Advisory for critical IT platforms — and the software that proves it.
ODYNEA advises Moroccan institutions on infrastructure, architecture and business continuity. We also publish the software that turns those obligations into evidence a regulator will accept.
Two practices that answer to the same standard.
We work on systems an organisation cannot afford to lose. Whether we are advising on an architecture or shipping a product, the test is the same: can you demonstrate, afterwards, that it was done properly?
Advisory and assistance
We sit on the client's side of the table. Feasibility studies, architecture review, specification, tender analysis, acceptance testing and production rollout — you remain the project owner, we provide the technical judgement.
Business continuity
Design, formalisation and testing of continuity and disaster-recovery plans. Most organisations own recovery infrastructure; far fewer test it. We treat the test as the deliverable.
Software publishing
Three platforms of our own, covering operational resilience, information security management and AI data governance for regulated sectors.
Four phases, each feeding the next.
Every project passes through the same sequence, and the output of one stage is the input of the following one. Skipping a stage does not save time; it moves the cost later.
-
Study and advisory
Technology watch and benchmarking, requirements definition, analysis of the existing estate, feasibility study, architecture selection, technical specification, and analysis of tender responses through to award.
-
Delivery assistance
Verification that what is delivered matches the specification: architecture certified free of single points of failure, vendor recommendations and good practice applied, deliverables and documentation checked.
-
Implementation assistance
Technical acceptance and qualification, pilot sites, production rollout with a rollback plan, post-deployment supervision, and a closing review of what the project returned.
-
Technical assistance and support
Ongoing support by email, telephone, VPN access or on site; managed operations; and scheduled service days drawn down over the year.
Software in production today.
Each platform addresses a distinct obligation faced by regulated organisations in Morocco and beyond.
-
Valendir — Operational Resilience Command Center
Real-time command centre, evidence vault and compliance automation for BAM, DORA and ISO 22301. Built for live response, and for the audit that follows it.
-
Hisn — Information security management
A management system aligned to ISO/IEC 27001: controls, documentation, review cycle, and the evidence required at certification and surveillance audits.
-
AI Data Defence — Sovereign AI data governance
A control post that inspects requests and files sent to AI services — from browsers, desktop applications and code editors — within Moroccan jurisdiction, before they cross a border. Sensitive data is detected and either anonymised or blocked, and every decision is written to a tamper-evident audit log.
Who you will actually be working with.
ODYNEA is a small firm by design. The person who scopes an engagement is the person accountable for delivering it — you deal directly with the engineer who made the call, not with an account manager relaying it.
That matters most in the work we are hired for. Certifying an architecture free of single points of failure, ruling on a tender, or standing next to a client during a real continuity activation are not tasks that survive being passed down a chain.
It is also why we stay on the client's side of the table. We do not resell the solutions we assess, so a recommendation costs us nothing to make honestly.
We run the platform we recommend.
Our products are not hosted on someone else's managed service. They run on a Kubernetes platform we build, operate and answer for ourselves — which is why our advice on infrastructure comes from operating it, not from reading about it.
- Kubernetes platform engineering — cluster design, sizing and lifecycle
- Container runtime, networking and multi-tenant workload isolation
- Ingress and automated TLS, with certificates issued and renewed unattended
- Persistent block storage, replication, snapshots and tested restore
- Private container registry and supply-chain control
- Observability — metrics, dashboards, alert routing and on-call escalation
- CI/CD on self-hosted runners, with GitOps-driven deployment
- Encrypted secrets management committed safely to version control
- High availability, backup and disaster recovery across sites
Discuss a project with us.
Tell us what you need to study, build, secure or bring into compliance. We reply with a written scope, a timeline and a price before any work begins.