Skip to main content
Skip to main content

Trust Center

Security and privacy you can verify.

A compliance product has to hold itself to a higher standard than its customers. Everything here is implemented and verifiable. Where a certification is still in progress, we say so plainly — no badges we have not earned.

Compliance posture

Where we stand on certifications.

We are an early-stage company building toward formal certification. Rather than imply we already hold reports we don’t, here is the honest status of each framework.

POPIA (South Africa)

Operational

POPIA-native by design. We have appointed an Information Officer and operate the section 18 notice, 30-day data-subject-request workflow, 72-hour breach process, ROPA, and DPIA tooling.

GDPR

Aligned

EU/UK data-subject rights honoured, Standard Contractual Clauses for cross-border transfers, and a processor-grade Data Processing Agreement available to every customer.

SOC 2 Type II

In progress

Our controls are implemented and operating, and we run them through SecureByte itself. We are not yet certified — a formal independent audit is planned and in our pipeline.

ISO/IEC 27001

In progress

Our information-security management controls are aligned to ISO/IEC 27001:2022. Formal certification is planned and not yet held.

PCI DSS

Scope minimised

Card data never touches SecureByte. Payments are handled by PayFast, a PCI-DSS-compliant gateway; we store only an encrypted recurring-billing token.

Our transparency commitment.We dogfood SecureByte to run our own compliance programme — when the platform is audit-ready for us, it is audit-ready for you. Until a certificate is issued, we will only ever describe a framework as “in progress” or “aligned”, and we are happy to share our current control evidence under NDA.

Security

The controls behind the platform.

A summary of the safeguards that protect customer data every day. The full, control-by-control detail lives on the Security page.

Encryption everywhere

  • AES-256-GCM encryption at rest, including client-side (zero-knowledge) encryption of uploaded evidence.
  • TLS 1.2/1.3 in transit with HTTP Strict Transport Security.
  • Per-tenant key separation and key-rotation tooling. Customer-managed encryption keys for SecureByte-held data are not yet available; Bring-Your-Own-Key at Enterprise covers AI provider credentials only.

Tenant isolation

  • PostgreSQL Row-Level Security is force-enabled on tenant tables.
  • One organisation can never read another organisation’s data — enforced at the database layer.
  • Application-level checks provide defence in depth on top of the database boundary.

Identity & access

  • Two-factor authentication, single sign-on (SAML 2.0 / OIDC), and SCIM provisioning.
  • Role-based access control with separation-of-duty safeguards.
  • Per-organisation IP allowlisting and tuned per-route rate limiting.

Tamper-evident audit trail

  • Append-only, HMAC hash-chained audit logs with database-enforced immutability.
  • Daily integrity roots anchored to write-once (WORM) storage for external verification.
  • Per-customer legal hold prevents deletion of evidence under disputed audits.

Data residency

  • Customer data hosted in AWS Cape Town (af-south-1) by default.
  • EU (eu-west-1) or US (us-east-1) residency available at Enterprise and Enterprise+.
  • Cross-border processing limited to scrubbed observability and optional AI tooling.

Privacy by default

  • No advertising or cross-site tracking. We never sell personal information.
  • Only strictly-necessary cookies plus first-party, privacy-masked telemetry.
  • Sub-processors are minimised, disclosed, and bound by data-processing agreements.

Data & privacy

Your data stays yours — and stays in South Africa.

SecureByte is the operator of the personal information you process through the platform. You remain the responsible party, and our agreements reflect that.

Customer data is hosted in AWS Cape Town (af-south-1) by default, with EU or US residency available at Enterprise tiers. We minimise sub-processors and disclose every one of them, and we never use your data to train third-party AI models.

You can exercise access, correction, deletion, and objection rights at any time, and our Data Processing Agreement sets out the technical and organisational measures, the 48-hour breach-notification commitment, and the sub-processor flow-down in full.

Report a vulnerability

Found something? Tell us.

We accept responsible disclosure of security issues. Email security@securebyte.co.za and a founder will respond within 48 hours. For sensitive reports, request our PGP public key in your first message and we will share it for encrypted follow-up.

We aim to fix confirmed critical issues within 7 days and coordinate public disclosure no earlier than 90 days after a fix is available. We do not currently run a paid bug-bounty programme.

Need the full security-questionnaire pack?

SIG-Lite and CAIQ-style answers, the MSA, the DPA, and our sub-processor list are all on hand. Ask in your first email and we will send them over.