Security & Compliance

Security Controls and Assurance Readiness

SalesPro Hub provides layered product security and privacy-supporting controls. Formal SOC 2 and ISO/IEC 27001 assurance work is still in progress; no report or certificate is claimed.

POPIA-Aligned Controls

Privacy, access, consent, and data-handling controls designed around POPIA requirements

Four Pillars of Security

Our security architecture is built on four fundamental pillars that ensure comprehensive protection of your data and systems.

Data Encryption

Layered transport, credential, application-field, and mobile offline-data protections.

  • HTTPS/TLS required for production application traffic
  • Passwords stored using one-way password hashing
  • Selected secrets and sensitive fields encrypted by the application
  • Identity-scoped authenticated encryption for sensitive mobile offline caches
  • Signed webhooks and signed managed-connector update packages

Access Control

Multi-layered authentication and authorization systems.

  • Multi-factor authentication (MFA)
  • Role-based access control (RBAC)
  • Tenant-aware authorization boundaries
  • Hashed, scoped, expiring and revocable API keys
  • Managed connector enrollment restricted to Enterprise tenants

Infrastructure Security

Application and connector controls designed to reduce exposed services and privileges.

  • Hosting region and subprocessors documented during procurement
  • Production security headers and request-size controls
  • Rate limits on authentication and sensitive API paths
  • Outbound-only managed connector communication by default
  • No connector remote shell or arbitrary command channel

Monitoring & Detection

Application telemetry, operational health, audit records, and a documented assurance roadmap.

  • Application error and operational-health telemetry
  • Audit records for selected user, system, and integration actions
  • Breach-incident and privacy-request administration
  • Owner-authorized internal security assessment completed in August 2026
  • Independent specialist assessment remains a release and assurance follow-up

Current Assurance Status

Product controls, organizational compliance, independent attestation, and certification are different. This page states the current boundary explicitly.

🇿🇦

POPIA-Supporting Controls

Consent, access, export, deletion, incident, audit, and security features that can support a customer’s lawful processes

Product controlsNot legal certification
🛡️

SOC 2 and ISO/IEC 27001

Technical hardening and management-system readiness work is in progress

Not certifiedNo report or certificate issued
🔍

Internal Security Assessment

Local synthetic-data assessment, remediation and retest completed with no open critical, high or medium finding

Internal passAugust 2026 · independent review pending

Security Practices & Controls

Verified product controls are listed separately from organizational work that remains underway.

Development Security

  • Automated unit, integration, browser, native, and tenant-isolation tests
  • Mutation testing for selected high-risk controls
  • Code review and typed application boundaries
  • Dependency constraints and a vulnerability-management backlog
  • Release gates with regression and artifact checks

Data Protection

  • Encrypted application fields for selected secrets
  • Scoped and encrypted sensitive mobile offline records
  • User export, deletion, consent, and privacy-request workflows
  • Retention and backup automation with further governance work tracked
  • Data minimisation and secret-redaction checks in high-risk paths

Application Protection

  • Role- and permission-based access control
  • Tenant-scoped models, policies, APIs, exports, and connector operations
  • Signed webhook delivery with replay-resistant identities
  • SSRF, redirect, request-size, and error-sanitisation controls
  • Correlation identifiers for operational and audit investigation

Assurance Work and Open Gates

  • Draft security and privacy policy set awaiting organizational approval
  • Asset, data-flow, vendor, subprocessor, and risk inventories
  • Backup restoration and disaster-recovery exercises
  • Internal security assessment: 13 tracked items, 10 remediated and retested, with no open critical, high or medium finding
  • Independent application, API, mobile, and Windows-agent assessment
  • SOC 2 examination and ISO/IEC 27001 certification only after readiness

Security Incident Response

The response lifecycle prioritizes evidence, containment, lawful notification, verified recovery, and corrective action. Response timing depends on the incident and tested operating plan.

Detection

Prompt triage

Receive, record, classify, and preserve a suspected incident for investigation

  • Capture the report or alert
  • Assign severity and ownership
  • Preserve relevant evidence
  • Escalate using the approved contact path

Response

Risk based

Contain the affected boundary and determine scope, cause, and legal obligations

  • Incident containment measures
  • Forensic investigation initiation
  • Impact assessment
  • Stakeholder communication

Recovery

Verified recovery

Restore from a verified safe state and validate security and business integrity

  • System and data restoration
  • Service availability verification
  • Customer communication
  • Business operations resumption

Learning

After closure

Post-incident analysis and security improvement

  • Root cause analysis
  • Security control improvements
  • Process refinement
  • Team training updates

Hosting and Data Handling

Primary processing is in South Africa. International service providers may be used with safeguards; request the current hosting and subprocessor details during procurement.

Data Residency

Hosting requirements and available regions are confirmed for each customer

Physical Security

Provider controls and assurance evidence are reviewed for the contracted hosting scope

Infrastructure

Application health, scheduled work, backups, recovery, and availability require environment-specific evidence

Security Transparency

We believe in transparency about our security practices and incident response.

Encryption
TLS in transit; selected secrets, fields, and sensitive mobile caches encrypted
Access Controls
Role-based access with tenant isolation
Audit Logging
Selected human and system events logged; coverage expansion remains in progress

Report Security Issues

If you discover a security vulnerability or have security concerns, please report them immediately to our security team.