Skip to content

Systems for banks, NGOs and government

Since 2017 we have built core banking, payments, identity and beneficiary systems for financial institutions, humanitarian organisations and the public sector. This page is for your architecture, security and procurement teams.

For institutions that answer to regulators, donors and the public

See our work

Five stages, each one signed off by you

Every engagement follows the same path. Each stage ends with something your team can review and approve before the next one starts.

  1. 1

    Discovery

    Workshops with your business, IT, risk and compliance teams. We map the current process and systems, agree the scope and the risks, and put both in writing.

    You getScope, plan and a written proposal

  2. 2

    Architecture

    The solution design, the integration contracts with your core systems, and the security and data-protection design: where data lives, who can see it and how access is logged.

    You getAn architecture your team has reviewed

  3. 3

    Build

    Short cycles, each ending in a working demonstration in your test environment. Code is reviewed before it merges, and integrations are built and tested against sandboxes before they touch production.

    You getWorking software at every step

  4. 4

    Hardening

    Testing for what goes wrong: timeouts, duplicate requests, a callback that never arrives. Load tests, fixes for anything your penetration testers find, and user acceptance testing with your team.

    You getUAT sign-off and runbooks

  5. 5

    Run

    Go-live with close monitoring in the first weeks, then support under a service level agreed up front. Your team gets documentation and a handover, or we run the system for you.

    You getA live system and agreed support

The security practices we work by

We hold ourselves to these on every enterprise project. Send us your vendor security questionnaire: we answer it in writing, control by control, and our engineers will walk your security team through how the system is built.

Least-privilege access

We give each person and each integration only the access it needs. Access to production is named, limited and removed when the work ends.

Secrets kept out of code

API keys, passwords and certificates live in environment configuration or your secrets store, never in source code, tickets or chat.

Encrypted and masked

Every integration we build runs over TLS, or over an encrypted private link where your network requires it. We mask sensitive fields such as ID and account numbers in logs and on screens that do not need them.

Audit trails

We build audit trails into administrative and financial actions, recording who changed what and when, so your auditors can trace any change.

Data where your policy says

We can deploy on your own servers or in the cloud region you choose, so where data lives follows your policy and Kenya's Data Protection Act 2019.

Confidentiality by default

We work under NDA as standard, and we offer a data processing agreement whenever we handle personal data for you.

IntegWatch: financial crime intelligence

Transaction monitoring and case management for banks, SACCOs and fintechs, built on an open-source engine. Now onboarding early-access partners.

Documents on request

Ask for any of these when your vendor process starts. We send them by email.

Company registration

Registration documents for Deefrent Collective Limited.

KRA tax compliance

A current tax compliance certificate from the Kenya Revenue Authority.

References

Contacts at past clients who have agreed to speak with you, matched to the kind of project you are planning.

NDA

We sign your NDA, or send our mutual NDA, before anything confidential changes hands.

Request documents

Talk to our enterprise team

Tell us about the system, the timeline and who needs to sign off. We reply within one working day with next steps, and with an NDA first if you need one.