Security & compliance

Built so the compliance review is short.

The answers your compliance team needs, in plain language — POPIA, residency, zero data retention and tokenisation, applied to every build from day one.

Controls in place

  • POPIA compliance
  • Data residency · SA
  • Zero data retention
  • PII tokenisation
  • AES-256 encryption
  • RBAC + MFA, full audit logs
Applied to every engagement
The controls

What's in place on every build.

C-01In place

POPIA compliance

Information Officer registered with the SA Information Regulator

C-02In place

Data residency · SA

Storage, processing and backups stay in-region

C-03In place

Zero data retention

Contractually agreed with the model provider

C-04In place

PII tokenisation

Identifiers swapped for tokens before any model call

C-05In place

Encryption

AES-256 at rest, TLS 1.2+ in transit

C-06In place

Access control

RBAC with MFA, full audit logs, SAML/OIDC on request

Bring compliance to the first call.

Send your due-diligence questionnaire to hello@pallisadedata.com and we'll return it completed. No portal, no ticket.

Book a consult