Skip to content
@jolarca-dev

jolarca-dev

Journey of Life — Marketplace Platform

Building the most compliant marketplace in the Baltics.


🏗️ Architecture

We operate a 90/10 hybrid infrastructure topology:

  • 90% Bare Metal — Hardened PostgreSQL, Vault, MinIO, WireGuard mesh (Ansible-managed)
  • 10% GCP — GKE, Cloud DNS, IAM (Terraform-managed)
  • Zero Trust — No public IPs, CMEK encryption everywhere, two-person rule for production changes

📦 Repository Fleet

Repository Purpose Visibility
jolarca Platform application (Django + Next.js) Public
jolarca-infrastructure IaC: Terraform, Ansible, K8s, WireGuard Public
jolarca-compliance SOC 2 / ISO 27001 / GDPR evidence Private
jolarca-legal Contracts, ToS, VAT OSS filings Public
jolarca-data Analytics, retention-as-code, schemas Private

🛡️ Compliance Posture

We take compliance seriously — it's not an afterthought, it's architecture.

Standard Status Anchor
SOC 2 Type II 🟢 Aligned CC6.1, CC7.2, CC8.1
ISO 27001:2022 🟢 Aligned A.5-A.18 controls
GDPR 🟢 Compliant Art. 5, 17, 25, 30, 32
PCI-DSS 🟢 SAQ-A Stripe-hosted payments

Key principles:

  • Retention as code — Policy is executable, not prose
  • Evidence integrity — Every audit artifact is hashed and manifest-tracked
  • Payment boundary — PCI scope isolated from marketplace logic
  • Data residency — EU-only processing, no transfers without TIA

🌍 Markets

Pilot: Lithuania 🇱🇹
Expansion: Latvia 🇱🇻, Estonia 🇪🇪 (Q1 2027)
Target: EU-27 by 2028

🔒 Security

  • Bug bounty: Coming soon
  • Vulnerability disclosure: See SECURITY.md in each repository
  • Security contacts: security@jolarca.com

📚 Documentation

🤝 Contributing

We follow Conventional Commits and enforce:

  • Pre-commit hooks (gitleaks, terraform fmt, checkov)
  • Two-person rule for security-sensitive paths
  • Plan-first change management (no direct pushes to main)

See CONTRIBUTING.md in each repository for details.


Built with paranoia. Shipped with confidence.

Popular repositories Loading

  1. jolarca-infrastructure jolarca-infrastructure Public

    Marketplace infrastructure-as-code and provisioning (scope-segregated from church-platform infra).

    HCL

  2. jolarca-compliance jolarca-compliance Public

    Marketplace compliance evidence and audit records (ISO 27001 / SOC 2 / PCI-DSS).

    Python

  3. jolarca-legal jolarca-legal Public

    Marketplace legal artifacts: contracts, terms, privacy notices, VAT OSS filings.

    Python

  4. jolarca-data jolarca-data Public

    Marketplace data schemas and migrations (no production data in git).

    Python

  5. jolarca jolarca Public

    Marketplace platform application code (PCI-DSS payments, KYC/AML, VAT OSS scope).

    TypeScript

  6. .github .github Public

    Organization-wide defaults: reusable workflows, templates, and profile

Repositories

Showing 6 of 6 repositories

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Top languages

Loading…

Most used topics

Loading…