Trust Surface
Trust, security & privacy
How Izenzo secures the governance network and handles the data within it.
Last updated: 21 June 2026
Shared responsibility
Izenzo secures the platform infrastructure; workspace administrators are responsible for managing user access, API key rotation, and the accuracy of data submitted to the network.
Access & authentication
- Email and password authentication
- Role-based access control (RBAC) per workspace
- Row-level security on all tenant data
- API keys scoped per workspace, revocable at any time
- Session expiry and re-authentication for sensitive actions
Platform & hosting context
- Managed Postgres database
- Object storage for evidence and documents
- Serverless functions for API endpoints
- TLS in transit for all traffic
Data we collect & how it is used
We collect account, entity, KYB/KYC, and trade-record data necessary to operate the governance network. This data is used to verify counterparties, run compliance workflow, and produce hash-sealed trade records — never sold to third parties.
Retention & deletion
- Trade records are retained per regulatory requirements
- Account data is retained for the life of the workspace
- Deletion requests are honoured subject to audit retention obligations
Subprocessors & integrations
A current list of subprocessors is available on request.
Cookies & analytics
We use minimal, privacy-respecting analytics to operate and improve the platform.
Privacy requests
For privacy requests, contact privacy@izenzo.co.za.
Security contact & vulnerability reporting
Report security issues to security@izenzo.co.za.
Compliance & certifications
For compliance enquiries, including POPIA, contact compliance@izenzo.co.za.
This page is editable project content maintained by the Izenzo team. It is not independently verified and should not be relied upon as legal advice.