Trust Center

Where your data lives, how we protect it, and the controls that govern it. · Last updated April 2026

Where Your Data Lives

Customer application data is stored exclusively in the European Union, with no replication outside the region.

EU Residency

All customer data is hosted in AWS eu-west-1 (Dublin, Ireland) – application servers, database, file storage, and outbound email.

Enterprise Infrastructure

Amazon RDS for the database, Amazon S3 for file storage, Amazon ECR/ECS for the application – all running in the same EU region.

No Cross-Region Replication

We do not replicate customer data outside the EU. The only data that leaves the region is to the limited sub-processors listed below.

Encryption & Network Security

Every layer is encrypted by default – in transit and at rest – with the database isolated on a private network tier.

Defence in depth: a perimeter layer, an encryption layer, and an encrypted, EU-resident data layer with tamper-evident audit. PERIMETER TLS 1.2+ HTTPS-only Private DB tier ENCRYPTION In transit (TLS) At rest (AES-256) Automatic key rotation DATA EU residency No cross-region copies Tamper-evident audit
Layered by design – a weakness in any single control is contained by the layers around it.

TLS 1.2+ in Transit

Every public endpoint enforces TLS 1.2 or higher. HTTP requests are automatically redirected to HTTPS – no plain-text traffic accepted.

Encrypted at Rest

AWS-managed encryption on RDS volumes, S3 objects, and EBS volumes. Encryption keys are rotated automatically.

Private Database Tier

The database lives on a private subnet, reachable only from the application tier. There is no direct internet path to your data.

Authentication & Access Control

Identity, authentication, and authorisation controls – built in, configurable, and audited.

Single Sign-On

SAML and OIDC SSO via WorkOS for enterprise customers. Centralise identity, enforce MFA, and revoke access from your IdP.

Password Security

Passwords are stored as bcrypt hashes. Failed-attempt rate limiting protects against brute-force and credential-stuffing attacks.

Granular Permissions

Per-object ShareGrants with four permission tiers – control exactly who can read, comment, edit, or manage every process, form, or wiki.

Endpoint Audit Log

Sensitive write operations are recorded with the user, endpoint, and timestamp. Audit log entries are retained for 30 days.

CSRF Protection

Per-session CSRF tokens guard every state-changing request. Cookie flags and origin checks defend against cross-site attacks.

Tenant Isolation

Each company operates in its own logical tenant – no shared data, no cross-tenant access paths, even for support staff.

Secure Development & Vulnerability Management

Security is built into how we ship code – automated scanning at every stage of the development pipeline.

Dependency Scanning

Dependabot continuously monitors third-party libraries for known vulnerabilities and proposes upgrade pull requests automatically.

Container Image Scanning

Every container image is scanned with Trivy in CI before deployment. Builds fail on critical CVEs in our image layer.

Static Analysis

The application passes PHPStan level 10 with zero errors on every commit – strict typing and dead-code detection enforced in CI.

Compliance & Frameworks

We process personal information in accordance with internationally recognised data protection laws and security frameworks.

EU GDPR

Compliant with the EU General Data Protection Regulation. Mutual EU–UK adequacy means no SCCs are required for transfers between the regions.

UK GDPR

Compliant with UK GDPR and the Data Protection Act 2018, supervised by the Information Commissioner's Office (ICO).

CCPA & US State Privacy

Compliant with California (CCPA / CPRA) and the comparable laws of Virginia, Colorado, Connecticut, Utah, Texas, and the growing list of US state privacy laws. Global Privacy Control (GPC) signals are honoured.

POPIA

Compliant with South Africa's Protection of Personal Information Act, supervised by the Information Regulator.

PCI-DSS

SAQ-A self-attested (April 2026) – card data is handled by PayFast under their PCI-DSS Level 1 Service Provider attestation and never touches our servers. Hosted-redirect model; scope statement and SAQ-A available via the Security & Compliance Pack.

SOC 2 Type II

Working toward certification.

ISO 27001

On the certification roadmap.

Cyber Essentials

UK NCSC scheme – on the roadmap, prioritised when a UK gov, NHS, or council prospect requires it.

Sub-Processors

The third parties below process limited categories of data on our behalf. Standard Contractual Clauses (SCCs) are in place for unavoidable transfers outside the EU.

