Sovereign DSPM & Enterprise AI Governance for Mauritius Financial Services
The only bank-grade, 100% on-premises Data Security Posture Management (DSPM) platform built specifically to satisfy the Mauritius Data Protection Act 2017 (DPA 2017), the Bank of Mauritius (BoM) Cloud Computing Directives, and Financial Services Commission (FSC) data residency rules.
Engineered for Port Louis & Ebène Cybercity Regulations
Navigating the complex convergence of data privacy, banking secrecy, and offshore corporate governance in the Republic of Mauritius.
Mauritius Data Protection Act 2017
Section 31 & Section 36 Absolute Safeguards: Under Section 36 of DPA 2017, personal data cannot be transferred outside Mauritius without verified adequacy or Commissioner clearance. Custos runs 100% inside your data center, eliminating offshore transfer exposure entirely.
- Automated Section 37-40 Subject Access & Right to Erasure fulfillment.
- Continuous Section 23 Storage Limitation & ROT storage purge.
- Shields officers from fines up to Rs 200,000 and statutory sanctions.
Bank of Mauritius (BoM) Cloud Guidelines
Strict Banking Data Residency & Audit Mandates: BoM guidelines on outsourcing and cloud computing mandate that financial institutions retain primary data residency, sovereign key custody, and unhindered regulatory audit rights.
- Core banking ledgers (Oracle RAC, SQL Server) scanned in-place with 0 database downtime.
- Customer-managed keys (CMEK) and HSM key retention; zero vendor key sharing.
- Full audit trail accessibility for Bank of Mauritius onsite supervisory inspections.
Financial Services Commission (FSC) Outsourcing
Protection for Global Business Licensees (GBLs) & Trusts: Offshore management companies and investment funds must prevent customer data commingling and multi-tenant supply chain vulnerabilities.
- Cryptographic isolation of international investor beneficial ownership data.
- Eliminates US CLOUD Act subpoena risk by locking all metadata on-premise.
- EU GDPR Article 32 & Chapter V adequacy alignment for European funds.
Why Mauritian Financial Institutions Choose Custos Over US Cloud DSPMs
US cloud SaaS DSPMs introduce critical regulatory non-compliance for entities operating under Bank of Mauritius and FSC oversight.
| Architectural & Regulatory Metric | US Cloud DSPMs (Cyera, BigID, Securiti.ai, Varonis) | Custos™ DSPM by GovernX |
|---|---|---|
| Telemetry & Metadata Movement | WAN Egress Required: Replicates metadata, database schemas, and data sample payloads to multi-tenant US/EU clouds. | 100% In-Place, Zero WAN Egress: Scanning daemon runs inside your private VPC/datacenter. Zero bytes leave Mauritius. |
| Mauritius DPA 2017 (Section 36) | High Regulatory Liability: Transfers sensitive data to foreign jurisdictions without individual statutory authorizations. | Full Statutory Immunity: Operates strictly on-island; no cross-border transfer trigger occurs. |
| Bank of Mauritius (BoM) Cloud Directives | Non-Compliant: Co-mingles telemetry on public SaaS infrastructure; vendor holds encryption keys. | 100% Compliant: Customer-held keys, local audit access, and single-tenant cryptographic boundaries. |
| Mauritian Data Classifiers | Generic US/EU Templates: Flags US SSNs and credit cards; fails to parse Mauritian NIC and local corporate filings. | Native Mauritian Algorithmic Parsers: Deterministic checksum verification for NIC, TAN, VAT, and offshore banking ledgers. |
| In-Line Generative AI Guardrail | API Latency Penalty (>250ms): Routes completions through offshore API endpoints for redaction. | Sub-5ms Custos Guard: In-network reverse proxy stripping PII in-flight before LLM ingestion (Gemini, Claude, DeepSeek-R1). |
| Deployment Footprint | Complex multi-month cloud integration with recurring USD forex volatility. | 1-Click Turnkey Installer: Single pre-compiled Go binary deployed on Kubernetes, OpenShift, or bare-metal Linux in hours. |
Native Classifiers for Mauritian Banking & Offshore Entities
Custos eliminates false positives with mathematical checksum validation specifically engineered for Mauritian identifiers.
Mauritian National Identity Card (NIC)
Parses the 14-character alphanumeric structure (First letter of surname + DOB in DDMMYY format + unique sequence number + check digit) across structured and unstructured datastores.
Tax Account Number (TAN) & VAT
Scans payroll, invoice repositories, and ERP tables for 8-digit Mauritius Revenue Authority (MRA) TAN references and VAT registration IDs.
Offshore Financial & SWIFT/IBAN Accounts
Detects Mauritian bank account formats (MCB, SBM, Absa Mauritius, HSBC) and international SWIFT BIC routing identifiers in transaction logs.
Beneficial Ownership & Trust Ledgers
Identifies sensitive beneficial ownership disclosures, corporate registries, and trust indenture documents across CIFS/NFS file shares.
Turnkey 30-Day Sovereign Proof of Value (POV)
Tailored specifically for Chief Information Security Officers, Compliance Directors, and Data Architects at Mauritian commercial banks, offshore management companies, and financial groups.
Sovereign Risk & Statutory Compliance Audit
Key Deliverables to the Board of Directors:
- ✓ In-Place Sensitive Data Discovery: Full inventory of unencrypted citizen NICs, tax numbers, and account records across designated Oracle, SQL Server, Postgres, or S3 stores.
- ✓ Mauritius DPA 2017 & BoM/FSC Audit Dossier: Executive scorecard benchmarking statutory readiness against Section 31, Section 36, and Bank of Mauritius cloud directives.
- ✓ ROT Storage Cost Reclaim Matrix: Immediate discovery of duplicate, stale, and orphaned database dumps, identifying 20%–40% reclaimable SAN capacity.
- ✓ 100% Conversion Credit: 100% of the ,000 POV fee is fully credited toward your annual enterprise subscription upon conversion.
Frequently Asked Questions: Mauritius Financial Data Sovereignty
Addressing the core technical, regulatory, and architectural inquiries of Mauritian enterprise leaders.
No. Absolute Zero WAN Egress. Custos DSPM is engineered from the ground up to operate in pure air-gapped environments. The binary runs entirely within your local local area network (LAN) or private sovereign VPC. It does not phone home, does not send telemetry, and uses eBPF kernel filters to mathematically enforce that no outbound packets leave the cluster nodes.
The Bank of Mauritius mandates that financial institutions ensure continuous data residency, maintain complete ownership and custody of encryption keys, avoid vendor lock-in, and guarantee supervisory authorities on-site access to data and logs. Custos DSPM satisfies every clause by keeping 100% of data and metadata inside the institution's private infrastructure, supporting customer-managed keys (HSM/KMS), and generating exportable local audit logs.
Yes. Custos utilizes lightweight read-only streaming cursors throttled to consume less than 2% CPU overhead. In enterprise banking topologies, Custos is configured to query Active Data Guard physical standbys or SQL Server AlwaysOn read-only secondary replicas, guaranteeing zero impact on high-throughput OLTP core banking processing.
Financial institutions are eager to leverage LLMs for wealth management research, credit analysis, and customer service, but are barred by confidentiality laws from sending customer data to external AI clouds. Custos Guard acts as a local reverse proxy that sanitizes prompts in-flight (<5ms latency), replaces citizen IDs, card numbers, and balances with cryptographic tokens, and allows only sanitized queries to reach models. When answers return, tokens are safely rehydrated inside the bank's perimeter.