The Mifos Regenerative Economy Model
Executive Summary & Impact Report
From Open-Source Contributors to Ecosystem Protectors: How Educational Advocacy and Practical Mentorship Advance Global Financial Inclusivity.
This report details how the Mifos Initiative serves as a public-benefit educational engine, advancing global financial inclusivity by training and mentoring the next generation of technologists. Through a structured three-part lifecycle, new open-source contributors transform into industry practitioners who safeguard critical digital public infrastructure (DPI).
- Phase I — Genesis (Open-Source Engagement): Contributors enter via Google Summer of Code (GSoC) and Code for GoodTech (C4GT), mastering complex, distributed codebases with a mission-driven focus on financial inclusion.
- Phase II — Evolution (Enterprise Practice): Practitioners transition to enterprise environments like Nucleus Systems, mastering DevSecOps, penetration testing, and security governance under senior mentorship.
- Phase III — Regeneration (Ecosystem Leadership): Rather than suffering from regional “brain drain,” talent remains in our ecosystem. As our ecosystem is built from local partners where our software has impact, they remain locally rooted—mentoring new contributors whilst still undertaking roles in our ecosystem.
The Vision: Solving “Brain Drain” Through a Regenerative Economy
For those new to Mifos, our mission goes far beyond software development: we advocate for and build open-source digital public infrastructure that brings financial inclusion to underserved populations worldwide. However, sustainable technology requires sustainable local economies.
Traditionally, the global technology sector operates on an extractive model—identifying top technical talent in emerging regions and pulling them away from their home economies. This regional “brain drain” leaves local institutions dependent on imported, proprietary solutions.
The Mifos ecosystem and industry partners like Nucleus Systems champion a Regenerative Economy. By hiring, mentoring, and investing in local IT talent within their home regions, we create a self-sustaining cycle where practitioners build, govern, and secure the very infrastructure their communities rely on.
1. Talent Discovery → Extracted Abroad 1. Open-Source Entry → Locally Educated (Mifos/GSoC)
2. Infrastructure → Imported / Proprietary 2. Enterprise Mastery → Locally Employed (Nucleus Systems)
3. Long-Term Impact → Regional Brain Drain 3. Continued Return → Mentors & Secures Open DPI
Part I: Initial Engagement — The Open-Source Spark and Mission Alignment
The first step in the regenerative lifecycle begins with educational advocacy and public-inclusivity programs like Google Summer of Code (GSoC) and Code for GoodTech (C4GT) with the Mifos Initiative. Open-source programs provide a rigorous proving ground where contributors work with production-grade codebases, collaborate across global time zones, and develop an early appreciation for technology that serves a social purpose. They also get the chance to work with experienced open source contributors (mentors), some of whom are giving back at the end of their careers to keep open source a sustained codebase.
“Over the 13+ years Mifos has mentored interns we have seen a circular returning economy grow. Early interns starting their open-source journey with Mifos have moved onto roles in a number of companies in our eco-system. Some even starting their own. Often they then return as mentors to the next generation of interns or at the end of their careers come back to volunteer and give back to the community that helped them on this journey.”
Mifos invests heavily in this model because we believe that the digital public infrastructure powering local economies should be built, governed, and secured by local talent. This is not a side project; it is a cornerstone of our broader educational advocacy program. Over our 13+ years of deep, continuous involvement with Google Summer of Code, we have seen the compounding benefits of this investment firsthand, cultivating a vibrant, global community of over 200 alumni who have gone on to shape the fintech landscape.
Today, we are expanding that footprint. As a proud partner of Code for GoodTech (C4GT), we continue to bridge the gap between academic theory and open-source reality. This comprehensive educational program ensures that contributors don’t just learn to write functional code—they learn to build resilient, mission-driven systems that democratize financial access.
