Product
ProcessProtectReconComply
Use Cases
PSPs & Payment ProcessorsFintechs & Digital BanksFinancial InstitutionsEnterprise TreasuryTransit & Municipal
Developer
API-FirstMCP for Coding AgentsSelf-Hosting & DeployArchitecture & Stack
Built for AI
Meet FloKnowledge BaseInternal MCP ToolsContext-Aware UIDocument Intelligence About
Book a DemoTry Free →
Comply Pillar

"The Proof Lives Here"

POPIA, FICA, and SARB compliance built into the platform architecture — not retrofitted. Blockchain-anchored ledger integrity, a full KYC workflow, and an immutable audit trail that starts before your application does.

Compliance That Auditors
Can Actually Verify

Most compliance features are application-layer controls that can be bypassed if someone hits the API directly. LedgerFlow's compliance is enforced at the database trigger layer — bypassing the application changes nothing.

Blockchain-Anchored Audit
Every ledger root hash is anchored to Bitcoin via OriginStamp and OpenTimestamps. Third-party-independent, cryptographic proof of ledger state at any point in time. Unique in the SME tier.
Immutable Trigger-Based Audit
Every table change captured by PostgreSQL trigger: who (user + role), where (client IP), what (action), before/after (JSON diffs). Stored in security.system_audit.
Full KYC Workflow
5-state KYC lifecycle per customer: invited → in_progress → under_review → approved / rejected. Document upload, hash verification, expiry management, and reviewer audit trail.
POPIA & FICA Compliance
Built around POPIA (Protection of Personal Information Act, Act 4 of 2013) and FICA (Financial Intelligence Centre Act) requirements from the data model up — not applied as a policy layer after the fact.
Maker-Checker as Compliance Control
The 5-state maker-checker workflow satisfies FICA's dual-authorisation requirement. Maker and checker identities are JWT-derived at the database session layer — non-forgeable.
Data Sovereignty — Self-Hosted
Deploy LedgerFlow on your own infrastructure. No mandatory cloud dependency. Satisfies NDPR (Nigeria), Data Protection Act (Kenya), GDPR, and POPIA data localisation requirements simultaneously.

A Complete KYC Lifecycle.
Document to Approval.

INVITED
Customer invited to portal
IN
PROGRESS
Customer uploading documents
UNDER
REVIEW
Compliance team reviewing
APPROVED
Customer cleared to transact
REJECTED
Reason recorded — appeal path available

Document hash verification, expiry tracking, and reviewer audit trail included. Each document change triggers an audit entry in security.system_audit.

One Platform. Multiple
Regulatory Frameworks.

SARB
South African Reserve Bank
Payment System Oversight requirements including transaction reporting, settlement finality, and audit trail retention.
FICA
Financial Intelligence Centre Act
KYC/AML requirements: customer identification, beneficial ownership, suspicious transaction reporting, and record-keeping.
POPIA
Protection of Personal Information Act
Data minimisation, purpose limitation, consent management, data subject rights, and Information Officer obligations.
GDPR
General Data Protection Regulation
Self-hosting satisfies data localisation and data residency requirements for EU-connected operations. Data subject request workflows included.
NDPR / DPA
Nigeria & Kenya Data Laws
Self-hostable deployment satisfies in-country data residency requirements under NDPR (Nigeria) and the Data Protection Act (Kenya).
ISO 27001
Information Security (Roadmap)
ISO 27001 alignment is on the Horizon 2 roadmap. Current immutable audit trail and RBAC architecture provide a strong baseline for certification.
Need compliance you can prove in a regulator's exam?
Blockchain-anchored audit + immutable trigger log + full KYC — all in one platform.
Start Free Trial →Book a Demo