Security Overview

How CertiGuard GRC protects your data, secures your tenant, and maintains the trust of banks, governments, and enterprises across SADC and beyond.

Last updated: January 2026 · Version 2.0

Encryption Everywhere

AES-256-GCM at rest, TLS 1.3 in transit, KMS-managed keys with 90-day rotation.

Identity & Access

OIDC SSO, 12+ char password policy, MFA-ready, least-privilege RBAC.

Tenant Isolation

Row-Level Security (RLS) on every entity — one tenant can never see another's data.

Immutable Audit Trail

Hash-chained, WORM-style event logs — tamper-evident by design (IGGL).

1. Access Control

Role-based access control (RBAC): admin, compliance officer, risk manager, auditor, department head, viewer
Row-Level Security (RLS) enforced server-side on every database query
Service-role credentials isolated from app-user credentials
Session tokens are Secure, HttpOnly, SameSite=Strict cookies
Automatic session timeout and idle lock for sensitive operations

2. Data Protection

AES-256-GCM encryption for all stored data (database, files, backups)
TLS 1.3 with HSTS for all network communication — no fallback to TLS 1.2
Evidence files stored with signed, time-limited access URLs
PII fields never logged in plaintext in audit trails or application logs
Secure data export and cryptographic erasure on request

3. Audit & Monitoring

Every entity mutation (create/update/delete) logged with user, timestamp, and change diff
Audit trail entries are hash-chained — any tampering breaks the chain visibly
ControlTestResult entity is append-only (update/delete denied via RLS)
Real-time security alerts via Slack for critical findings and control regressions
Continuous control monitoring runs daily with automated evidence collection

4. Vulnerability Management

Dependency scanning on every build — vulnerable packages blocked from deployment
Regular penetration testing by independent third-party firms
Responsible disclosure program — security researchers can report vulnerabilities
Critical security patches deployed within 48 hours of availability
OWASP Top 10 and CWE coverage in automated security tests

5. Incident Response

Documented incident response plan with defined roles (incident commander, comms, forensics)
Automated escalation chains for critical and high-severity incidents
Customer notification within 30 minutes for confirmed Critical/High incidents
MTTR (Mean Time to Resolve) tracked per incident with continuous improvement targets
Post-incident reviews with root-cause analysis and remediation tracking

6. Business Continuity

Multi-availability-zone deployment with automatic failover
Database snapshots every 15 minutes (RPO ≤ 15 min)
Full service restoration within 4 hours (RTO ≤ 4 hours)
Quarterly disaster recovery exercises with documented results
Immutable backup vaults protect against ransomware and destructive attacks

Compliance Posture

SOC 2 Type II

In Progress

Security, availability, and confidentiality criteria

ISO 27001

In Progress

Information security management system

POPIA (South Africa)

Aligned

Protection of Personal Information Act

GDPR (EU)

Aligned

General Data Protection Regulation

FSRA Cyber Rules (Botswana)

Aligned

Financial Sector Regulatory Authority

Kenya DPA

Aligned

Data Protection Act, 2019

Our Commitment to Your Trust

CertiGuard GRC is engineered to meet the security and compliance requirements of the most demanding organisations — central banks, government ministries, financial institutions, mining houses, manufacturers, and educational institutions. We continuously invest in security hardening, independent audits, and transparency because your trust is our core DNA.

CertiGuard GRC · A product of Ethical Edge GRC Consulting (Pty) Ltd · Gaborone, Botswana

Security questions? Contact our security team for due diligence packages and right-to-audit provisions.

Trust Center·SLA·Data Residency·Privacy Policy·Terms