Trust Center

Where your data lives, how we protect it, and the controls that govern it. · Last updated 29 September 2026

Where Your Data Lives

Customer application data is stored exclusively in the European Union, with no replication outside the region.

EU Residency

All customer data is hosted in AWS eu-west-1 (Dublin, Ireland) – application servers, database, and file storage.

Enterprise Infrastructure

A private Lightsail managed MySQL database, Amazon S3 for file storage, and application containers on Amazon Lightsail – all in the same EU region.

No Cross-Region Replication

We do not replicate customer data outside the EU. The only data that leaves the region is to the limited sub-processors listed below.

Encryption & Network Security

Every layer is encrypted by default – in transit and at rest – with the database isolated on a private network tier.

Defence in depth: a perimeter layer, an encryption layer, and an encrypted, EU-resident data layer with tamper-evident audit. PERIMETER TLS 1.2+ HTTPS-only Private DB tier ENCRYPTION In transit (TLS) At rest (AES-256) App-level encryption DATA EU residency No cross-region copies Tamper-evident audit
Layered by design – a weakness in any single control is contained by the layers around it.

TLS 1.2+ in Transit

Every public endpoint enforces TLS 1.2 or higher. HTTP requests are automatically redirected to HTTPS – no plain-text traffic accepted.

Encrypted at Rest

AWS encrypts the database, stored files, and backups at rest.

Private Database Tier

The database is private, with no internet path to it. Only the application reaches it; staff reach it only through an AWS Systems Manager tunnel.

Encrypted a Second Time

Queue items, their output and failure messages, and transaction details are encrypted again by the application, with a key held outside the database. A copy of the database or a backup alone does not reveal them. Vault credentials have their own key.

Authentication & Access Control

Identity, authentication, and authorisation controls – built in, configurable, and audited.

Single Sign-On

SAML and OIDC SSO via WorkOS for enterprise customers. Centralise identity, enforce MFA, and revoke access from your IdP.

Password Security

Passwords are stored as argon2id hashes, the current recommended method, and passwords found in known data breaches are refused. Failed-attempt rate limiting protects against brute-force and credential-stuffing attacks.

Granular Permissions

Per-object ShareGrants with four permission tiers – control exactly who can read, comment, edit, or manage every process, form, or wiki.

Endpoint Audit Log

Calls to critical endpoints are recorded with the user, endpoint, and time, and kept for 30 days. The separate security log, which also records every view of client data, is kept for 365 days.

CSRF Protection

Per-session CSRF tokens guard every state-changing request. Cookie flags and origin checks defend against cross-site attacks.

Tenant Isolation

Each company operates in its own logical tenant – no shared data between customers. Automize staff access your data only to support you and run the service, and every time anyone opens the content of a record, it is written to your security log.

See Client Data

Opening what a record holds – queue item data, transaction details, failure messages – needs the “See client data” permission. Company admins have it; Viewer, Operator and Editor do not, unless a company admin switches it on for that role. Everyone else sees that a record exists and how it ended. Every view is written to your security log.

Secure Development & Vulnerability Management

Security is built into how we ship code – automated scanning at every stage of the development pipeline.

Dependency Scanning

Dependabot continuously monitors third-party libraries for known vulnerabilities and proposes upgrade pull requests automatically.

Container Image Scanning

Every container image is scanned with Trivy in CI before deployment. Builds fail on critical CVEs in our image layer.

Static Analysis

The application passes PHPStan level 10 with zero errors on every commit – strict typing and dead-code detection enforced in CI.

Compliance & Frameworks

We process personal information in accordance with internationally recognised data protection laws and security frameworks.

EU GDPR

Aligned with the EU General Data Protection Regulation. Mutual EU–UK adequacy means no SCCs are required for transfers between the regions.

UK GDPR

Aligned with UK GDPR and the Data Protection Act 2018, supervised by the Information Commissioner's Office (ICO).

CCPA & US State Privacy

Aligned with California (CCPA / CPRA) and the comparable laws of Virginia, Colorado, Connecticut, Utah, Texas, and the growing list of US state privacy laws. Global Privacy Control (GPC) signals are honoured.

POPIA

Aligned with South Africa's Protection of Personal Information Act, supervised by the Information Regulator.

PCI-DSS

SAQ-A self-attested (April 2026) – card data is handled by PayFast under their PCI-DSS Level 1 Service Provider attestation and never touches our servers. Hosted-redirect model; scope statement and SAQ-A available via the Security & Compliance Pack.

SOC 2 Type II

Working toward certification.

ISO 27001

On the certification roadmap.

Cyber Essentials

UK NCSC scheme – on the roadmap, prioritised when a UK gov, NHS, or council prospect requires it.

