Trust Centre
Security, Privacy, and Sovereign System Governance
KePAY is engineered from the ground up to protect employee data sovereignty and eliminate the risk of corporate information exposure. We operate as a strictly audited Operator under South African data frameworks, choosing technical blindness over centralized data storage.
System Security & Cryptographic Artifacts
Hybrid Zero-Knowledge posturing
- Payload Isolation: All granular payroll values, bank account numbers, and net salary distributions are immediately encrypted at the ingestion boundary using the Advanced Encryption Standard (AES-256). KePAY holds zero plaintext visibility or master decryption keys.
- Directory Metadata Protection: Basic routing indicators (employee personnel numbers and cellular contact nodes) are maintained in a completely separate, isolated database instance encrypted at rest using AES-256.
Client-Side Local Decryption
- Zero Cloud Visibility: Our cloud databases do not store or compile unencrypted, pre-built PDF documents. Cryptographic math executes solely within the user's local mobile browser memory using single-use 2FA verification PINs.
- On-Device PDF Export: High-fidelity, bank-ready PDF payslips generate directly inside the phone's physical cache, evaporating from our platform network once the browser session terminates.
Sovereign Cloud Infrastructure & Repositories
South African Sovereign Hosting
- Data Residency Alignment: 100% of KePAY platform application code, directory databases, routing tables, and backups reside within enterprise cloud availability zones located strictly within the borders of the Republic of South Africa (AWS Cape Town/Johannesburg regions).
Immutable Operational Controls
- Dual-Authorization Code Merges: Our development infrastructure bars individual code deployment actions. No software updates or schema modifications can push live without a formal Pull Request co-signed digitally by the CEO via secure, hardware-backed authentication profiles.
- Tamper-Proof Audit Logging: Every administrative action, database query, backend interaction, and transmission outcome generates a permanent, non-deletable system log entry for forensic validation.
Business Continuity & Operational Resilience
Disaster Recovery SLA Targets
- Recovery Point Objective (RPO): Maximum of 1 (one) hour of data lag under any technical failover condition.
- Recovery Time Objective (RTO): Full application environment re-stabilization and failover operational readiness within 4 (four) hours of an infrastructure anomaly.
Anti-Theft Device Infrastructure Policy
- Rapid Kill-Switch Routines: All Company engineering computers and developer endpoints utilize full-disk encryption, local biometric sandboxing, and automated remote-wipe configurations that trigger within 60 minutes of any physical theft report.
Statutory Compliance & Legal Blueprints
To fast-track corporate vendor onboarding processes, download our clean, verified legal frameworks directly:
Vulnerability Ingestion & Incident Response
KePAY operates a proactive vulnerability monitoring pipeline. If you are an enterprise security researcher, white-hat pentester, or client administrator and uncover a potential system anomaly, please engage our monitoring desk directly:
Direct Security Desk Email: security@kepay.co.za
Response Commitment: Our engineering team will review, triage, and acknowledge all security disclosures within 4 (four) hours of payload receipt, providing an automated remediation path within 24 hours.
