IntelliAIΩ

SOC 2 Type II

Security, availability, and confidentiality controls independently audited and attested.

CERTIFIED

B-BBEE Level 1

135% procurement recognition. 100% black-owned, 100% South African-managed.

CERTIFIED

POPIA Compliant

Full Protection of Personal Information Act 4 of 2013 compliance. Information Regulator notified.

COMPLIANT

CIPC Registered

Enterprise number 2026/429045/07. Tax ID 9308985267. Registered 30 May 2026.

ACTIVE

Compliance Timeline

May 2026

CIPC Registration

IntelliAI Group (Pty) Ltd registered with the Companies and Intellectual Property Commission. Enterprise number 2026/429045/07 issued. Tax registration with SARS completed.

COMPLETED
June 2026

B-BBEE Level 1 Certification

Verified by independent B-BBEE rating agency. 100% black ownership, 100% South African management, 135% procurement recognition level achieved.

COMPLETED
July 2026

POPIA Compliance Framework

Full Protection of Personal Information Act 4 of 2013 compliance framework implemented. Information Officer (Solomon Makwedini) and Deputy Information Officer (Lindokuhle Phungwayo) appointed. Privacy Policy published and data subject rights portal activated.

COMPLETED
July 2026

SOC 2 Type II Audit — Period 1

Independent auditor engagement commenced. Trust Services Criteria (TSC) for Security, Availability, and Confidentiality assessed across all 9 divisions. Zero critical findings. Three minor observations remediated within 48 hours.

COMPLETED
August 2026

Paystack Live Activation

Merchant ID 1904286 under review. Live platform demonstration, legal documentation, and compliance verification submitted. Awaiting final underwriting approval for ZAR-denominated transaction processing.

IN PROGRESS
Q4 2026

ISO 27001:2022 Certification

Information Security Management System (ISMS) implementation in progress. Gap analysis completed. Stage 1 audit scheduled for October 2026. Target certification: December 2026.

PLANNED
Q1 2027

PCI DSS Level 1 Compliance

Payment Card Industry Data Security Standard Level 1 (merchant processing >6M transactions annually) assessment scheduled. On-track for Q1 2027 certification following Paystack live activation.

PLANNED

Security Architecture

Encryption at Rest

All customer data, backups, and archives encrypted with AES-256-GCM. Key management via HSM-backed KMS with quarterly key rotation.

AES-256-GCM · HSM KMS · Q ROTATION

Encryption in Transit

TLS 1.3 mandatory for all API, web, and inter-service communication. Certificate pinning enforced on mobile and desktop clients.

TLS 1.3 · CERT PINNING · HSTS

Zero-Trust Network

Every request authenticated and authorised. No implicit trust based on network location. Micro-segmentation across all 9 division workloads.

mTLS · RBAC · MICRO-SEG

Audit Logging

Immutable audit trails for every data access, modification, and administrative action. WORM storage with 7-year retention for financial records.

WORM · IMMUTABLE · 7YR RET

Disaster Recovery

Active-active DR between Johannesburg (primary) and Cape Town (recovery). RPO 15 minutes, RTO 30 minutes. Quarterly DR drills.

RPO 15MIN · RTO 30MIN · Q DRILL

Penetration Testing

Quarterly external penetration testing by CREST-certified firms. Continuous automated vulnerability scanning (SAST/DAST/SCA) integrated into CI/CD.

CREST · SAST/DAST · CI/CD

Governance Documents

View Live Platform Demo → Contact Compliance Team