APEX

Compliance & security

Your audit trail exists before anyone asks for it.

POPIA and NCA obligations enforced by the system — not by someone's memory. Eight controls, built in, impossible to switch off by accident.

NCA pre-screening

Your minimum criteria — for example R1m minimum turnover and 3+ active supply clients — are enforced at application stage. The rule cannot be bypassed, deleted or overridden by accident.

Weighted risk engine

Every application is scored on an auditable matrix — credit score 40%, financials 30%, industry risk 20%, collateral 10% — with a credit risk profile you can see and defend.

POPIA field-level logging

Every access to personal information is logged at field level — who, when, what, why. Your PII isn't just protected, its access history is provable.

DSAR workflow

Data subject access requests run a tracked workflow with a 21-business-day SLA. Nothing is assembled on demand from inboxes.

Committee approval

Loans above your committee threshold require mandatory Credit Committee sign-off. Single-person control is a design flaw we engineered out.

Anomaly detection

Access patterns are monitored across the platform. Unusual behaviour is flagged before it becomes a breach notification.

7-year audit trail

The System Audit Trail logs every action immutably — user, entity, old value, new value, timestamp. Exportable on demand.

NCA compliance report

A structured report covering your credit provider obligations, generated for your annual submission or legal team.

Independently validated

UAT run by the client's own Risk, Compliance & Legal Officer.

Before go-live, the first enterprise tenant's Risk, Compliance and Legal Officer ran user acceptance testing on the live system. Result: zero critical or high-severity issues. That's the standard every deployment is held to.

Every deployment is followed by a 90-day defects liability period. Your compliance officer signs off the close — not us.

UAT sign-off summary

Passed
Critical severity issues0
High severity issues0
Data migration accuracy100%
Tested byClient Risk / Compliance / Legal
Deployment typeOnboarding, not development

Trust & security

The infrastructure facts your Risk officer will ask for.

Data residency

South African data residency

Encryption

Encryption at rest and in transit

Access control

6 role-based levels — admin, manager, officer, collector, accountant, committee

Authentication

Two-factor authentication (MFA) + session timeouts

Bank integrations

FNB / SBSA / Nedbank mandates

Messaging

Real Meta WhatsApp Business API

UAT

Zero critical or high-severity issues before go-live

Warranty

90-day defects liability after every deployment

Not sure where your compliance stands? Get the 12-point readiness check.

Twelve questions on KYC, retention, DSAR, access logging and consent. A scored report names your specific gaps — and what closing them looks like.

See your gaps