Data Security & Privacy

Your data is secure,
private, and yours.

RiskScope is built for the South African insurance industry, where data integrity, confidentiality, and regulatory compliance are non-negotiable. This page explains exactly how we protect your data and your clients' information.

🔒TLS 1.3 Encrypted
⚖️POPIA Compliant
🛡️Grade A Security
📅5-Year Retention

In plain language

Is my data encrypted?
Yes, in transit and at rest, using bank-grade TLS encryption.
Do you sell my data?
Never. Your data is not shared with any third party for any commercial purpose.
How long is data kept?
Five years, in line with FAIS requirements. Earlier deletion available on request.
Who can see my reports?
Only you, your authorised team members, and RiskScope support staff.
Are you POPIA compliant?
Yes. We process all personal information in accordance with POPIA Act 4 of 2013.
Can data be mixed between users?
No. Each assessment has a unique session ID. Data isolation is enforced at the database level.

Security built for the South African insurance industry

Commercial property risk assessments contain sensitive client data, property details, and business information. South African brokers, underwriting managers, and insurers require confidence that this data is handled with the same rigour expected of any regulated financial services provider.

RiskScope is registered under POPIA with the Information Regulator of South Africa, processes all payments through a PCI-DSS Level 1 certified provider, retains records for the minimum five-year period required under FAIS, and implements bank-grade TLS 1.3 encryption across all data in transit and at rest.

🔒

Data Encryption & Transmission

  • All data transmitted between your device and RiskScope is encrypted using TLS 1.2/1.3, the same standard used by South African banks and financial institutions.
  • Connections are enforced over HTTPS at all times. Unencrypted HTTP access is automatically blocked.
  • Assessment data, photos, and personal information are never transmitted in plain text.
🗄️

Data Storage & Infrastructure

  • All assessment data, reports, and photos are stored in a secure, encrypted PostgreSQL database hosted on enterprise-grade cloud infrastructure.
  • Photos submitted during assessments are compressed and stored as encrypted database records not stored as publicly accessible files on the internet.
  • Database access is restricted exclusively to the RiskScope backend server. No external party can query the database directly.
  • Infrastructure is hosted within a secure cloud environment with automated backups and monitoring.
🔑

Authentication & Access Control

  • User authentication is handled by Clerk, an enterprise-grade authentication provider. Passwords are never stored in plain text; they are hashed using industry-standard bcrypt encryption.
  • Each user session is individually verified on every API request. Session tokens expire automatically.
  • Enterprise account credit balances are stored exclusively on the server side and can only be modified by the RiskScope backend after a confirmed payment and cannot be altered by a user's browser session.
  • Admin access to internal systems is restricted to authorised RiskScope personnel only, protected by multi-factor authentication.
🛡️

Data Isolation & Privacy

  • Each assessment runs in its own isolated session identified by a unique session ID. It is technically impossible for one user's data to appear in another user's report.
  • Enterprise broker accounts are fully isolated. Each account can only access its own assessments and report history.
  • RiskScope does not sell, rent, share, or transfer any client data to third parties for any commercial purpose.
  • Assessment data is used solely for the purpose of generating the requested risk assessment report.
⚖️

POPIA Compliance

  • RiskScope processes personal information in accordance with the Protection of Personal Information Act, 2013 (POPIA), Act 4 of 2013.
  • RiskScope (Pty) Ltd is registered with the Information Regulator of South Africa as a responsible party under POPIA, with a designated Information Officer responsible for data governance. Registration certificate held on file.
  • Personal information is collected only for the specific purpose of generating a risk assessment report and is not used for any other purpose without explicit consent.
  • Data subjects have the right to request access to, correction of, or deletion of their personal information at any time by contacting support@riskscope.co.za.
  • Complaints relating to the processing of personal information may be submitted to the Information Regulator at inforegulator.org.za.
📅

Data Retention

  • Assessment records and generated reports are retained for a minimum of five years from the date of submission, in line with FAIS record-keeping requirements applicable to the South African short-term insurance industry.
  • After the applicable retention period, data is permanently deleted from all systems.
  • Clients may request earlier deletion of their personal information at any time, subject to any legal record-keeping obligations that may apply.
🤝

Third-Party Service Providers

  • RiskScope uses a small number of carefully selected infrastructure providers to operate the platform. These providers act as data processors; they provide technical infrastructure only and do not have access to assessment content or report outputs for their own purposes.
  • All third-party providers are contractually bound to process data only as instructed by RiskScope and to maintain appropriate security standards.
  • No assessment data, client information, or report content is shared with insurers, brokers, or any other party without the explicit instruction of the account holder.
🌐

Website Security Headers

  • The RiskScope website implements a full suite of HTTP security headers, including Content Security Policy (CSP), HTTP Strict Transport Security (HSTS), X-Frame-Options, and Permissions Policy.
  • These headers protect against common web attacks including cross-site scripting (XSS), clickjacking, and man-in-the-middle attacks.
  • Our security header implementation has been independently verified and achieves a Grade A rating on the securityheaders.com assessment tool.
📋

Report Integrity

  • Every photo submitted during an assessment carries GPS coordinates and a timestamp embedded in the file metadata, confirming the location and time of capture.
  • RiskScope's logic engine cross-references all submitted answers for internal consistency. Contradictions or inconsistencies are automatically flagged.
  • The submitting broker or client signs off that all information provided is accurate and complete. This is the same declaration used on standard insurance proposal forms, carrying the same liability framework.
💳

Payment Security & PCI-DSS

  • All payment card transactions on riskscope.co.za are processed exclusively by PayFast, a PCI-DSS Level 1 certified payment service provider — the highest level of payment security certification available.
  • RiskScope never receives, stores, processes, or transmits payment card numbers, CVV codes, or banking credentials of any kind. Card data goes directly from your browser to PayFast over an encrypted connection.
  • Because RiskScope has no access to card data at any point in the transaction, the platform is PCI-DSS compliant by design through the use of a certified third-party processor.
  • Enterprise EFT payments are processed via PayFast secure EFT gateway. No bank account details are stored on RiskScope infrastructure.
Security enquiries

Questions about data security, POPIA compliance, or to request a data processing agreement:

support@riskscope.co.za →
Company details

RiskScope (Pty) Ltd
Reg. No. 2026/536813/07
B-BBEE Level 1 Contributor
Member of FPASA

This security statement was last updated July 2026. RiskScope reviews and updates its security practices regularly. Material changes will be reflected here.