Security Controls and Assurance Readiness
SalesPro Hub provides layered product security and privacy-supporting controls. Formal SOC 2 and ISO/IEC 27001 assurance work is still in progress; no report or certificate is claimed.
Privacy, access, consent, and data-handling controls designed around POPIA requirements
Four Pillars of Security
Our security architecture is built on four fundamental pillars that ensure comprehensive protection of your data and systems.
Data Encryption
Layered transport, credential, application-field, and mobile offline-data protections.
- HTTPS/TLS required for production application traffic
- Passwords stored using one-way password hashing
- Selected secrets and sensitive fields encrypted by the application
- Identity-scoped authenticated encryption for sensitive mobile offline caches
- Signed webhooks and signed managed-connector update packages
Access Control
Multi-layered authentication and authorization systems.
- Multi-factor authentication (MFA)
- Role-based access control (RBAC)
- Tenant-aware authorization boundaries
- Hashed, scoped, expiring and revocable API keys
- Managed connector enrollment restricted to Enterprise tenants
Infrastructure Security
Application and connector controls designed to reduce exposed services and privileges.
- Hosting region and subprocessors documented during procurement
- Production security headers and request-size controls
- Rate limits on authentication and sensitive API paths
- Outbound-only managed connector communication by default
- No connector remote shell or arbitrary command channel
Monitoring & Detection
Application telemetry, operational health, audit records, and a documented assurance roadmap.
- Application error and operational-health telemetry
- Audit records for selected user, system, and integration actions
- Breach-incident and privacy-request administration
- Owner-authorized internal security assessment completed in August 2026
- Independent specialist assessment remains a release and assurance follow-up
Current Assurance Status
Product controls, organizational compliance, independent attestation, and certification are different. This page states the current boundary explicitly.
POPIA-Supporting Controls
Consent, access, export, deletion, incident, audit, and security features that can support a customer’s lawful processes
SOC 2 and ISO/IEC 27001
Technical hardening and management-system readiness work is in progress
Internal Security Assessment
Local synthetic-data assessment, remediation and retest completed with no open critical, high or medium finding
Security Practices & Controls
Verified product controls are listed separately from organizational work that remains underway.
Development Security
- Automated unit, integration, browser, native, and tenant-isolation tests
- Mutation testing for selected high-risk controls
- Code review and typed application boundaries
- Dependency constraints and a vulnerability-management backlog
- Release gates with regression and artifact checks
Data Protection
- Encrypted application fields for selected secrets
- Scoped and encrypted sensitive mobile offline records
- User export, deletion, consent, and privacy-request workflows
- Retention and backup automation with further governance work tracked
- Data minimisation and secret-redaction checks in high-risk paths
Application Protection
- Role- and permission-based access control
- Tenant-scoped models, policies, APIs, exports, and connector operations
- Signed webhook delivery with replay-resistant identities
- SSRF, redirect, request-size, and error-sanitisation controls
- Correlation identifiers for operational and audit investigation
Assurance Work and Open Gates
- Draft security and privacy policy set awaiting organizational approval
- Asset, data-flow, vendor, subprocessor, and risk inventories
- Backup restoration and disaster-recovery exercises
- Internal security assessment: 13 tracked items, 10 remediated and retested, with no open critical, high or medium finding
- Independent application, API, mobile, and Windows-agent assessment
- SOC 2 examination and ISO/IEC 27001 certification only after readiness
Security Incident Response
The response lifecycle prioritizes evidence, containment, lawful notification, verified recovery, and corrective action. Response timing depends on the incident and tested operating plan.
Detection
Prompt triageReceive, record, classify, and preserve a suspected incident for investigation
- Capture the report or alert
- Assign severity and ownership
- Preserve relevant evidence
- Escalate using the approved contact path
Response
Risk basedContain the affected boundary and determine scope, cause, and legal obligations
- Incident containment measures
- Forensic investigation initiation
- Impact assessment
- Stakeholder communication
Recovery
Verified recoveryRestore from a verified safe state and validate security and business integrity
- System and data restoration
- Service availability verification
- Customer communication
- Business operations resumption
Learning
After closurePost-incident analysis and security improvement
- Root cause analysis
- Security control improvements
- Process refinement
- Team training updates
Hosting and Data Handling
Primary processing is in South Africa. International service providers may be used with safeguards; request the current hosting and subprocessor details during procurement.
Data Residency
Hosting requirements and available regions are confirmed for each customer
Physical Security
Provider controls and assurance evidence are reviewed for the contracted hosting scope
Infrastructure
Application health, scheduled work, backups, recovery, and availability require environment-specific evidence
Security Transparency
We believe in transparency about our security practices and incident response.
Report Security Issues
If you discover a security vulnerability or have security concerns, please report them immediately to our security team.