Sub-Processors

The third parties below process limited categories of data on our behalf. Standard Contractual Clauses (SCCs) are in place for unavoidable transfers outside the EU.

Sub-processor Purpose Region
Amazon Web Services Hosting, storage, document OCR (Textract), face matching (Rekognition, only if you use it) Ireland (eu-west-1)
SendGrid (Twilio) Transactional email – notifications, password resets, invites United States (SCCs)
WorkOS SSO identity brokering United States (SCCs)
PayFast Payment processing South Africa
Anthropic / OpenAI AI features (when enabled by you) – only what you and your bots choose to send, with personal details hidden by default United States (SCCs)
Sentry Application error telemetry European Union (Frankfurt)

A current sub-processor list and Data Processing Agreement (DPA) are available via our Security & Compliance Pack request form, or by e-mail to privacy@automize.co.za. We will notify customers at least 30 days before adding a new sub-processor or making a material change to an existing one, so you have time to object before the change takes effect.

Data Lifecycle

Clear, predictable retention windows for every category of data we hold on your behalf.

Active Data

Retained for the duration of your subscription.

Account Export

Available for 30 days after termination on request.

Deletion

After the 30-day export window, your data is erased automatically and backups roll off soon after.

Logs

Run logs follow your plan (365 days if it sets none). Security log: 365 days. Endpoint audit log: 30 days.

Business Continuity

Automatic backups, point-in-time recovery, and a public status page keep the platform available, recoverable, and verifiable.

Automatic Backups

Automatic backups of the managed database with point-in-time restore. Backups are encrypted at rest by AWS and stay in the same EU region as the live database.

Point-in-Time Recovery

The database can be restored to a recent point in time – not just to the last nightly backup.

Live Service Status

Check current platform health on our status page – database, cache, storage, and queue connectivity in real time.

Incident Response

How we detect, respond to, and notify you about security incidents.

Detection

Continuous monitoring of uptime, error rates, and latency. On-call engineers are paged on incident-grade signals.

24-Hour Breach Notification

Affected customers are notified within 24 hours of us becoming aware of a personal-data breach, so they can meet their own 72-hour duty under GDPR Article 33.

Post-Incident Review

Material incidents are followed by a written root-cause analysis, shared with affected customers along with remediation steps.

The Bot Runtime

The Automize Bot is a desktop application that runs on machines you control. You control what leaves your machines.

Runs On Your Infrastructure

The Bot runs on your workstation, VM, or data centre – not on our servers. Windows, Mac, and Linux are supported – including Windows Server for always-on, unattended deployments.

Outbound Connection Only

The Bot connects outbound to the platform in eu-west-1. The screens, files, and credentials it uses stay on your machine unless an automation or your privacy settings send them.

You Choose What to Upload

What reaches the platform is what your automations send: run results, queue items, transaction details, step thumbnails, and failure screenshots (blurred by default). Admins set these switches in Bot privacy settings.

Personal Details Hidden From AI

On by default. Before text goes to an AI model, ID numbers, card and bank numbers, phone numbers, email addresses and passwords are swapped for placeholders.

See the full system requirements for supported operating systems, network rules, and machine specifications.

Documents & Resources

Reference legal documents and downloadable resources.

Privacy Policy

How we collect, use, store, and protect personal information.

Your Privacy Choices

The rights you can exercise (access, delete, correct, opt-out, limit) and how Global Privacy Control is honoured.

Privacy Request

The form to submit a data subject access, deletion, correction, opt-out, or other privacy request.

Terms of Service

The contractual terms that govern your use of the Automize platform.

Cookie Policy

The cookies and similar technologies we use, and how to manage them.

Security & Compliance Pack

Self-serve request form for our DPA, security overview, sub-processor list, audit-log architecture, governance policy pack, and PCI-DSS SAQ-A – for vendor reviews, procurement, and auditors.

Security Disclosure

Embedded HackerOne submission form, response SLA, scope, and safe-harbour terms.

Antivirus & Firewall Exclusions

The exact folders, executables, and outbound endpoints your endpoint-protection and network teams need to allowlist the bot – with a rationale per entry, the EDR behaviours to expect, and a ready-to-run Defender snippet.

Audit Log

Tenant-scoped record of every call to a critical endpoint – viewable by company admins, with filters and CSV export. Each row is part of a SHA-256 hash chain with nightly automated integrity verification and an admin-visible chain-status panel.

Report a Security Issue

If you believe you have found a security vulnerability, submit it via the embedded HackerOne form on our security disclosure page, or by e-mail. We acknowledge reports within two business days and will keep you updated on progress.

Machine-readable contact information is published at /.well-known/security.txt in line with RFC 9116.

For privacy or data-protection questions: privacy@automize.co.za or privacy-request  ·  General support: support@automize.co.za