Trust
Built for regulated programmes from the first line of code.
POPIA-safe by default. Biometric templates never leave our infrastructure. Every record has an audit trail row exportable as JSON.
99.94%
Uptime (90d)
Rolling
< 8m
Mean incident response
Business hours
AES-256
Encryption at rest
Every record
0
POPIA breaches
Since launch
Controls
Defence in depth.
POPIA gate
Every message and every capture logged with timestamp. Revocable on request. Data-subject requests fulfilled within 7 days.
Biometric policy
Face + voice templates encrypted at rest, never used in denominator for KPIs. B+V ≥ 80% threshold for compliance.
Audit log
Every record — who saw what, when, from which device. Exportable JSON per programme, per cohort, per period.
Hosting
AWS eu-central-1 (Frankfurt) primary. af-south-1 (Cape Town) disaster recovery. RPO 5m, RTO 30m.
Penetration testing
External pen-test quarterly. Report available under NDA. Latest: April 2026, no critical findings.
Sub-processors
AWS, WhatsApp Business API, Sponsor Bank (TPPP), Twilio (OTP). Full list and DPAs on request.
Sub-processors
Who touches your data.
| Vendor | Purpose | Region |
|---|---|---|
| AWS | Compute, storage, database | eu-central-1 · af-south-1 |
| WhatsApp Business API | Participant messaging | Meta EU |
| Sponsor Bank (TPPP) | Cashout payment rail | ZA |
| Twilio | OTP delivery | ZA · EU |
| Anthropic | Model inference (Haiku, Sonnet) | US · EU |
| Sentry | Error monitoring | EU |