Sub-processor Purpose Region
Amazon Web Services Hosting, storage, document OCR (Textract) Ireland (eu-west-1)
SendGrid (Twilio) Transactional email – notifications, password resets, invites United States (SCCs)
WorkOS SSO identity brokering United States (SCCs)
PayFast Payment processing South Africa
Anthropic / OpenAI AI features (when enabled by you) – only the prompts you submit, never background data United States (SCCs)
Sentry Application error telemetry United States – EU migration in progress

A current sub-processor list and Data Processing Agreement (DPA) are available via our Security & Compliance Pack request form, or by e-mail to privacy@automize.co.za. We will notify customers at least 30 days before adding a new sub-processor or making a material change to an existing one, so you have time to object before the change takes effect.

Data Lifecycle

Clear, predictable retention windows for every category of data we hold on your behalf.

Active Data

Retained for the duration of your subscription.

Account Export

Available for 30 days after termination on request.

Deletion

Live data deleted within 30 days of termination; backups expire within 35 days.

Logs

Application and audit logs retained for 30 days.

Business Continuity

Continuous backups, point-in-time recovery, and a public status page keep the platform available, recoverable, and verifiable.

Continuous Backups

AWS RDS automated backups: daily snapshots plus continuous transaction logs that capture changes to the second. All backups are encrypted with AWS KMS and stored in the same EU region as the live database.

Point-in-Time Recovery

The database can be restored to any second within the retention window – no manual snapshot juggling, no rolling back to the last nightly backup.

Live Service Status

Check current platform health on our status page – database, cache, storage, and queue connectivity in real time.

Incident Response

How we detect, respond to, and notify you about security incidents.

Detection

Continuous monitoring of uptime, error rates, and latency. On-call engineers are paged on incident-grade signals.

72-Hour Breach Notification

Affected customers are notified within 72 hours of a confirmed personal-data breach, in line with GDPR Article 33.

Post-Incident Review

Material incidents are followed by a written root-cause analysis, shared with affected customers along with remediation steps.

The Bot Runtime

The Automize Bot is a desktop application that runs on machines you control. Your screens, files, and credentials stay with you.

Runs On Your Infrastructure

The Bot runs on your workstation, VM, or data centre – not on our servers. Windows, Mac, and Linux are supported – including Windows Server for always-on, unattended deployments.

Outbound Connection Only

The Bot connects outbound to the platform in eu-west-1. We do not see the screens, files, or credentials it uses on your machine.

You Choose What to Upload

Only data you explicitly upload – process definitions, configured outputs, opt-in screenshots – reaches the platform.

See the full system requirements for supported operating systems, network rules, and machine specifications.

Documents & Resources

Reference legal documents and downloadable resources.

Privacy Policy

How we collect, use, store, and protect personal information.

Your Privacy Choices

The rights you can exercise (access, delete, correct, opt-out, limit) and how Global Privacy Control is honoured.

Privacy Request

The form to submit a data subject access, deletion, correction, opt-out, or other privacy request.

Terms of Service

The contractual terms that govern your use of the Automize platform.

Cookie Policy

The cookies and similar technologies we use, and how to manage them.

Security & Compliance Pack

Self-serve request form for our DPA, security overview, sub-processor list, audit-log architecture, governance policy pack, and PCI-DSS SAQ-A – for vendor reviews, procurement, and auditors.

Security Disclosure

Embedded HackerOne submission form, response SLA, scope, and safe-harbour terms.

Antivirus & Firewall Exclusions

The exact folders, executables, and outbound endpoints your endpoint-protection and network teams need to allowlist the bot – with a rationale per entry, the EDR behaviours to expect, and a ready-to-run Defender snippet.

Audit Log

Tenant-scoped record of every call to a critical endpoint – viewable by company admins, with filters and CSV export. Each row is part of a SHA-256 hash chain with nightly automated integrity verification and an admin-visible chain-status panel.

Report a Security Issue

If you believe you have found a security vulnerability, submit it via the embedded HackerOne form on our security disclosure page, or by e-mail. We acknowledge reports within two business days and will keep you updated on progress.

Machine-readable contact information is published at /.well-known/security.txt in line with RFC 9116.

For privacy or data-protection questions: privacy@automize.co.za or privacy-request  ·  General support: support@automize.co.za