Blockchain-Anchored Audit
Every ledger root hash is anchored to Bitcoin via OriginStamp and OpenTimestamps. Third-party-independent, cryptographic proof of ledger state at any point in time. Unique in the SME tier.
Immutable Trigger-Based Audit
Every table change captured by PostgreSQL trigger: who (user + role), where (client IP), what (action), before/after (JSON diffs). Stored in security.system_audit.
Full KYC Workflow
5-state KYC lifecycle per customer: invited → in_progress → under_review → approved / rejected. Document upload, hash verification, expiry management, and reviewer audit trail.
POPIA & FICA Compliance
Built around POPIA (Protection of Personal Information Act, Act 4 of 2013) and FICA (Financial Intelligence Centre Act) requirements from the data model up — not applied as a policy layer after the fact.
Maker-Checker as Compliance Control
The 5-state maker-checker workflow satisfies FICA's dual-authorisation requirement. Maker and checker identities are JWT-derived at the database session layer — non-forgeable.
Data Sovereignty — Self-Hosted
Deploy LedgerFlow on your own infrastructure. No mandatory cloud dependency. Satisfies NDPR (Nigeria), Data Protection Act (Kenya), GDPR, and POPIA data localisation requirements simultaneously.