Skip to content
Mon to Fri, 08:00 to 17:00 SAST
SeptiBytes Solutions
What we do

Protection designed into the build

Every control below is decided before development begins and proven before release. Security is part of the architecture, not a layer added at the end.

01

Security architecture

Threat modelling, trust boundaries and control design agreed before development begins.

02

Identity and access control

Role based permissions, multi factor authentication, segregation of duties and delegated authority.

03

Encryption and key management

Protection of data in transit and at rest, with managed keys and certificate lifecycles.

04

Testing and remediation

Vulnerability assessment, penetration testing, code review and a prioritised fix plan.

05

Monitoring and response

Centralised logging, alerting, audit trails and a rehearsed incident response process.

06

Governance and continuity

POPIA and GDPR readiness, retention policy, backup, disaster recovery and recovery testing.

Security controls protecting a client data estate
SeptiBytes engineers at work
6controls proven before release
Assurance

Evidence, not assurances

  • Tested before release

    Findings fixed before go live, not logged for a later sprint

  • Segregation of duties

    The maker of a transaction cannot be its checker or its payer, enforced in the platform

  • Full audit trail

    Every decision and payment traceable to a user, a rule and a timestamp

  • Regulatory readiness

    POPIA and GDPR, with evidence packs an auditor will accept

  • Recovery proven

    Disaster recovery designed and then actually tested, not assumed

  • Independent review

    Third party penetration testing arranged on request

The SeptiBytes team reviewing live data together
Related

The other two disciplines

We deliver all three together, because the application, the data it holds and the network it travels on have to be designed against the same requirements.

SeptiBytes developers reviewing code together