Security & compliance

Built for POPIA. Hosted in South Africa.

Below is what we actually do, stated specifically enough that you or your attorney can check it. We would rather be verifiable than impressive.

First, an honest word about "POPIA compliant"

There is no official POPIA certification scheme in South Africa. Nobody with regulatory authority certifies software as compliant, and any vendor telling you otherwise is selling you a private certificate, not an accreditation.

More to the point, compliance is a property of your organisation's practices — what you collect, why, who you tell, how long you keep it. Software cannot confer that on you. A perfectly secure vault used carelessly is still a compliance problem.

What MasterVault does is remove specific obstacles that make POPIA harder for a small firm, and give you the contractual and technical artefacts your obligations require. Here they are, one by one.

Where your data lives

Files are stored in Amazon S3 in the Africa (Cape Town) region, and the servers running your instance are in South Africa. Personal information in MasterVault does not leave the country in the ordinary course of the service.

This matters because POPIA section 72 places conditions on transferring personal information outside the Republic. It does not forbid it — and we want to be precise about that, because plenty of marketing implies otherwise. What South African hosting does is make the question moot: there is no transfer to justify, no adequacy assessment to run, and no foreign sub-processor chain to diligence.

Your operator agreement

When we store personal information on your behalf, you are the responsible party and we are the operator. Section 21(1) requires a written contract between us ensuring we maintain the security measures section 19 describes. Section 21(2) obliges us to notify you immediately where we have reasonable grounds to believe your data has been accessed or acquired by an unauthorised person.

Every MasterVault account includes that agreement, accepted at signup and countersigned by us. You can read it in full before you buy. If your attorney wants changes, we will talk.

Technical measures

  • Encryption in transit. TLS 1.2 or better on every connection, with HSTS. No plaintext fallback.
  • Encryption at rest. Server-side encryption on all stored objects, with keys managed in AWS KMS in the Cape Town region.
  • Tenant isolation. Each customer gets their own instance and their own storage prefix. Your files are not commingled with another business's in a shared database.
  • Backups. Daily, retained for 30 days, stored in South Africa, and restore-tested — a backup nobody has restored is a hypothesis, not a backup.
  • Access control. Group and folder-level permissions, enforced server-side. Two-factor authentication available on all accounts and enforceable across your organisation.
  • Audit logging. Views, downloads, shares, permission changes and deletions are logged against a user and timestamp, and exportable.
  • Patching. Security updates applied on a defined schedule, with out-of-band patching for critical advisories.

How this maps to your obligations

What POPIA asks of youWhat MasterVault gives you
s19 — appropriate, reasonable technical and organisational security measures, regularly verifiedThe measures listed above, plus a written summary you can attach to your own risk assessment
s21(1) — a written contract with your operatorIncluded in every account, signed at checkout
s21(2) — immediate notification of unauthorised accessContractual commitment, backed by a documented incident-response process
s14 — don't keep personal information longer than necessaryRetention policies per folder, with scheduled deletion
s23 — a data subject's right of accessSearch and export across your whole vault, plus the access log
s72 — conditions on transfers outside South AfricaNo transfer to justify — storage and processing stay in the country

What we are not claiming

  • We are not ISO 27001 certified. If we get there we will say so, with the certificate number and scope.
  • We do not offer client-side end-to-end encryption by default. We can technically access your files in order to operate, back up and restore the service. Any vendor offering both full management and zero knowledge is being loose with one of those words.
  • We cannot make your organisation compliant. We can remove several of the hardest obstacles and hand you the artefacts. The rest is your policies and your people.

Intellitics provides infrastructure and contractual assurances that support your POPIA obligations. Compliance depends on how your organisation uses the service. This page is information, not legal advice.

Ask us a hard question