BUILT FOR A CONNECTED ECONOMYRwanda • Platform preview
MoTa
Live Sandbox
MoTa
SECURITY, SOVEREIGNTY & COMPLIANCE

Trust belongs in the foundation.

MoTa’s production architecture must protect fiscal records, respect Rwanda’s data requirements and give institutions control over their infrastructure.

Explore Live Sandbox
RWANDAA sovereign control planeLaw No 058/2021
01

Law No 058/2021

Rwanda’s personal data and privacy law governs processing obligations, data subject rights and controller or processor registration. Legal review is required before deployment.

02

Kigali residency plan

Evaluate AOS National Data Center services and RISA directives. These are proposed residency options, not MoTa’s confirmed hosting or a compliance endorsement.

03

Controlled access

Least privilege, authenticated production endpoints, encrypted storage, key rotation and auditable access are required controls.

02 / SHA-256

Receipt integrity, not authority certification

SHA-256 fingerprints detect changes when compared with a trusted record. A hash alone is not a digital signature, proof of origin or RRA approval.

Fingerprint previewSIMULATED
03 / Audit lifecycle
01Sale received and validated
02Payment status recorded independently
03Authority acknowledgement stored and reported
04Auditability & portability

Required production trail: append-only events, restricted writes, retention policy and independently verified backups.

A security model with verifiable boundaries

A security model with verifiable boundaries

Security must protect both the content of a fiscal record and the authority to access or change it. Data location, cryptographic integrity, identity, operational audit and recovery are separate controls. A strong design explains what each control proves and what still requires independent verification.

01 / Fingerprints, signatures and verification chains

SHA-256 produces a fingerprint of a defined byte sequence. For repeatable verification, a production format must fix field ordering, number formatting, text encoding and versioning before hashing. Changing a quantity or total then changes the fingerprint. Comparison is meaningful only against an independently trusted record, not a hash supplied alongside data by an untrusted caller.

A proposed audit chain can include the previous event hash in the next event’s canonical payload, with periodic checkpoints stored independently. This helps detect missing or altered events but does not prevent a privileged actor from rebuilding an entire unanchored chain. Digital signatures require protected signing keys, and official fiscal signatures require certified authority processing. Neither is created by the hash preview above.

hash[n] = SHA-256(canonical(event[n]) + hash[n-1])

02 / Rwanda residency and operational sovereignty

Law No 058/2021 frames personal-data obligations and data subject rights. A deployment review must establish controller and processor responsibilities, registration requirements, processing purposes and transfer rules with qualified local advice. Kigali residency planning should cover primary storage, backups, logs and support access, not only the location of the main application.

AOS National Data Center services and RISA directives are options and references to evaluate, not confirmed MoTa hosting. Independent operation requires documented deployment procedures, exportable data, infrastructure ownership and tested restoration outside a single vendor. Sovereignty also depends on who controls keys, access approvals and incident response. No current hosting certification is implied.

03 / Least privilege and zero-trust boundaries

Production authorization must be enforced at the data and service boundary, not just by hiding buttons. Merchant users should access only their permitted records; district reviewers receive scoped read access; national analysts receive approved aggregates. Privileged administration should be separated from routine reporting, with role assignment protected from user-editable profile fields.

Every sensitive request must authenticate its caller, authorize the requested operation and verify the scope of the target record. TLS, encryption at rest, key rotation and short-lived credentials are complementary controls, not substitutes for authorization. Public simulations must never gain the privileges of a certified fiscal adapter or an institutional administrator.

Proposed access matrix

RolePermitted evidence
MerchantOwn sales, receipts and daily exports. No cross-merchant access.
Authorized reviewerRead-only records within the approved institutional scope.
Institutional analystApproved aggregates with restricted personal-data exposure.
Privileged operatorSeparately authorized administration with audited actions.

04 / Audit retention, incident response and recovery

A proposed append-only audit trail captures actor, action, object, time, result and correlation reference. Sensitive values should be minimized or redacted, and access to the trail must itself be audited. Fiscal corrections retain links to the original transaction and the approving actor. Retention periods must follow the applicable legal and institutional policy rather than an arbitrary product default.

Recovery readiness requires independently protected backups, restoration drills and a reconciliation procedure for events received during an outage. Incident response assigns responsibility for containment, evidence preservation, stakeholder notification and controlled restart. Data-loss and recovery-time objectives must be agreed and tested before a production claim is made. These are deployment requirements, not assertions that every control is already operating.

LET’S BUILD WHAT COMES NEXT

A more connected fiscal future.

Talk to MoTa
MoTa

Mobile Tax Automation