Izenzo
Trust Surface

Trust, security & privacy

How Izenzo secures the governance network and handles the data within it.

Last updated: 21 June 2026

Shared responsibility

Izenzo secures the platform infrastructure; workspace administrators are responsible for managing user access, API key rotation, and the accuracy of data submitted to the network.

Access & authentication

  • Email and password authentication
  • Role-based access control (RBAC) per workspace
  • Row-level security on all tenant data
  • API keys scoped per workspace, revocable at any time
  • Session expiry and re-authentication for sensitive actions

Platform & hosting context

  • Managed Postgres database
  • Object storage for evidence and documents
  • Serverless functions for API endpoints
  • TLS in transit for all traffic

Data we collect & how it is used

We collect account, entity, KYB/KYC, and trade-record data necessary to operate the governance network. This data is used to verify counterparties, run compliance workflow, and produce hash-sealed trade records — never sold to third parties.

Retention & deletion

  • Trade records are retained per regulatory requirements
  • Account data is retained for the life of the workspace
  • Deletion requests are honoured subject to audit retention obligations

Subprocessors & integrations

A current list of subprocessors is available on request.

Cookies & analytics

We use minimal, privacy-respecting analytics to operate and improve the platform.

Privacy requests

For privacy requests, contact privacy@izenzo.co.za.

Security contact & vulnerability reporting

Report security issues to security@izenzo.co.za.

Compliance & certifications

For compliance enquiries, including POPIA, contact compliance@izenzo.co.za.

This page is editable project content maintained by the Izenzo team. It is not independently verified and should not be relied upon as legal advice.