IT Infrastructure & Support

Build, deploy and maintain secure banking infrastructure for licensed fintechs in Cabo Verde and beyond — on Paymart resources or on Customer premises. DORA, PCI DSS Level 1, ISO 27001, MiCA, GDPR and SOC 2 compliant architecture from day one.

DORA PCI DSS Level 1 ISO 27001 MiCA GDPR SOC 2 Type II

What Paymart Provides

Three integrated services covering the full lifecycle of your banking infrastructure.

Infrastructure Build-Out

Architecture, deployment, and configuration of Paymart Suite as your core banking platform — DORA-compliant from day one. We handle the full stack: redundant data centre setup with primary and disaster recovery sites, network segmentation, firewall rules, HSM integration for key management, SEPA and SWIFT connectivity, and encryption at rest (AES-256) and in transit (TLS 1.3).

Managed Operations

24/7 SOC monitoring, patch management, incident response with post-mortem (DORA Art. 17-19), capacity planning, performance tuning, backup verification, and DR testing. Your infrastructure stays secure and available. In our experience, the biggest risk at this layer isn't hardware failure — it's connectivity. When the ACE submarine cable was cut in early 2024, our failover to SAT-3/WASC kicked in within 90 seconds. The client never noticed. That's what properly tested DR looks like.

Audit & Certification Support

End-to-end preparation for regulatory audits: PCI DSS Level 1 assessment, ISO 27001 certification, DORA ICT risk management documentation, MiCA compliance for crypto-asset services, and regulator audit evidence packages. Surprises in an audit are expensive. We prepare evidence continuously, not just before the assessor arrives — so when the QSA walks in, everything is already documented and traceable.

Deployment Models

Choose the infrastructure model that matches your licensing, compliance, and growth requirements.

Shared Infrastructure

Paymart Suite installed on Contractor’s shared hardware. Projects are isolated from each other. Best for small projects, pilots, and quick launches.

  • Fast launch — up to 2 weeks
  • Cost included in SaaS monthly fee
  • Suitable for 1–10 thousand users
  • Contractor manages backups and IT security
  • Not suitable for PCI DSS audit (scope too wide)

Dedicated Private Cloud

A dedicated Private Cloud is vital for financial organizations. Guarantees data control, regulatory compliance, and full isolation. Supports PCI DSS Level 1.

  • Exclusive resources and full isolation
  • Clustering and floating IP for failover
  • PCI DSS Level 1 compliant scope
  • Protective systems for stronger resilience
  • Included in Paymart Suite SaaS Dedicated fee

License — Paymart Suite Infra

One-time license with installation on Customer’s equipment — or rented equipment provided by the Contractor. Full infrastructure control can be transferred to the Customer.

  • One-time license fee, no yearly fees
  • Installed on customer or rented hardware
  • Cluster structure same as Dedicated Private Cloud
  • Optional full support service from Contractor
  • Full infrastructure control transfer possible

We build infrastructure on our own resources or on the Customer’s premises, depending on the selected delivery model — SaaS Monthly, SaaS Dedicated Private Cloud, or Life Time License. Detailed resource sizing is determined during system and network environment preparation, based on planned load and performance requirements.

Infrastructure Architecture

Five layers, each designed for a specific failure mode.

1

Physical & Network Layer

Redundant data centres with N+1 power, diversified internet uplinks, and submarine cable connectivity (ACE, SAT-3/WASC). DDoS protection and network segmentation isolate traffic between tenant environments.

2

Platform & Application Layer

Paymart Suite modules run in containers with auto-scaling, load balancing, and high availability across availability zones. The API gateway handles routing, rate limiting, and authentication for all client integrations.

3

Data & Storage Layer

Encrypted databases (AES-256 at rest) with automated backups, point-in-time recovery, and geographic replication for disaster recovery. HSM key vaults protect encryption keys with FIPS 140-2 Level 3 certified hardware.

4

Security & Compliance Layer

SIEM correlates events across all layers. IDS/IPS and WAF inspect traffic in real time. Continuous compliance monitoring tracks DORA, PCI DSS, MiCA, and ISO 27001 controls — so audit evidence is collected as a byproduct of operations, not assembled manually after the fact.

5

Integration & Connectivity Layer

Secure connections to SEPA, SWIFT, card networks, PAPSS, and local African payment rails. Message-level encryption and replay protection ensure that intercepted messages cannot be reused or tampered with.

Regulatory Compliance

What regulations does your infrastructure need to satisfy?

DORA

The Digital Operational Resilience Act (EU 2022/2554) has been mandatory since January 2025 for all financial entities operating in the EU. Our infrastructure maps directly to DORA articles: ICT risk management framework (Art. 5-15), major incident reporting with 4-hour initial notification (Art. 17-19), digital operational testing including TLPT, and third-party risk management across the supply chain (Art. 28-44).

MiCA

The Markets in Crypto-Assets Regulation (EU 2023/1114) governs crypto-asset issuance, trading, and custody from December 2024. We support CASP authorisation with prudential requirements, custody and safekeeping controls, transaction monitoring integrated with AML, and white-paper generation support for crypto-asset issuers.

PCI DSS Level 1

The highest PCI DSS tier — for organisations processing over 6 million card transactions annually. We handle network segmentation, cardholder data encryption and tokenization, vulnerability scanning, penetration testing, and preparation for the annual on-site QSA assessment.

ISO 27001

International standard for information security management systems. Certification requires ISMS scope definition, risk assessment, a Statement of Applicability, Annex A controls implementation, internal audit, and management review. We support the full cycle — not just the initial certification, but the continuous improvement loop that keeps it maintained.

Audit Support Process

We guide you through every stage — from gap assessment to certification.

1

Gap Assessment

Audit current infrastructure against DORA, PCI DSS, ISO 27001, and MiCA requirements. Identify gaps and remediation plan.

2

Remediation

Implement missing controls, update policies, configure security settings, and document evidence for auditors.

3

Pre-Audit

Internal audit dry-run, evidence collection, and walkthrough with your team before the external assessor arrives.

4

Certification

On-site support during external audit, real-time evidence provision, and follow-up on findings until certification is granted.

Ready to Build Your Infrastructure?

From architecture design to audit certification — Paymart handles your IT infrastructure so you can focus on your business.

Request Consultation FinTech Licensing