Overview

Security & compliance

Payments, vault, personal data — the bank-grade level required.

Security is built into the architecture, not added at the end: a single entry through the Traefik gateway, isolated services, Rust for critical modules.

Defence in depth

Each level is independent of the others.

LevelMeasureWhat it stops
PerimeterTraefik: single entry, TLS 1.3 termination, hardened headersInterception, scattered attack surface
AccessTwo-factor authentication (2FA) on extended rolesPassword theft
Authorization7 sealed roles, admin-configurable permissionsPrivilege escalation, cross-project leaks
ApplicationRust services for Finance & vaultMemory corruption, injection
Supply chainDependency scanning on every build (DevSecOps, GitHub Actions)Known CVEs, vulnerable dependencies
TraceabilityImmutable audit log via the NATS/JetStream busDispute, trace erasure

The digital vault

For land titles, contracts and plans. Encryption engine written in Rust:

  • AES-256 encryption per file — a distinct key for each document
  • Certified timestamping of every deposit
  • Double-confirmation deletion, logged
  • PIN / biometric access on mobile, independent of the app session

Legally valid e-signature

Two levels, matched to the stakes:

  • Advanced (built-in) for volume — quotes, site reports: document hash, identity (2FA), timestamping and an immutable audit log, in PAdES format (verifiable over time)
  • Qualified via an accredited Senegalese trust provider (SenTrust / Afric Trust) for critical documents — contracts, land titles, acceptance reports

Compliant with law n° 2008-08 and decree n° 2008-720 on electronic certification — probative value recognised in Senegal; eIDAS option for the European diaspora.

Continuity

  • Encrypted daily backups, 90-day retention, geographic replication of object storage (MinIO)
  • Kubernetes restarts a failed service; Blue-Green deploys update with zero downtime
  • Recovery point (RPO) and recovery time (RTO) defined with you and contractualised
  • A restore drill run before go-live, with a report

What we prove before launch

  • Penetration tests (OWASP) — report delivered, fixes verified
  • Load tests at 2,000+ concurrent users — report delivered, breaking point documented
  • GDPR and Senegalese law n° 2008-12 on personal data protection compliance
  • Privacy policy and terms of use built into sign-up
ERK+× Vortex-Soft

Vortex-Soft's technical proposal for ERK+, ERK Group's construction project management platform — Dakar, Senegal.

Vortex-Soft
Vortex-Soft
© 2026 Vortex-Soft — DakarConfidential document prepared for ERK Group.