Security & trust
Built to be trusted with your firm's data.
A security firm's records are sensitive: customers, sites, officers and money. This is how SecureGrid looks after them.
Where your data lives
Your records are stored in Microsoft Azure's South Africa North region. The database keeps 35 days of point-in-time restore, and application secrets are held in Azure Key Vault, never in the code. Email notifications go out through an email delivery service outside South Africa.
How sign-in works
Microsoft Entra handles every sign-in, password reset and multi-factor prompt, so SecureGrid never stores a password. Access is by invitation: a person can sign in only after your administrator has invited them.
Who can see what
Each firm's records are kept apart by row-level security in the database itself, not only in the application. Where someone shares their own SecureMarket profile with your firm, what you see follows what they chose to share. Within your firm, roles and permissions decide what each person can see and do.
The audit trail
Every change records who made it and when. Sensitive actions, such as opening an identity number, are logged separately, so you can show exactly who looked at what.
POPIA
Consent is recorded when personal information is collected, and opening a person's identity number or documents is logged. People on SecureMarket can download or delete their own data. Your records stay yours: we don't sell or share them.
PSIRA
Officers' PSIRA grades and registration details sit on their records, and PSIRA documents can be verified, so scheduling and HR work from the same facts.
Questions from your IT team?
We'll go through hosting, sign-in and data handling with them in as much detail as they need.