Hosting & infrastructure
The platform runs on enterprise cloud infrastructure (AWS), with services containerised and deployed behind a hardened gateway. All traffic is encrypted in transit with TLS; data at rest is encrypted at the storage layer.
Tenant isolation
Isolation is enforced at the database, not just in application code: every tenant's rows are protected by PostgreSQL row-level security, and each service connects with least-privilege credentials that cannot bypass those policies. One tenant's data is invisible to another's queries by construction.
Identity & access
Single sign-on across every module, built on the OpenID Connect standard. One identity per person, role-based access per module, and central administration of joiners, movers and leavers.
Auditability
Binding actions are written to a signed, append-only audit ledger — tamper-evident by design. Every AI recommendation carries its evidence; every approval records who, when and on what basis.
Data residency
Regional hosting options are available per engagement; personal-information handling is described in our privacy policy (POPIA-aligned).
Certifications & standards
We are deliberate about certification language — three phrases, used honestly:
- Certified — independently audited and certificate in hand.
- In progress — engagement underway with an auditor, not yet certified.
- Designed to align — built to the standard's requirements; certification not (yet) pursued.
A standard appears on this page only once its status is confirmed, which is why you will not find a wall of logos here. Our current position against ISO 27001, SOC 2, POPIA, GDPR and ISO 45001 is provided in writing for a specific engagement — ask us and you will get a straight answer rather than an aspiration.