Advanced Search
Search Results
1250 total results found
Production Deployment
Drop AWS Amplify Deployment Guide Rebrand note (2026-02-14): Originally titled "FontelePay". Product rebranded to Drop. Some env var references (Swan, Stripe) are FUTURE integrations — Drop uses a PSD2 pass-through model. See Drop CLAUDE.md. This guide cover...
DevOps/SRE Stack
DevOps/SRE Stack for Drop (originally FontelePay) Rebrand note (2026-02-14): FontelePay was renamed to Drop. Some references to FontelePay remain in this document (metric names, Sentry projects, API URLs). These should be updated when implementing the actual ...
WAF Rules
WAF Rules — Drop Payment App MC #1229 — Web Application Firewall configuration for Drop fintech. Overview Drop runs on Fly.io which does not provide a built-in WAF. Protection is layered: Middleware-level (Next.js Edge Middleware) — first line of defense Fly....
Cloud Deployment Options
Cloud Deployment Options for Drop Rebrand note (2026-02-14): Originally titled "FontelePay". Product rebranded to Drop. See Drop CLAUDE.md. Date: 2026-02-05 Purpose: Evaluate cloud deployment options for European mobile banking MVP Requirements Summary R...
Security Audit
Drop Security Audit (originally FontelePay) Rebrand note: FontelePay was renamed to Drop. This audit predates the backend implementation and PSD2 pass-through architecture. Many issues identified here (localStorage PIN, client-side auth) have been addressed i...
Security QA Audit
Drop App Security & QA Audit Report Date: 2026-02-11 Auditor: John (AI Director) Scope: Next.js 16 fintech app with SQLite database, JWT auth, 24 API routes HISTORICAL NOTE (2026-03-03): This audit was performed against the pre-ADR-014 codebase which used SQL...
Regulatory Map
Drop Regulatory Map v2 Norwegian Financial Services Regulatory Framework Date: 2026-02-12 Prepared for: ALAI Holding AS / Drop Payment App Scope: All regulations applicable to a payment app serving ALL residents of Scandinavia App model: Pass-through payments ...
Compliance Gap Analysis
Drop Gap Analysis v2 Regulatory Compliance Gap Assessment Date: 2026-02-12 Prepared for: ALAI Holding AS / Drop Payment App Source code reviewed: /Users/makinja/ALAI/products/Drop/src/drop-app/src/ Security rapport: /Users/makinja/ALAI/products/Drop/security/d...
License Application Prep
Konsesjonssøknad — Forberedelse Dokument: Forberedelse til søknad om konsesjon som betalingsforetak Hjemmel: Finansforetaksloven (LOV-2015-04-10-17), betalingssystemloven (LOV-1999-12-17-95) Virksomhet: ALAI Holding AS, org.nr 932 516 136 Produkt: Drop — betal...
Business Plan (Regulatory)
Virksomhetsplan — Drop (ALAI Holding AS) Dokument: Virksomhetsplan for søknad om konsesjon som betalingsforetak Formål: Vedlegg til konsesjonssøknad til Finanstilsynet Virksomhet: ALAI Holding AS, org.nr 932 516 136 Produkt: Drop (getdrop.no) Versjon: 1.0 Dato...
Compliance Gap (Feb 2026)
Drop Compliance Gap Analysis — Overnight Sprint 2026-02-16 TL;DR Readiness: 8/100 (per gap-analysis-v2.md, 2026-02-12) We have more than we think: 14 substantive legal draft documents (6,238 lines total) 36 API endpoints, security hardened (0 CRITICAL, 0 HIG...
Privacy Policy
Personvernerklæring for Drop Sist oppdatert: 2. mars 2026 Behandlingsansvarlig: ALAI Holding AS, org.nr. 932 516 136 Kontakt: [email protected] Nettsted: https://getdrop.no 1. Innledning Denne personvernerklæringen beskriver hvordan ALAI Holding AS («vi»,...
DPIA Assessment
Vurdering av personvernkonsekvenser (DPIA) — Drop Dokument-ID: DPIA-DROP-001 Versjon: 1.0 Dato: 12. februar 2026 Utarbeidet av: ALAI Holding AS Behandlingsansvarlig: ALAI Holding AS, org.nr. 932 516 136 Status: Godkjent 1. Innledning og bakgrunn 1.1 Formål De...
Data Processing Protocol
Behandlingsprotokoll — Drop (ALAI Holding AS) Dokument: Protokoll over behandlingsaktiviteter (GDPR artikkel 30) Behandlingsansvarlig: ALAI Holding AS, org.nr. 932 516 136 Kontakt behandlingsansvarlig: [email protected] Personvernombud: [email protected] Prod...
Outsourcing Policy
Utkontrakteringspolicy — Drop Dokument-ID: UTKONTR-DROP-001 Versjon: 1.0 Dato: 12. februar 2026 Eier: ALAI Holding AS, org.nr. 932 516 136 Klassifisering: Intern Regulatorisk grunnlag: DORA (EU) 2022/2554 art. 28-30, Finanstilsynets retningslinjer for utkontra...
AML Procedures
Hvitvaskingsrutiner — Drop (ALAI Holding AS) Dokument: Internrutiner for tiltak mot hvitvasking og terrorfinansiering Hjemmel: Lov om tiltak mot hvitvasking og terrorfinansiering (hvitvaskingsloven, LOV-2018-06-01-23) Virksomhet: ALAI Holding AS, org.nr 932 51...
AML Risk Assessment
Risikovurdering — Hvitvasking og terrorfinansiering Dokument: Virksomhetsinnrettet risikovurdering, jf. hvitvaskingsloven §6 Virksomhet: ALAI Holding AS, org.nr 932 516 136 Produkt: Drop — betalingsformidling og pengeoverføringer Versjon: 1.0 Dato: 2026-02-12 ...
Suitability Assessment
Egnethetsvurdering — Fit & Proper Dokument: Rutiner for egnethetsvurdering av styre, ledelse og nøkkelpersoner Hjemmel: Finansforetaksloven §§3-5 til 3-7 (LOV-2015-04-10-17) Virksomhet: ALAI Holding AS, org.nr 932 516 136 Produkt: Drop — betalingsformidling og...