Security
How we secure the platform.
A compliance product has to hold itself to a higher standard than its customers. Every control listed below is implemented and verifiable. The few items still on the roadmap are labelled honestly — no "coming soon" sleight of hand.
Controls
What's implemented today.
Every group below corresponds to a question we routinely see on procurement questionnaires.
Data residency & encryption
Customer data hosted in AWS af-south-1
LiveCape Town region by default. Enterprise+ may opt into eu-west-1 or us-east-1.
Encryption at rest — AES-256
LiveEvidence objects use S3 server-side encryption under AWS-managed keys. Sensitive fields use AES-256-GCM under a per-tenant derived key.
Encryption in transit — TLS 1.3
LiveAll API and dashboard traffic. HTTP requests redirect to HTTPS at the edge.
Identity & access
OIDC SSO for every tier (Google + Microsoft)
LiveDefault sign-in for Foundation users. No password-based fallback for SSO orgs.
SAML 2.0 SSO at Scale and above
LiveOkta, Azure AD, OneLogin, JumpCloud. SP-initiated and IdP-initiated flows.
SCIM 2.0 provisioning at Enterprise
LiveJoiner-mover-leaver lifecycle stays in lockstep with your IdP.
Scoped RBAC at Enterprise
LivePer-business-unit, per-cloud-account access scoping.
Application controls
CSRF protection
LiveDouble-submit cookie pattern + Origin/Referer validation on all state-changing endpoints.
Per-IP and per-account rate limits
LiveTuned per route — login, registration, password reset, marketing-form ingest.
Row-Level Security in Postgres
LiveTenant boundary enforced at the database layer; the application is defence in depth.
AI-output attestation
LiveEvery AI-generated artefact is labelled and requires human attestation before it appears as evidence.
Audit chain & evidence integrity
Append-only audit log
LiveEvery state change is recorded. The audit log table is INSERT-only at the database role level.
Merkle-anchored daily root
LiveDaily root committed to S3 Object Lock — tamper-evident and externally verifiable.
Legal hold
LivePer-customer legal hold prevents deletion of evidence under disputed audits or investigations.
Payments & PII handling
PayFast handles all card data — PCI DSS Level 1
LiveNo card numbers ever touch SecureByte infrastructure. We store an encrypted recurring-billing token only.
POPIA s.18 notice on data collection
LiveMarketing form ingest captures only what is needed for follow-up; full notice in /legal/privacy.
POPIA s.22 breach workflow
LiveRegulator-ready breach notification template available at Enterprise+ tier.
Backups, DR, and continuity
Postgres point-in-time recovery
LiveContinuous WAL archival; restore to any second within the retention window.
Cross-AZ replication
LiveProduction data replicated synchronously across af-south-1 availability zones.
SOC 2 Type II report (in scope)
RoadmapCurrently running our own controls through SecureByte; a formal auditor engagement is planned and in our pipeline.
ISO 27001 certification (in scope)
RoadmapSame plan as above. We are dogfooding the platform — when it is audit-ready for us, it is audit-ready for you.
Report a vulnerability
See something? Send us a structured report.
We do not currently run a public bug-bounty programme. We do accept responsible disclosure via email at security@securebyte.co.za. A founder will respond within 48 hours.
For high-severity issues affecting customer data, you can use our PGP key (fingerprint published on /trust). We commit to fixing critical issues within 7 days of confirmed report and coordinated public disclosure no earlier than 90 days after fix availability.
Want the full security-questionnaire pack?
SIG-Lite + CAIQ-style answers, MSA, DPA, sub-processor list — all on hand. Ask in your first email.