SOC 2 and trust: assurance for the NamPost sandbox platform
Why SOC 2-style controls matter when BoN, NAMFISA, and MoF programme officers rely on NamPost ICT's platform evidence.

Supervisors and partner banks ask one question: can we rely on your controls? For the NamPost Innovation Sandbox, assurance spans append-only audit logs, Keycloak realm separation, Kong gateway policies, and DR drills aligned to RPO ≤5 min and RTO ≤2 h exemplars (PSD-12 pattern).
What participants should expect
- httpOnly session cookies via portal BFF—no long-lived secrets in
localStorage. - Parameterized data access; synthetic namespaces isolated per participant.
- Export artefacts for exit packs—PDF + CSV with HMAC verification script.
What SOC 2 does not replace
Statutory supervision. NPIF approval. Step-up 2FA on every payment. Your own product disclosures.
Trust is cumulative: platform assurance + your conformance + regulator Observation Deck.
Ready for your 6-week PoC?
Apply for sandbox accessMore Articles
Auditable NPIF workflows: why sandbox automation needs a paper trail
Application → provision → monitor → exit as LangGraph state—with append-only history for BoN/NAMFISA review.
May 4, 2026
Official sources — sandboxes, payments, and supervision (reading list)
Curated supervisor and programme links for NamPost sandbox participants—Namibia-first, SADC context, not internal platform docs.
May 6, 2026
