Case Study · Financial Data / Security & Compliance
Locking down the nation’s credit data — without losing a second
How Khwarizm brought encryption, privileged-access control, and data redaction to i-Score’s Oracle platform — meeting Central Bank of Egypt requirements with near-zero downtime and under 2% performance cost.
Some databases you simply cannot afford to get wrong. i-Score, the Egyptian Credit Bureau, holds the credit histories of the country’s consumers and small businesses — the records that decide whether a loan is granted, at what rate, and to whom. Protecting that data is a matter of national trust. Khwarizm was engaged to harden it: to layer strong encryption, access control, and redaction across i-Score’s Oracle platform, in the main and disaster-recovery sites, to meet Central Bank of Egypt requirements — and to do it without taking the service down and without slowing the reports lenders depend on.
The vault at the heart of Egyptian lending
Almost every formal credit decision in Egypt touches i-Score. The bureau holds close to all of the consumer and SME credit data reported by the country’s banks, and lenders query it in real time before they approve a card, a loan, or a line of credit. That makes its database two things at once: a high-value target that must be protected to the highest standard, and a latency-sensitive engine that has to answer fast, all day, every day.
Those two demands usually pull against each other — and that tension was the whole challenge.
A regulator’s mandate, and a hard constraint
The Central Bank of Egypt set the bar: sensitive credit data had to be protected with strong, demonstrable controls — encrypted, access-governed, and shielded from misuse. Compliance was not optional.
But i-Score could not simply be switched off while it was re-engineered. It is mission-critical infrastructure for the entire lending sector, running across primary and disaster-recovery sites that must stay in step. So the work carried three hard constraints at once: add heavy security without meaningfully slowing the database, apply it consistently across main and DR, and do it all with minimum downtime to a live national service.
Three layers of protection
Khwarizm implemented a defense-in-depth stack on i-Score’s Oracle platform, each layer closing a different risk:
Oracle Transparent Data Encryption secures the data at rest — so datafiles and backups are unreadable if the underlying media is ever stolen or copied, without any change to the applications above.
Oracle Database Vault enforces separation of duties and locks down privileged access — so that even highly privileged administrators cannot reach the credit data itself. It closes the insider-risk gap that pure encryption leaves open.
Oracle Data Redaction masks sensitive fields in query results in real time, according to policy — so users and applications see only what they are entitled to see, while the stored data is never altered.
On engineered hardware, across two sites
The platform runs on Oracle SuperCluster, the engineered system that consolidates compute, storage, and networking for exactly this kind of demanding, consolidated workload. Khwarizm applied the full security stack on SuperCluster in both the main and disaster-recovery sites, so protection and behavior are identical wherever the service runs — and a failover never means a drop in either security or performance.
Hardened live, with the lights on
Because the bureau serves the whole lending sector, the rollout was engineered for minimum downtime. The controls were introduced in a carefully sequenced, tested progression across the estate, keeping the service available to lenders throughout and keeping the primary and DR environments consistent at every step.
We raised our data protection to exactly what the Central Bank asked for — encryption, access control, redaction — and our lenders never saw a slowdown, or an interruption.
Secure — and still fast
The hardest part was proving that security did not have to cost speed. Adding encryption, a privileged-access layer, and real-time redaction to a heavily queried database would, done naively, slow it noticeably. Khwarizm tuned relentlessly — so that after the full security stack was live, full report queries still returned in under five seconds, and the measured overhead the security layers added came in at under 2% of query latency.
For a system where lenders wait on every answer, that is the difference between a control that is adopted and one that is quietly worked around. Here, the protection is invisible in the one place it should be: the clock.
The results
i-Score now meets the Central Bank of Egypt’s data-protection requirements with a defense-in-depth platform — encrypted at rest, governed against privileged misuse, and redacted at query time — across both of its sites. And it did not trade a single second of performance to get there. For an institution whose entire value rests on being both trusted and fast, that is the whole point: the nation’s credit data is locked down, and the reports the market runs on are as quick as they ever were.