IT Infrastructure & Support

Build, deploy and maintain secure banking infrastructure for licensed fintechs in Cabo Verde and beyond — on Paymart resources or on Customer premises. DORA, PCI DSS Level 1, ISO 27001, MiCA, GDPR and SOC 2 compliant architecture from day one.

DORA PCI DSS Level 1 ISO 27001 MiCA GDPR SOC 2 Type II

What Paymart Provides

Three integrated services covering the full lifecycle of your banking infrastructure.

Infrastructure Build-Out

Architecture, deployment, and configuration of Paymart Suite as your core banking platform — DORA-compliant from day one.

  • Redundant data centre setup (primary + DR)
  • Network segmentation & firewall rules
  • HSM integration for key management
  • SEPA / SWIFT connectivity configuration
  • Encryption at rest (AES-256) & in transit (TLS 1.3)

Managed Operations

24/7 monitoring, maintenance, and incident response — your infrastructure stays secure and available.

  • 24/7 SOC monitoring & alerting
  • Patch management & security updates
  • Incident response & post-mortem (DORA Art. 17-19)
  • Capacity planning & performance tuning
  • Backup verification & DR testing

Audit & Certification Support

End-to-end preparation for regulatory audits and security certifications — evidence, documentation, and remediation.

  • PCI DSS Level 1 assessment preparation
  • ISO 27001 certification support
  • DORA ICT risk management documentation
  • MiCA compliance for crypto-asset services
  • Regulator audit evidence packages

Deployment Models

Choose the infrastructure model that matches your licensing, compliance, and growth requirements.

Shared Infrastructure

Paymart Suite installed on Contractor’s shared hardware. Projects are isolated from each other. Best for small projects, pilots, and quick launches.

  • Fast launch — up to 2 weeks
  • Cost included in SaaS monthly fee
  • Suitable for 1–10 thousand users
  • Contractor manages backups and IT security
  • Not suitable for PCI DSS audit (scope too wide)

Dedicated Private Cloud

A dedicated Private Cloud is vital for financial organizations. Guarantees data control, regulatory compliance, and full isolation. Supports PCI DSS Level 1.

  • Exclusive resources and full isolation
  • Clustering and floating IP for failover
  • PCI DSS Level 1 compliant scope
  • Protective systems for stronger resilience
  • Included in Paymart Suite SaaS Dedicated fee

License — Paymart Suite Infra

One-time license with installation on Customer’s equipment — or rented equipment provided by the Contractor. Full infrastructure control can be transferred to the Customer.

  • One-time license fee, no yearly fees
  • Installed on customer or rented hardware
  • Cluster structure same as Dedicated Private Cloud
  • Optional full support service from Contractor
  • Full infrastructure control transfer possible

We build infrastructure on our own resources or on the Customer’s premises, depending on the selected delivery model — SaaS Shared, SaaS Dedicated Private Cloud, or License Paymart Suite Infra. Detailed resource sizing is determined during system and network environment preparation, based on planned load and performance requirements.

Infrastructure Architecture

Layered architecture designed for resilience, security, and regulatory compliance.

1

Physical & Network Layer

Redundant data centres with N+1 power, diversified internet uplinks, and submarine cable connectivity (ACE, SAT-3/WASC).

  • N+1 Power
  • Submarine cable
  • Firewall
  • DDoS Protection
  • Network Segmentation
2

Platform & Application Layer

Paymart Suite modules deployed in containers with auto-scaling, load balancing, and high availability across availability zones.

  • Container Orchestration
  • Load Balancer
  • API Gateway
  • Auto-scaling
  • High Availability
3

Data & Storage Layer

Encrypted databases with automated backups, point-in-time recovery, and geographic replication for disaster recovery.

  • AES-256 at Rest
  • Automated Backups
  • Geo-replication
  • PITR
  • HSM Key Vault
4

Security & Compliance Layer

SIEM, IDS/IPS, WAF, and continuous compliance monitoring covering DORA, PCI DSS, MiCA, and ISO 27001 controls.

  • SIEM
  • IDS/IPS
  • WAF
  • DORA Monitoring
  • Audit Logging
5

Integration & Connectivity Layer

Secure connections to SEPA, SWIFT, card networks, and local African payment rails with message-level encryption and replay protection.

  • SEPA SCT/Inst
  • SWIFT GPI
  • Card Networks
  • PAPSS
  • API Security

Regulatory Compliance

Infrastructure designed to meet the latest European and international financial regulations.

DORA

Digital Operational Resilience Act (EU 2022/2554). Mandatory from January 2025 for all financial entities in the EU.

  • ICT risk management framework (Art. 5-15)
  • Major incident reporting (Art. 17-19)
  • Digital operational testing & TLPT
  • Third-party risk management (Art. 28-44)

MiCA

Markets in Crypto-Assets Regulation (EU 2023/1114). Governs crypto-asset issuance, trading, and custody from December 2024.

  • CASP authorisation & prudential requirements
  • Custody & safekeeping controls
  • Transaction monitoring & AML integration
  • White-paper generation support

PCI DSS Level 1

Payment Card Industry Data Security Standard — highest level for organisations processing over 6M card transactions annually.

  • Network segmentation & firewall rules
  • Cardholder data encryption & tokenization
  • Vulnerability scanning & penetration testing
  • Annual on-site assessment by QSA

ISO 27001

International standard for information security management systems (ISMS). Certification requires risk assessment, controls, and continuous improvement.

  • ISMS scope & risk assessment
  • Statement of Applicability (SoA)
  • Annex A controls implementation
  • Internal audit & management review

Audit Support Process

We guide you through every stage — from gap assessment to certification.

1

Gap Assessment

Audit current infrastructure against DORA, PCI DSS, ISO 27001, and MiCA requirements. Identify gaps and remediation plan.

2

Remediation

Implement missing controls, update policies, configure security settings, and document evidence for auditors.

3

Pre-Audit

Internal audit dry-run, evidence collection, and walkthrough with your team before the external assessor arrives.

4

Certification

On-site support during external audit, real-time evidence provision, and follow-up on findings until certification is granted.

Ready to Build Your Infrastructure?

From architecture design to audit certification — Paymart handles your IT infrastructure so you can focus on your business.

Request Consultation FinTech Licensing