Bank-Grade Security Architecture

Enterprise Security & ITIDA CAdES-BES Compliance

Built to satisfy strict ITIDA requirements and Egyptian Tax Authority digital signature standards, protecting your sensitive financial data with end-to-end encryption.

📜

1. ITIDA CAdES-BES Compliant

Enforces SHA-256 digest hashing, detached CMS signature structures (`sha256WithRSAEncryption`), ESSCertIDv2 attribute verification, and full trust chain validation reaching the Egypt Root CA.

🔑

2. Zero Private Key Exposure

With the OTax Agent Bridge, your USB hardware token private keys never leave your physical device. Cryptographic hashing occurs on-device via local WebSocket PKCS#11 interface.

👥

3. Role-Based Access (RBAC)

Granular permission management for team members, tax accountants, and external auditors. Enforces strict organization data isolation with multi-tenant encryption.

🔒

4. AES-256 & TLS 1.3 Tunneling

All database connections and API payload transmissions run over TLS 1.3 encrypted sockets with AES-256 at-rest encryption for certificate stores and tokens.

Technical Compliance Specs

Full Alignment with Egypt Digital Trust Framework

Certified compatibility across all major Egyptian Trust Service Providers (TSPs).

Detached Signature Format

Generates standard ASN.1 PKCS#7 signed-data structures formatted precisely for the Egyptian Tax Authority portal parser.

Egypt Root CA Trust

Validates hardware token certificates from Egypt Trust, Misr El Makkasa, and accredited Egyptian Trust Service Providers.

AES-256 At-Rest Encryption

All cloud certificates (PFX), API credentials, and client database connections are encrypted at rest with AES-256.

TLS 1.3 Transmission

All API requests between OTax Agent Bridge, Express Middleware, and ETA portal run over TLS 1.3 encrypted sockets.

Need custom security or deployment reviews?

Our ITIDA compliance engineers are available for enterprise architecture reviews.

Contact Security Team →