For contributors, this initial engagement fundamentally changes how they view engineering:
Akshat Sharma: From Code to Financial Inclusion
GSoC with Mifos was a turning point for Akshat. Because Mifos gave him the opportunity to represent the community at international conferences, he connected technology with practical, real-world impact. “It wasn’t just about building software,” he notes, “it was about building systems that create real-world impact, especially in financial inclusion.”
Yash Sancheti: Foundational Collaboration in Distributed Systems
Beginning his journey in 2023, Yash used his GSoC tenure to master secure software development and distributed open-source collaboration. Learning to navigate complex, large-scale codebases built the technical and communication resilience needed to tackle enterprise security challenges.
Nkep Kerlyn Manyi: Rising to High Standards
Coming from an unconventional career path, Kerlyn found that GSoC accelerated the practitioner she was already becoming. The open-source environment demanded high standards and accountability—proving her capability and fast-tracking her transition into professional cybersecurity.
Part II: Enterprise Evolution — Transitioning to Professional Practice
The second stage of the narrative occurs when mentees transition into formal corporate environments. An example of this being Nucleus Systems, a Mifos ecosystem partner.
A prime example of this evolution, Nucleus Systems is a core Mifos Ecosystem partner based in South Africa. Led by Godfrey Kutumela—a seasoned cybersecurity leader with a long-standing history of involvement within the Mifos community—Nucleus specializes in providing independent, evidence-based assurance across fintech platforms. At Nucleus Systems, open-source alumni do not merely write features; they step into mission-critical cybersecurity, trust assurance, and DevSecOps engineering across production financial ecosystems.
But why does a high-stakes enterprise firm like Nucleus look specifically to Mifos interns as a primary feeder of talent? The answer lies in the open-source crucible. By the time these contributors transition into corporate roles, they have already proven their ability to navigate massive, distributed codebases, collaborate across global time zones, and align their technical work with real-world impact. They arrive not just as junior developers seeking training, but as mission-tested engineers equipped to tackle systemic security challenges from day one.
The Nucleus Systems Mentorship Model: Why Open-Source Talent Thrives
Under the leadership of Godfrey Kutumela, young talent is cultivated through five core pillars that bridge technical execution with business strategy:
This environment accelerates technical depth and professional maturity across diverse specializations:
Akshat Sharma: End-to-End Ownership & Production Security
Core Focus: SAST/SCA Analysis & Large-Scale Systems Testing
At Nucleus Systems, Akshat transitioned from feature development to in-depth security assessments across massive production codebases. He was entrusted with Static Application Security Testing (SAST) and Software Composition Analysis (SCA) across a portfolio of vital fintech and digital public infrastructure systems:
- Tazama & OpenG2P: Executed security analysis for financial integrity monitoring systems and digital public infrastructure designed for inclusive financial ecosystems.
- Crosslake, Paysys Labs & Ringstone: Performed security assessments on complex fintech integrations and system components.
- Mifos Core Security: Conducted in-depth SAST and SCA audits to strengthen the underlying Mifos open-source ecosystem.
With Godfrey Kutumela’s sponsorship and continuous mentorship, Akshat expanded his formal credentials—clearing both the CompTIA PenTest+ and Linux Foundation Security Essentials certifications. “I wasn’t just assigned tasks,” Akshat explains. “I was trusted to think through problems, suggest improvements, and take responsibility for end-to-end solutions.”
Yash Sancheti: DevSecOps & Security-First Architecture
Core Focus: Automated Security Pipelines & Vulnerability Testing
Yash’s professional evolution centered on embedding security directly into the software development lifecycle. Instead of treating security as a final audit, Yash builds DevSecOps integrations that make resilience an engineering standard:
- Pipeline Automation: Developed scripts and internal tooling to detect CI/CD pipeline failures, inconsistencies, and vulnerabilities at scale.
- Secure Design: Evaluated system architectures through the lens of risk, ensuring robustness from initial design to production operations.
- Business-Risk Alignment: Learned to view engineering decisions through organizational goals—understanding how security directly supports business continuity.
