Skip to main content

Governance & Security

Comprehensive approach to governance and security of the NDCI platform includes governance, KYC/AML integration, and operational security.

Governance

G1

Prospectus/listing workflow: roles, approvals, versioning, dating

G2

Segregation of duties (SoD), 4-eyes principle, CAB (Change Advisory Board)

G3

Audit and records: hash/anchor, retention policies

G4

Contractual framework: MoU (UAT/SIM access), DPA

KYC/AML

K1

External providers, privacy-by-design, no unnecessary data

Operations & Security

O1

IAM (OIDC, SSO, RBAC/ABAC, least privilege)

O2

Network (mTLS, WAF, rate-limiting, DDoS protection)

O3

Data (encryption, HSM/KMS, key rotation, field tokenization)

O4

Vulnerability management (SAST/DAST, SBOM, patching, 2× yearly pentest)

O5

Observability (SLO/SLA, tracing, logs; MTTR ≤2h; availability ≥99.5% in pilots)

O6

BCP/DR (geo-redundancy, drills, runbooks; RTO ≤4h, RPO ≤1h)

Want to Learn More?

Contact us for detailed documentation on NDCI governance, security, and compliance framework.

Schedule UAT Call