Trust / Compliance & posture
Compliance & posture
Under POPIA the obligations sit with the client as the responsible party. The architecture supports those obligations; Phase Transitions holds no certification against them.
POPIA: operator and responsible party
Under POPIA you are the responsible party for your data and Phase Transitions acts as your operator, processing it on your instruction and for your purposes. Stored documents are held in the EU. Where clients are financial-services providers, they remain separately regulated. Phase Transitions is not itself an FSP.
Data-subject rights, mapped to mechanisms
- Access. Every figure traces back to its source record and can be produced.
- Correction. Corrections are made in your accounting system, the source of truth, and flow through on the next sync.
- Deletion. Your database can be deleted in full when the engagement ends.
- Objection. You can revoke our access at any time, which stops further processing.
- Portability. You can take a full export of your data in a standard format.
Sub-processors
| Render | Per-client PostgreSQL databases + application hosting |
| Cloudflare R2 | Raw data + document storage (EU) |
| Auth0 (Okta) | Identity and authentication |
| Anthropic | The AI analyst layer (read-only) |
| Files.com | Managed SFTP / partner-data ingress |
| Resend | Transactional email (one-time codes) |
| GitHub | Source control and CI |
Phase Transitions is the contracting entity. Each is SOC 2 and/or ISO 27001 certified, and data-processing agreements are in place; copies are available on request.
Resilience: daily backups, a tested restore, and an incident-response plan.
Databases are backed up daily. A restore has been drilled with a known recovery time and verified integrity. A written, cross-system incident-response plan covers the South African reporting timelines (POPIA, the Cybercrimes Act, and the FSCA/PA Joint Standard), and a written data-storage policy governs jurisdiction and retention.
Insurance: Technology E&O + Cyber cover is in force.
A combined Technology Professional Indemnity / E&O and Cyber Liability policy in the name of Phase Transitions (Pty) Ltd is in force (bound 20 July 2026). Policy details are available on request.
A self-assessed SOC 2 / vendor-DDQ posture, available under NDA.
We maintain a SOC 2 and vendor-due-diligence posture, self-assessed against the standard. It is available in full under NDA, with the sub-processor agreements.
What we do not have yet
- No third-party SOC 2 audit. The posture is self-assessed, available under NDA.
- Object-storage versioning is on for buckets created under the current policy; two buckets that predate it do not carry versioning yet.
- Encryption at rest is platform-managed. There are no customer-managed keys yet.
- Request-level access auditing covers login-based deployments. Read-only static deployments have no sign-in, so carry no per-user audit trail.