Okestreta LogoOKESTRETA
Platform

Your data never leaves your infrastructure.

In African financial services, a data breach carries regulatory fines and reputational damage that can take years to recover from. Every Okestreta deployment is air-gapped, single-tenant, and jurisdiction-resident. Compliance is structural, not a configuration option.
SOC 2 Type II
ISO 27001
GDPR Ready
PCI DSS

Complete isolation. No shared risk.

Compute, storage, network, and encryption keys are dedicated exclusively to your institution. No shared infrastructure, no data co-mingling, no regulatory ambiguity about boundaries. Your customer data environment is entirely separated from every other deployment.

Dedicated Infrastructure

Each deployment runs on completely isolated infrastructure. Your compute, storage, and network resources are never shared with other organisations.

Separate Encryption Keys

Customer-managed keys with HSM support. No vendor access to your data during maintenance, support, or any other operation.

Air-Gap Isolation

True air-gap isolation for institutions where board mandates or regulatory directives require complete network separation.
0compliance violationslast 24 months
12 weeksto productionvs 9 months typical
100%audit pass rateall customers

Deploy where your regulator requires.

Different jurisdictions mandate different residency and control requirements. Every deployment model delivers identical predictive capabilities with identical security controls.
CLOUD

Your Cloud Account

Customer data stays within your AWS, Azure, or Google Cloud account in your preferred African region. Okestreta provisions and manages the platform. Your team retains full ownership and visibility.
Your cloud account
Your data region
We handle operations
ON-PREMISE

Your Data Centre

On-premise deployment behind your firewall for institutions where board mandates or regulatory directives require air-gapped isolation. Same predictive capabilities. Complete physical control.
Behind your firewall
Air-gapped option
Full sovereignty
MANAGED

Dedicated Managed

Full platform management on dedicated infrastructure without operational overhead. Complete tenant isolation, enterprise SLA, and 24/7 support. Okestreta handles scaling, maintenance, and security updates.
Dedicated resources
24/7 support
Zero maintenance

Security that satisfies your board and your regulators.

Encryption

Customer data encrypted at rest and in transit. You control your own encryption keys. No vendor access to your data during maintenance, support, or any other operation.

Access Governance

Granular field-level access control. Multi-factor authentication, network restrictions, and complete audit logging at every access level. Integrates with your existing SSO and SIEM systems.

Zero-Trust Model

Every access request verified regardless of origin. No implicit trust, no standing privileges, no exceptions.

Resilience

Automated backups to your designated storage. 1-hour recovery point objective. 4-hour recovery time objective. Recovery plans testable without production impact.

Named regulators. Not generic claims.

Compliance controls are built for African financial regulation from the ground up. POPIA, Nigeria Data Protection Act, Kenya Data Protection Act, CBK Prudential Guidelines. Not adapted from frameworks designed for other markets.

Banking

SARB, CBN, CBK, Bank of Uganda, Bank of Tanzania prudential guidelines. Basel-aligned reporting where required.

Insurance

IRA (Kenya), FSCA (South Africa), NAICOM (Nigeria). Solvency and conduct requirements mapped per jurisdiction.

Pensions

RBA (Kenya), NPRA (Ghana), PenCom (Nigeria), URBRA (Uganda). AUM reporting and member data protection requirements.

Mobile Money

Central bank e-money directives. Transaction reporting, agent network compliance, float management oversight.

Data Protection

POPIA (South Africa), Kenya DPA, Nigeria DPA, Uganda DPA. In-country residency enforced by automated controls that prevent cross-border data movement without explicit authorisation.

Every action logged. Every decision explainable.

Immutable audit trails record who did what, when, and why. Tamper-proof logs export directly to your SIEM. Automated compliance reports generate on schedule for regulatory submission. Every model decision carries a full explanation chain, auditable at the individual customer level. When auditors arrive, every question has a documented answer without manual preparation.

Immutable Audit Logs

Every action logged with who, what, when, where. Export to your SIEM. Tamper-proof records for compliance.

Automated Reports

Scheduled compliance reports for regulators. Generate on demand or on schedule without manual preparation.

Explainable AI

Full explanation chain for every model decision. Auditable at the individual customer level across all jurisdictions.

Connects to your existing stack.

Okestreta uses a side-chain integration architecture that operates alongside your production systems without impacting their performance or stability. Pre-built connectors for core banking platforms (T24, Flexcube, Finacle), mobile money systems, and insurance policy administration platforms common across African financial services. Custom integrations for proprietary systems where needed. Batch and real-time data ingestion supported. Typical pilot integration: 2 to 4 weeks.Platform changes follow your internal approval process, your maintenance windows, and your testing requirements. Nothing changes in your environment without your authorisation.

Assess your deployment requirements.

Assess Deployment Fit