Security & Compliance
Built on a foundation of security, privacy, and regulatory compliance.
Our commitment
Security and compliance are not afterthoughts — they are foundational to how we build Vunari. Every architectural decision considers the regulatory and security implications for our customers and their end users.
Compliance areas
PCI DSS
Payment Card Industry Data Security Standards alignment for card payment processing.
POPIA
South Africa's Protection of Personal Information Act compliance for data privacy.
Encryption
AES-256 at rest, TLS 1.3 in transit. Key management via hardware security modules.
Incident Response
Defined breach notification procedures. 72-hour regulatory reporting where required.
Access Controls
Role-based access, MFA-ready architecture, session management, audit logging.
Vendor Management
Third-party risk assessment for all payment processors and infrastructure providers.
Certifications & attestations
| Standard | Status | Details |
|---|---|---|
| PCI DSS SAQ A | Aligned | Self-assessment for hosted payment page model |
| ISO 27001 | In Progress | Information security management system certification |
| SOC 2 Type II | Planned | Security, availability, and confidentiality attestation |
Data residency & sovereignty
Primary region
All production data resides in South Africa (Johannesburg/Cape Town) via AWS or equivalent local infrastructure providers. No cross-border data transfers without explicit configuration.
Backup & disaster recovery
Automated encrypted backups with geo-redundancy within South Africa. RPO < 1 hour, RTO < 4 hours for critical financial systems. Regular restore testing.
Questions?
Our security team is available to discuss compliance requirements, share documentation, or support vendor assessments.