CVE commitment
Proving compliance starts with knowing where every datum lives.
Know where every datum lives, and keep it in Nigeria
OpenMetadata for catalogue, classification and lineage; S3-compatible object storage and HDFS for the data itself. The block that gives your Chief Compliance Officer evidence instead of assurances.
- OpenMetadata
- MinIO
- Ceph
- Hadoop / HDFS
The technologies we cover
Products in this family

OpenMetadata
Open-source metadata platform: data catalogue, automated discovery, classification tags, column-level lineage, data quality tests and policy enforcement.
KubernetesPrivate cloudAir-gappedOfficial support
MinIO
High-performance S3-compatible object storage in a single binary, with erasure coding, Object Lock (WORM), versioning and site replication.
Bare metalKubernetesPrivate cloudAir-gappedOfficial support
Ceph
Unified software-defined storage delivering S3 object (RGW), block (RBD) and file (CephFS) from the same cluster, for multi-petabyte estates.
Bare metalKubernetes (Rook)Private cloudOfficial support
Apache Hadoop / HDFS
Distributed file system and YARN scheduler for existing data lakes; supported in place or as the source of a migration to object storage and Iceberg.
Bare metalPrivate cloudAir-gappedOfficial support
Why it matters for data localisation
Where this family meets the CBN directive
The CBN data-localisation directive sets a deadline of 1 January 2027 for primary processing, databases, backups, identity and access management, encryption keys and audit logs to reside in Nigeria, with no dependency on a foreign cloud. The hardest part of that obligation is not moving the data; it is proving where it is. An inspection will ask which systems hold customer and payment data, which copies exist, where the backups sit, who can access them and where the keys are. Most institutions cannot answer from a single source of truth. This family provides that source: OpenMetadata discovers and classifies data across databases, warehouses, streams and object stores, records lineage from origin to report, and produces the residency evidence the CCO signs. Underneath, S3-compatible object storage and HDFS keep backups, archives and the data lake on hardware in Nigerian data centres, with immutability and encryption keys under your control. Nothing here is legal advice; your compliance team should confirm the scope that applies to your institution.
The journey with NuxFamily
- 01Assess
- 02Design
- 03Build
- 04Migrate
- 05Operate
- 06Evolve
Every family is delivered through the same six-stage journey, with official 24×7 support and knowledge transfer built in.
Our expertise
Credentials, not adjectives
We have built Hadoop data lakes for banks and insurers since the early 2010s, and over the past five years we have migrated most of them to S3-compatible object storage with Iceberg tables on top. Our team runs MinIO and Ceph clusters for regulated customers where retention and immutability are contractual, and has deployed OpenMetadata as the catalogue of record for data-protection programmes under GDPR. That combination of catalogue and storage is what the CBN directive now asks of Nigerian institutions.
Sectors
- banking
- insurance
- retail
- industry
10+
Years with these technologies
20+
Production deployments
8 PB of S3-compatible object storage across two data centres
Largest scale delivered
Official vendor support
Support tiers for this family
Essential
- Coverage
- 8×5, Nigeria business hours
- P1 response
- 4 h
- Corrective support for OpenMetadata, MinIO, Ceph and HDFS
- Security patches for the supported release lines
- Access to the knowledge base and ticket portal
- Guidance on connector, bucket and lifecycle configuration
Business
- Coverage
- 24×7
- P1 response
- 1 h
- Everything in Essential
- Proactive monitoring of storage health, capacity and replication lag
- Quarterly health checks: erasure-set balance, scrub results, catalogue freshness
- Version management and minor-upgrade execution
- Assistance with new ingestion connectors and lineage coverage
Mission Critical
Most chosen- Coverage
- 24×7 with a named engineer
- P1 response
- 15 min
- Everything in Business
- Named engineer who knows your storage and catalogue estate
- Architecture review twice a year
- Major-upgrade support (Ceph releases, MinIO server, OpenMetadata majors)
- Support in CBN inspections: residency evidence and lineage extracts
Version policy
Response times and tier names are indicative and confirmed contractually.
Use cases
How it is used in a regulated bank
Use case 01
Data mapping for the CBN directive
A bank must show the regulator which systems process, store and back up Nigerian customer and payment data, and where each of them runs. The information is spread across spreadsheets maintained by different teams and is out of date within weeks. The CCO wants an automated, evidenced map.
Technologies
- OpenMetadata
- PostgreSQL
- Apache Kafka
- MinIO
Expected outcome
The bank has a living inventory of in-scope data with a location for each copy, refreshed automatically. Remediation work is prioritised from the gap list rather than from memory.