“Through [Godfrey’s] mentorship, I’ve learned how to think not just as an engineer, but as someone who understands how businesses operate, how security aligns with organizational goals, and how decisions are made in real industry environments,” Yash notes.
Nkep Kerlyn Manyi: From Technical PenTesting to Security Governance
Core Focus: Penetration Testing, Client Communication & Policy Development
Kerlyn’s trajectory highlights the rapid professional growth possible in a practitioner-led culture. Starting with penetration testing and DevSecOps engagements, she was given stretch assignments by Godfrey to expand into Security Governance and Policy Development:
- Translating Vulnerabilities for Business: Realized that identifying a flaw is only half the job. “If you cannot explain a vulnerability in a way that a non-technical client understands and acts on, then the work has not really landed.”
- Documentation as Resilience: Mastered the discipline of comprehensive reporting—recognizing that an undocumented finding is an unmitigated organizational risk.
- Dedicated Industry Sponsorship: Provided with access to paid industry platforms and sponsored for prestigious global conferences, including a commitment for DEF CON 33.
“In Godfrey, I found not just an employer but a champion who believes in my potential and backed that belief with action,” Kerlyn shares. “This is not just a job for me. This is exactly where I am supposed to be.”
Part III: Continued Engagement — Re-Investing in the Open-Source Ecosystem
What makes this narrative truly regenerative—and what sets Mifos educational advocacy apart from traditional technical internships—is the third phase: **continued engagement and ecosystem return**.
Instead of exiting the open-source community after advancing their careers, these practitioners actively give back. They mentor incoming GSoC students, contribute code reviews, and address shared, systemic vulnerabilities across digital public infrastructure.
| Practitioner | Phase I: Initial Spark (Mifos/GSoC) | Phase II: Enterprise Evolution | Phase III: Continued Return |
|---|---|---|---|
| Akshat Sharma | Connected coding to real-world financial inclusion; represented Mifos globally. | SAST/SCA security testing across production fintech systems (Tazama, OpenG2P). | Continuous security assessment of Mifos core; fostering mission-driven mindset. |
| Yash Sancheti | Built foundation in secure development and distributed open-source collaboration. | DevSecOps automation, CI/CD pipeline security, and secure architecture analysis. | Actively mentors new contributors; leads community initiatives & workshops. |
| Nkep Kerlyn Manyi | Thrived under high open-source standards; proved readiness for complex roles. | PenTesting, risk translation for non-technical clients, and security governance. | Advocates for non-traditional paths; champions mentorship (“Bring someone with you”). |
“Giving back to the open-source community aligns directly with our belief that digital trust is an ecosystem responsibility, not an individual one… Contributors help identify vulnerabilities, improve secure coding practices, and enhance the robustness of platforms that operate at scale. Importantly, their work often surfaces shared risks across reused components, which is critical in open ecosystems where vulnerabilities can propagate across multiple implementations.”
When contributors return to audit code, improve architectures, and mentor new students, they safeguard the shared dependencies that financial inclusion platforms rely upon. This closes the loop: **educational advocacy builds local practitioners, practitioners build secure enterprise infrastructure, and those same practitioners return to fortify the public open-source ecosystem.**
In this report, we have focused on the experience with Nucleus Systems, a Mifos Ecosystem Partner, as an illustrative example of how this works. However, this is not a one-off or single-region approach. Instead, Mifos sees this exact model being adopted across a number of partners in its ecosystem. Whether in Europe, Latin America, Africa, or Asia, we see similar approaches and the Regenerative model in action—all driven by Mifos’s continued investment in Educational Advocacy.
Building a Sustainable, Trustworthy Digital Future
The experiences of Akshat Sharma, Yash Sancheti, and Nkep Kerlyn Manyi demonstrate that financial inclusivity and enterprise cybersecurity go hand-in-hand. By supporting local IT talent through every stage of their professional journey—from open-source discovery to enterprise leadership—Mifos and its partners are building a regenerative economy that stops brain drain and ensures digital trust for all.









