Skip to content

πŸ“˜ ThitsaWorks Technical Documentation

Welcome to the ThitsaWorks technical documentation for security, architecture, deployment, and operations within the Mojaloop ecosystem.

This documentation describes how Mojaloop-based systems are actually implemented, secured, deployed, and operated in real-world environments.

It focuses on:

  • Practical architecture
  • Production security controls
  • Deployment models
  • Operational behavior
  • Integration patterns

This is implementation-driven documentation, not theoretical reference material.


πŸš€ Getting Started

Choose the deployment model that matches your environment:


πŸ—οΈ Architecture

  • Platform Architecture Overview
    Provides a high-level reference architecture covering:
  • Mojaloop Hub, PM4ML, and Tazama
  • Cloud, on-premise, and hybrid deployments
  • Primary–Standby topology
  • Platform responsibilities and trust boundaries

πŸ” Security Architecture

  • Hub ↔ PM4ML Security Architecture
    Describes the end-to-end security model between the Hub and PM4ML, including:
  • Mutual TLS (mTLS) for transport-level security
  • JWS for application-level message signing
  • Certificate lifecycle and rotation
  • Trust boundaries and ownership

βš™οΈ Operations & Reliability

The following sections are being developed and will reflect validated production behavior:

  • βœ… Pre-Deployment Checklist
  • πŸ” Certificate & Key Management
  • 🚨 Incident & Failure Scenarios
  • πŸ“ Environment & Capacity Model
  • πŸ“Š Monitoring & Alerting Architecture
  • 🧾 Operational Runbooks

🌐 More Information

For general information about ThitsaWorks, including company services and offerings:

πŸ‘‰ https://thitsaworks.com


πŸ“Œ About This Site

This documentation reflects real-world implementation and operational security practices used in Mojaloop-based deployments.

It is intended for:

  • Platform Engineers
  • Security Engineers
  • Infrastructure Engineers
  • DFSP Integration Teams
  • Operations Teams

The goal is to provide a clear, practical, and production-aligned understanding of how the system is secured, deployed, and operated.