSI/3GPP warrant and target lifecycle with hash-chain audit.

lawful_intercept

ISP LI handover

ETSI ES 201 671 handover interface accepting LEA intercept orders.

isp_lawful_intercept

LI mediation

Standalone mediation function for the intercept pipeline.

li_mediation

Privacy & Governance 4 modules

Prove compliance, don't just claim it.

Privacy compliance

POPIA/GDPR/HIPAA DSR, consent and breach notification.

security_popia_compliance

ISO 27001 ISMS

Information Security Management System for ISO 27001:2022.

security_isms_compliance

Audit logging

Generic audit log with archival and restore.

audit_logging

ICASA QoS

End-user service-charter QoS metrics and quarterly reporting.

mobile_icasa_qos
Tamper-evident by construction

An audit trail that can't be quietly edited.

Lawful-intercept records are un-deletable by design, and the audit log is a per-company SHA-256 hash chain — alter any entry and every later hash breaks, so tampering is detectable, not silent.

lawful_intercept
Standards & interop

Compliant against the real frameworks.

Built to the privacy, security and lawful-interception standards auditors and regulators actually test against.

POPIAGDPRHIPAAISO 27001:2022ETSI ES 201 671CALEA3GPP LIFICA / SARB
Part of the platform

Compliance as a feature, not a bolt-on.

Fraud, financial crime, lawful intercept and privacy are first-class parts of the platform — so every operator starts secure by default.

Operator Platform
271 modules · ~590k LOC · Odoo 19 Community / Enterprise