Security Statement
Last Updated: 15 June 2025
1. Our Commitment to Security
AIsend (Pty) Ltd is committed to maintaining the highest standards of information security. This Security Statement outlines our approach to protecting data and systems.
2. Security Practices
We implement a comprehensive security program based on industry best practices and standards:
- Risk Assessment: Regular security risk assessments to identify and mitigate potential threats
- Vulnerability Management: Continuous vulnerability scanning and timely patching
- Security Monitoring: 24/7 monitoring of systems and networks for security events
- Employee Training: Regular security awareness training for all employees
- Third-Party Reviews: Security assessments of vendors and service providers
3. Access Controls
We maintain strict access control measures:
- Principle of Least Privilege: Access is granted on a need-to-know basis
- Multi-Factor Authentication: Required for all administrative access
- Role-Based Access Control: Permissions defined by job function
- Access Reviews: Regular audits of user access and permissions
- Session Management: Automatic timeout and secure session handling
4. Data Protection
Data protection is central to our security program:
- Encryption in Transit: TLS 1.2+ for all data in transit
- Encryption at Rest: AES-256 encryption for stored data
- Data Classification: Information classified by sensitivity level
- Secure Backup: Encrypted backups with regular testing
- Data Minimisation: Only necessary data collected and retained
5. Incident Response
We maintain an incident response plan to address security events:
- Detection: Automated monitoring and alerting systems
- Containment: Immediate action to limit impact
- Investigation: Thorough analysis of incidents
- Remediation: Corrective actions to prevent recurrence
- Notification: Timely disclosure as required by law
6. Infrastructure Security
Our infrastructure is hosted in secure data centres with:
- Physical security controls including biometric access and surveillance
- Network segmentation and firewall protection
- Intrusion detection and prevention systems
- Regular penetration testing and security assessments
- Automated security patching and updates
7. Compliance and Certification
We align our security practices with:
- POPIA (Protection of Personal Information Act)
- Industry-standard security frameworks
- Client-specific security requirements
8. Reporting Security Concerns
To report a security vulnerability or incident, please contact us immediately:
Email: [email protected]
Response Time: We acknowledge security reports within 24 hours
