How it is built
The architectural decisions that a lender inherits, and the ones that are load-bearing for every claim on this site.
The decisions that matter
| Decision | What it means in practice | Status |
|---|---|---|
| One PostgreSQL boundary per tenant, enforced by the database | Every tenant table carries FORCED row-level security keyed on a session GUC that only a scoped transaction can set. The application role is not the table owner and cannot read past the policy; a query issued outside a tenant transaction returns zero rows rather than the wrong ones. | ✓ Live |
| ISO 20022 as the internal message shape | pain, pacs, camt and admi are the native envelopes throughout the core. A rail adapter translates outward at the edge; nothing translates inward. Adding a rail is an adapter, not a migration. | ✓ Live |
| A single money-mover framework | Every value movement goes through one executor that screens the parties, compare-and-swaps the lifecycle state, checks the ceiling, posts zero-guarded legs, applies limits and chains the evidence. Bypassing it is a compile error, not a code-review finding. | ✓ Live |
| Fail-closed by construction | An unavailable dependency refuses the operation and names the gate. No control degrades to permissive under load or misconfiguration — including the ones that would be more convenient if they did. | ✓ Live |
| Zero runtime dependencies | The platform is TypeScript on Node 24 with no third-party runtime packages. The supply-chain surface a lender inherits from us is the standard library and PostgreSQL, and that is a deliberate, load-bearing choice. | ✓ Live |
| Deployment topology | Primary in af-south-1 with disaster recovery in eu-west-1, per-tenant encryption keys in an HSM keyring, and a three-officer break-glass ceremony for key re-keying. CloudHSM provisioning is a deployment step. | ◐ In build |
The shape of a request
Every write in the platform takes the same path, which is why the security claims generalise rather than applying to whichever surface was reviewed last.
- Admission — an unsafe browser request is checked against an exact origin allowlist and Fetch Metadata; a cookie-authenticated one additionally carries a per-session synchronizer token.
- Identity — the credential resolves to a tenant, a user and a set of roles server-side. Nothing about authority is read from the request.
- Authorisation — a dual check runs before the handler: role-based permission, then attribute-based policy. A conditional denial fires; it does not fail open.
- Tenant transaction — the handler opens a scoped transaction that pins the tenant GUC. Every statement inside it is filtered by row-level security.
- The money mover — a value movement screens the parties, compare-and-swaps the lifecycle state, checks its ceiling, posts zero-guarded legs and chains the evidence. All of it, or none of it.
- Evidence — the audit event and the accounting fact commit in the SAME transaction as the movement. There is no window in which money moved and the record did not.
Where data lives
One database, many boundaries
Tenants share a PostgreSQL cluster and are separated by FORCED row-level security rather than by a schema-per-tenant sprawl nobody can migrate. The application role is not the table owner, so the policy applies to it unconditionally.
Keys per tenant, in an HSM keyring
Each tenant has its own data-encryption key, wrapped by a master key held in the HSM. Rotation re-wraps; re-keying mints a new key and is gated behind a three-officer ceremony bound to that specific operation.
Erasure that actually erases
A discharged POPIA erasure destroys the per-subject key, so residual ciphertext in a backup is unreadable rather than merely un-indexed. Legal holds interlock: a subject under hold is refused with the reason named.
Regions
Primary in af-south-1, disaster recovery in eu-west-1. A cross-border replica raises its own POPIA transfer question, and the answer is documented rather than assumed.
What we do not promise
- We do not publish a benchmark number. A throughput figure without your data shape, your rail latencies and your regulatory checks is marketing, not engineering — we will run one against your volumes during evaluation instead.
- We do not claim zero downtime. Failover across regions is minutes, not seconds, and the recovery-point objective is written into the contract rather than implied here.
- Controls marked in build above are not load-bearing yet, and a risk assessment should treat them as absent.
Wynk Systems is a bank-grade core-banking platform. Registered in South Africa.
This site is informational: nothing on it constitutes an offer, a quotation, or credit advice.