The Automize Security & Compliance Pack is for customer security teams, auditors, and procurement reviewers who need our trust artefacts to complete a vendor review. Fill in the short form below and we will share the pack with you, by e-mail, within 1–2 business days.
1. What's in the Pack
Items currently available:
- Security & architecture overview – how data flows through the platform, encryption in transit and at rest, tenant isolation model.
- Sub-processor list with regions and purposes, and our 30-day change-notification policy. (The current list is also published on our Trust Center.)
- Data Processing Agreement (DPA) template – GDPR Article 28 / UK GDPR / POPIA compatible, with the 2021 EU Standard Contractual Clauses appended.
- Privacy programme summary – lawful bases, data subject rights workflow, retention schedule, breach-notification timeline.
- Audit-log & tamper-evidence overview – tenant-scoped endpoint audit log with SHA-256 hash chain (V174), nightly automated integrity verification, and an admin-visible chain-status panel; see Trust Center.
- Governance policy pack – eight internal policies covering acceptable use, access review, breach notification, incident response, joiner/mover/leaver, password & MFA, patching SLA, and a v1 risk register. Mapped to SOC 2 CC1 / CC3 / CC6 / CC7 / CC8 / CC9.
- PCI-DSS scope statement & SAQ-A self-attestation – subscription payments are handled by PayFast (PCI-DSS Level 1 Service Provider) using a hosted-redirect model; cardholder data never enters the Automize boundary.
- Backup, recovery, and continuity – RPO/RTO targets, backup schedule, restore-test cadence.
Items on the roadmap (not yet available, communicated as such on request):
- SOC 2 Type II report – controls implementation in progress; report planned after the first observation window.
- External penetration test summary – scheduled; redacted summary will be added to the pack once delivered.
- ISO 27001 statement of applicability – tracked in the compliance roadmap.
If you need something not listed here, mention it in the form – we will tell you whether it is available.
2. Confidentiality & NDA
Click-through acceptance on the form below covers initial sharing and is sufficient for most vendor reviews. If your organisation requires a counter-signed mutual NDA before any materials change hands, tick the option below or reply to our acknowledgement e-mail and we will route a mutual NDA. We treat your request and the pack contents as confidential on our side too.
If you would prefer e-mail, write to compliance@automize.co.za – the same information is required either way.
4. What Happens Next
- Acknowledgement – automatic on submission. We log the request, the NDA acceptance, and your IP for our audit trail.
- Review – within 1–2 business days. Some packs are released to anyone with a corporate e-mail; others (e.g. the full pen test summary) require additional verification of who you are and what you need it for.
- Delivery – e-mail with the pack contents, or a time-limited link if any item is too large to attach.
- Updates – we re-send the pack on material changes for 12 months from your request, unless you ask us to stop.
- Compliance team: compliance@automize.co.za
- Mailing address: Capitol Hill Consulting (Pty) Ltd, 4 Muller Street, Bethlehem, Free State, 9701, South Africa.