Metric: Full inventory of in-scope assets within 6 weeks, with 100 % of payment-data columns tagged and located
- 1Connect every source. OpenMetadata connectors are pointed at core databases, the warehouse, Kafka, object storage buckets and the BI layer.
- 2Discover automatically. Schemas, tables, topics and buckets are crawled on a schedule; new assets appear without manual registration.
- 3Classify payment data. Pattern and sample-based classifiers tag columns holding BVN, account numbers, card data and personal identifiers; stewards confirm.
- 4Attach location. Each asset is tagged with hosting site, jurisdiction and provider, including backup targets and key-management location.
- 5Find the gaps. A saved query lists every asset tagged as payment data whose location is outside Nigeria or unknown.
- 6Produce the evidence. The map is exported as a signed report with timestamps and the crawler run history behind it.
Use case 02
End-to-end lineage of a regulatory report
Use case 03
Archiving and retention on S3-compatible storage in Nigeria
Reference architecture
What a compliant deployment looks like
Sources
Catalogue and governance
Storage in Nigeria
Consumers
Migration path
From where you are to a compliant platform
01
2-3 weeksDiscovery
Activities
- Inventory data platforms, backup targets and storage contracts, including foreign cloud buckets
- Interview data owners and compliance to agree classification categories
- Deploy OpenMetadata in a sandbox and connect the first three sources
- Draft the retention and immutability matrix
02
4-6 weeksCatalogue rollout
Activities
- Connect all in-scope databases, warehouse, streams, BI and object stores
- Run classifiers and have stewards validate payment-data tags
- Enable OpenLineage on pipelines and parse SQL lineage
- Define location properties and the gap query
03
4-8 weeksStorage build and repatriation
Activities
- Deploy MinIO or Ceph across two Nigerian sites with local key management
- Migrate foreign bucket contents with checksum verification
- Repoint backup software and applications to the local endpoint
- Bring HDFS under support or plan its migration to object storage
04
2-3 weeksRetention and evidence
Activities
- Apply Object Lock and lifecycle rules per retention class
- Register every bucket and lake path in the catalogue with its class and location
- Produce the first residency evidence pack and lineage extracts
- Confirm and document deletion at the foreign provider
05
OngoingOperate
Activities
- 24×7 support under the agreed tier
- Quarterly restore tests and catalogue freshness review
- Capacity planning and controlled upgrades
FAQ
Questions architects ask us
Institutions are expected to show where in-scope data is processed, stored and backed up, who can access it and where encryption keys are held. In practice that means an inventory with a location for every copy, kept current, plus the contracts and technical controls behind it. OpenMetadata gives you the inventory and the history of how it was produced. This is not legal advice; confirm the required format with your compliance function.
OpenMetadata is Apache 2.0 licensed, runs entirely on your infrastructure and ships with connectors for the databases, warehouses, streams and BI tools banks actually use. It covers discovery, classification, column-level lineage and data quality in one product with a stable API. It has no dependency on a vendor cloud, which matters under the directive.
MinIO is simpler to operate and very fast for S3 workloads such as backups, archives and lakehouse tables. Ceph is the choice when you also need block storage for virtual machines or file storage from the same cluster, or when the estate reaches many petabytes. We support both and help you choose from your workload mix and team.
Yes. We support Hadoop 3.x in place, including security hardening and upgrades. Many customers keep HDFS for existing batch workloads while new data goes to object storage with Iceberg tables, and migrate the remaining datasets over time. We plan that path with you rather than forcing a big-bang move.
Object Lock in compliance mode prevents any user, including root, from deleting or overwriting an object before its retention date. It is enforced by the storage platform, not by procedure, which is what auditors look for. We switch it on only after a dry run in governance mode and legal sign-off, because it cannot be undone.
Keys stay under your control in an HSM or key-management service in Nigeria; the storage platform requests them at runtime and never holds them at rest. This satisfies the directive's requirement that keys are localised and gives you the ability to revoke access to an entire archive if required.
NuxFamily engineers provide the support directly on OpenMetadata, MinIO, Ceph and Hadoop, from first response to root cause. Coverage includes security patches, upgrades, capacity reviews and, on the Mission Critical tier, a named engineer and assistance with evidence extraction during CBN inspections. The exact SLA terms are set out in the support agreement.
Over two decades
Built by the team behind the platforms of Santander, ING, Bankinter, Mapfre and Inditex
More than twenty years designing, building and operating private clouds for institutions that cannot afford to fail, and a delivery model where we stay with you from assessment to operation.
See our track record20+
Years building private clouds
40+
Private clouds delivered
Talk to an architect about this family
Tell us where you are today and we will come back with a first view of the target architecture and the migration path.