Trust & security at Phase Transitions
Phase Transitions (Pty) Ltd builds and operates custom data and AI software for business clients. Under POPIA it acts as an operator for its clients, who remain the responsible parties. It owns its intellectual property and controls its infrastructure.
Phase Transitions (Pty) Ltd. Registration 2026/448729/07. A South African private company, Johannesburg.
Core controls
- Read, never write. The AI reads finished, reconciled numbers. It cannot author or change them, and makes no automated decisions.
- Isolated per client. A separate database per client, with the isolation verified by an automated test in CI.
- Minimal AI exposure. The AI reads only, and stores nothing at rest. Where personal information is in its reach, it is tokenised first.
- Encrypted and backed up. AES-256 at rest, TLS 1.2+ in transit, daily backups with a tested restore.
- Documented. A self-assessed SOC 2 and vendor-DDQ posture, an incident-response plan, and a data-storage policy, available under NDA.
-
Your data
Where client data lives, how it is isolated and encrypted, and the residency position. One database per client, hosted in managed cloud, with stored documents in the EU.
-
How it works
The read-never-write boundary, per-client isolation verified by a test, and managed passwordless authentication that denies by default.
-
The AI analyst
What the analyst can see, and why it cannot change anything: read-only data at query time, tokenisation where personal information is in scope, no training on client data, a signed processor agreement, and CI-enforced guardrails.
-
Compliance & posture
The POPIA operator position, the named sub-processors, resilience, insurance, the self-assessed SOC 2 posture available under NDA, and what we do not yet have.
Sub-processors
The third parties that touch client data or infrastructure. Phase Transitions is the contracting entity. Each is SOC 2 and/or ISO 27001 certified, and data-processing agreements are in place. Copies are available on request.
| Render | Per-client PostgreSQL databases + application hosting |
| Cloudflare R2 | Raw data + document storage (EU) |
| Auth0 (Okta) | Identity and authentication |
| Anthropic | The AI analyst layer (read-only) |
| Files.com | Managed SFTP / partner-data ingress |
| Resend | Transactional email (one-time codes) |
| GitHub | Source control and CI |
What we do not have yet
- No third-party SOC 2 audit. The SOC 2 posture is self-assessed against the standard and a vendor DDQ. The full assessment is available under NDA.
- Object-storage versioning is on for buckets created under the current policy; two buckets that predate it do not carry versioning yet.
- Encryption at rest is platform-managed (AES-256). There are no customer-managed keys yet.
- Request-level access auditing covers login-based client deployments. Read-only static deployments have no sign-in, so carry no per-user audit trail.
Request the full pack, or ask a question
For the full self-assessed SOC 2 posture or the sub-processor agreements (under NDA), email us.
graham@phasetransitions.ai