Skip to content

Trust & security at Phase Transitions

Phase Transitions (Pty) Ltd builds and operates custom data and AI software for business clients. Under POPIA it acts as an operator for its clients, who remain the responsible parties. It owns its intellectual property and controls its infrastructure.

Phase Transitions (Pty) Ltd. Registration 2026/448729/07. A South African private company, Johannesburg.

Core controls

  • Read, never write. The AI reads finished, reconciled numbers. It cannot author or change them, and makes no automated decisions.
  • Isolated per client. A separate database per client, with the isolation verified by an automated test in CI.
  • Minimal AI exposure. The AI reads only, and stores nothing at rest. Where personal information is in its reach, it is tokenised first.
  • Encrypted and backed up. AES-256 at rest, TLS 1.2+ in transit, daily backups with a tested restore.
  • Documented. A self-assessed SOC 2 and vendor-DDQ posture, an incident-response plan, and a data-storage policy, available under NDA.

Sub-processors

The third parties that touch client data or infrastructure. Phase Transitions is the contracting entity. Each is SOC 2 and/or ISO 27001 certified, and data-processing agreements are in place. Copies are available on request.

Render Per-client PostgreSQL databases + application hosting
Cloudflare R2 Raw data + document storage (EU)
Auth0 (Okta) Identity and authentication
Anthropic The AI analyst layer (read-only)
Files.com Managed SFTP / partner-data ingress
Resend Transactional email (one-time codes)
GitHub Source control and CI

What we do not have yet

  • No third-party SOC 2 audit. The SOC 2 posture is self-assessed against the standard and a vendor DDQ. The full assessment is available under NDA.
  • Object-storage versioning is on for buckets created under the current policy; two buckets that predate it do not carry versioning yet.
  • Encryption at rest is platform-managed (AES-256). There are no customer-managed keys yet.
  • Request-level access auditing covers login-based client deployments. Read-only static deployments have no sign-in, so carry no per-user audit trail.

Request the full pack, or ask a question

For the full self-assessed SOC 2 posture or the sub-processor agreements (under NDA), email us.

Open in your email app