Home/Trust Centre
Trust Centre

We hold ourselves to our own standard

You’re trusting us with sensitive access and information. Here’s exactly how we protect it: our data residency, encryption, access controls, sub-processors and disclosure process, in the open.

All systems operational
Live operational status of Resilitech services
Updated
2026-07-09 08:04 SAST
Public websiteOperational
Client assurance portalOperational
SOC monitoring & alertingOperational
Secure evidence transferOperational
Our posture

How we protect your data

The controls behind every engagement, the same practices we assess in our clients.

Data residency

Client and evidence data is stored and processed in South Africa by default.

  • Primary hosting in Azure South Africa North (Johannesburg)
  • No cross-border transfer without documented POPIA basis
  • Data retention and secure-deletion schedules per engagement

Encryption

Strong encryption in transit and at rest across all systems.

  • TLS 1.2+ enforced for all data in transit
  • AES-256 at rest, with managed key rotation
  • Evidence encrypted end-to-end during transfer

Access & MFA

Least-privilege access with phishing-resistant MFA everywhere.

  • MFA mandatory on all staff and client-facing systems
  • Role-based access, reviewed quarterly
  • Just-in-time elevation for privileged actions

Monitoring & logging

Continuous monitoring of our own environment, 24/7.

  • Centralised, tamper-evident logging
  • SIEM-based detection and alerting
  • Documented incident-response runbooks

Resilience & backups

Tested recovery so an incident never becomes a loss.

  • Encrypted, geographically-separated backups
  • Recovery objectives tested twice yearly
  • Business-continuity plan aligned to ISO 22301

People & vetting

Trust starts with who we let near your systems.

  • Background-screened, permanently employed testers
  • Signed NDAs and engagement authorisation
  • Annual security-awareness certification
Transparency

Sub-processors

The third parties we rely on to deliver our services, what they process, and where. We notify clients of material changes.

Provider
Purpose
Data location
Safeguards
Microsoft Azure
PurposeCloud hosting & infrastructure
LocationZA North
SafeguardsISO 27001, SOC 2
Microsoft 365
PurposeEmail, documents & collaboration
LocationZA / EU
SafeguardsISO 27001, SCCs
Cloudflare
PurposeDNS, WAF & bot mitigation
LocationGlobal edge
SafeguardsISO 27001, SOC 2
Microsoft Sentinel
PurposeSIEM & security monitoring
LocationZA North
SafeguardsISO 27001, SOC 2
Zoho / secure portal
PurposeClient engagement & report delivery
LocationZA
SafeguardsISO 27001, DPA
Report a vulnerability

Responsible disclosure

Found a security issue in our systems? We want to hear from you, and we won’t take legal action against good-faith research.

If you believe you’ve found a vulnerability affecting Resilitech, please report it privately so we can fix it before it’s disclosed. We aim to acknowledge reports within one business day.

  1. Email us securelySend details to our security team, encrypted with our PGP key where possible.
  2. Give us the detailsSteps to reproduce, affected systems, and any proof-of-concept, enough for us to verify safely.
  3. Give us time to fixPlease allow us a reasonable window to remediate before any public disclosure.
  4. We’ll keep you postedWe acknowledge, triage, fix, and credit you if you’d like recognition.

Disclosure contact

Report to
security [at] resilitech.co.za
PGP fingerprint
3F91 A2C7 08D4 6E1B 5A9F  2D80 C4E7 71FB 9A03 6C1E
Machine-readable policy
In scope
  • resilitech.co.za & sub-domains
  • Client portal
Out of scope
  • Client environments
  • Social engineering / DoS

Safe harbour: good-faith research conducted within this policy is authorised, and we will not pursue legal action for it.

ISO 27001 certified ISMSSOC 2 Type II (annual)POPIA-compliant processingISO 22301 continuity

Need our security documentation?

Clients and prospects can request our ISO certificate, SOC 2 report and completed security questionnaires under NDA.