Cybersecurity Statement
Jurisdiction: South Africa
1. Identity and access
Every person must use an individual account. Access is role-based, privilege overrides follow least privilege, tenant data is isolated, sensitive administration is restricted and idle sessions expire automatically.
2. Application and data protection
The platform applies input validation, CSRF controls, prepared data access, secure password hashing, restricted uploads, private evidence delivery, encrypted integration secrets, audit logging and database indexes supporting reliable scoped queries.
3. Operational security
Scheduled maintenance handles session revocation, queue failures, notification archiving and bounded log retention. Administrators should monitor system health, delivery failures, login anomalies and integration status.
4. Customer responsibilities
Customers must promptly disable departed users, review privileges, secure endpoints and email accounts, train users against phishing, maintain accurate emergency contacts, configure HTTPS in production and protect exported reports and printed documents.
5. Incident reporting
Suspected compromise, unauthorized access, lost devices, credential exposure or abnormal transactions must be reported immediately through the authorized support channel. Preserve relevant evidence and avoid altering affected records unnecessarily.
6. Responsible disclosure
Security researchers should avoid accessing personal information, disrupting service or exploiting beyond what is required to demonstrate a concern. Reports should include reproducible details and allow reasonable time for investigation and remediation.
Questions, complaints or data-subject requests should be submitted through the authenticated support channel or to the subscribing organization’s designated Information Officer. This public notice is general information and does not replace an organization-specific agreement or legal advice.