SECURITY & TRUST

What we do, and what we won't claim.

You're being asked to trust a platform with your contracts, your costs and your commercial terms. That deserves specifics, not badges.

Role-based access

people see what's relevant to their role; leadership keeps the full picture.

Complete activity history

every action attributed and timestamped, permanently.

Secure document handling

contracts, quotes, POs and invoices stored against the record with controlled access.

Configurable reminders and escalation

the safety net is part of the security model.

Exportable records

your data is yours; take a complete export at any time.

Retention and deletion controls

data lifecycle on your terms.

Encryption, backups and monitored availability

in transit and at rest, tested, watched.

Documentation on request

our current security documentation, shared in a walkthrough.

POPIA-conscious by design

processing limited to what the service requires, retention and deletion controls in the product, and a plain-language privacy policy. UK GDPR readiness follows with our UK launch.

We run our own medicine

our own backups and failover tests are tracked as recurring obligations in Renewals360. We run our own medicine.

We don't hold ISO 27001 today, and you won't find a badge on this page pretending otherwise.

Our rule is simple: we only claim what we've built. What you've just read is exactly what's in place, and when a certification is in progress, this page will say "in progress", not "certified". If your procurement process needs more detail, ask: we'll walk you through it, honestly.

Ask us the hard questions.