SOC 2 Type II
Security, availability, and confidentiality controls independently audited and attested.
B-BBEE Level 1
135% procurement recognition. 100% black-owned, 100% South African-managed.
POPIA Compliant
Full Protection of Personal Information Act 4 of 2013 compliance. Information Regulator notified.
CIPC Registered
Enterprise number 2026/429045/07. Tax ID 9308985267. Registered 30 May 2026.
Compliance Timeline
CIPC Registration
IntelliAI Group (Pty) Ltd registered with the Companies and Intellectual Property Commission. Enterprise number 2026/429045/07 issued. Tax registration with SARS completed.
COMPLETEDB-BBEE Level 1 Certification
Verified by independent B-BBEE rating agency. 100% black ownership, 100% South African management, 135% procurement recognition level achieved.
COMPLETEDPOPIA Compliance Framework
Full Protection of Personal Information Act 4 of 2013 compliance framework implemented. Information Officer (Solomon Makwedini) and Deputy Information Officer (Lindokuhle Phungwayo) appointed. Privacy Policy published and data subject rights portal activated.
COMPLETEDSOC 2 Type II Audit — Period 1
Independent auditor engagement commenced. Trust Services Criteria (TSC) for Security, Availability, and Confidentiality assessed across all 9 divisions. Zero critical findings. Three minor observations remediated within 48 hours.
COMPLETEDPaystack Live Activation
Merchant ID 1904286 under review. Live platform demonstration, legal documentation, and compliance verification submitted. Awaiting final underwriting approval for ZAR-denominated transaction processing.
IN PROGRESSISO 27001:2022 Certification
Information Security Management System (ISMS) implementation in progress. Gap analysis completed. Stage 1 audit scheduled for October 2026. Target certification: December 2026.
PLANNEDPCI DSS Level 1 Compliance
Payment Card Industry Data Security Standard Level 1 (merchant processing >6M transactions annually) assessment scheduled. On-track for Q1 2027 certification following Paystack live activation.
PLANNEDSecurity Architecture
Encryption at Rest
All customer data, backups, and archives encrypted with AES-256-GCM. Key management via HSM-backed KMS with quarterly key rotation.
Encryption in Transit
TLS 1.3 mandatory for all API, web, and inter-service communication. Certificate pinning enforced on mobile and desktop clients.
Zero-Trust Network
Every request authenticated and authorised. No implicit trust based on network location. Micro-segmentation across all 9 division workloads.
Audit Logging
Immutable audit trails for every data access, modification, and administrative action. WORM storage with 7-year retention for financial records.
Disaster Recovery
Active-active DR between Johannesburg (primary) and Cape Town (recovery). RPO 15 minutes, RTO 30 minutes. Quarterly DR drills.
Penetration Testing
Quarterly external penetration testing by CREST-certified firms. Continuous automated vulnerability scanning (SAST/DAST/SCA) integrated into CI/CD.
Governance Documents
Terms of Service
Constitutional R1-R8, SLA guarantees, liability, and termination clauses.
Privacy Policy
Full POPIA compliance — Sections 11, 23-26, 72. Data subject rights and retention.
Refund Policy
14-day and 30-day cooling-off periods. Pro-rata refund formula and cancellation process.
Trust Center
This page. Compliance timeline, security architecture, and certification status.