Security, data protection and procurement
What Tractivity holds
- ISO 27001:2022, the international information security standard
- Cyber Essentials Plus, backed by the UK National Cyber Security Centre and required for many UK government contracts
- NHS Data Security and Protection Toolkit, audited annually
- Microsoft Azure hosting, SOC 2 compliant, in an environment meeting PCI DSS, HIPAA and ISO 27001 standards
- Annual independent penetration testing by a CREST-approved organisation
- Achilles UVDB Silver Plus membership
- UK G-Cloud Framework listing, as a Government Commercial Agency supplier
- WCAG 2.2 Level A today, on track for Level AA during 2026
Certificates, penetration test summaries and the SRM Service Definition document are available on request.

Enterprise-grade infrastructure, monitored 24/7
Tractivity runs in a cloud-based, highly secure Microsoft Azure environment, the same platform trusted for mission-critical workloads by health services, government departments and major infrastructure providers.
The platform is monitored 24/7/365, and there is no local software or plugin to install for administrators or for the public.
Antivirus and malware protection
Intrusion detection
Web Application Firewall (WAF)
Regular vulnerability scanning
OS-level patch monitoring
Advanced database at rest encryption
OS file integrity monitoring
24/7/365 security operations monitoring
How the platform is secured and run
Section 69 of POPIA covers direct marketing by electronic communication, including email, so buyers often ask about it. The Mailshot module checks every address and confirms the stakeholder has opted in before a mailshot goes out.
Security and operations at a glance
-
Encryption: Data is encrypted at rest and in transit.
-
Security operations: 24/7/365 monitoring, a web application firewall, intrusion detection, regular vulnerability scanning, and operating system file integrity and patch monitoring.
-
Availability: A 99.95% uptime guarantee.
-
Backups: Daily and encrypted, stored in a separate secure location for 30 days. Tested weekly by file integrity check and manual restore, signed off by a systems engineer and the Technical Director. Virtual machines can be restored within 60 minutes.
-
Maintenance and releases: Monthly maintenance out of hours, with staged testing, a documented process and a rollback plan. Critical updates are applied within 24 hours of release, also out of hours. Major feature releases every three to four months.
Where your data is hosted
Tractivity runs on Microsoft Azure, with UK data residency by default and other regions available.
There is no general data localisation requirement in South African law, but the National Policy on Data and Cloud pushes residency in policy terms, and state-owned enterprises increasingly write in-country hosting into ICT tenders. On published material reviewed August 2026, no vendor in this category offers in-country South African hosting. If in-country hosting is a requirement of your tender, raise it at the outset so the available options for your deployment can be confirmed in writing.
POPIA, in the terms a procurement process will ask about
Full analysis, including the eight conditions for lawful processing and the four ways POPIA differs from the GDPR, is on our POPIA and your stakeholder database page. In summary, six things get asked, and here are the answers.

POPIA questions that come up
Answered in the order a procurement officer usually asks them.
Roles
You are the responsible party. Tractivity is the operator. Section 20 requires us to process only with your knowledge or authorisation and to treat the information as confidential.
Lawful basis
A statutory participation register does not rest on consent. Section 11(1)(c) covers processing that complies with an obligation imposed by law, and section 11(1)(e) processing necessary for the proper performance of a public law duty by a public body.
Special personal information
Race or ethnic origin, political persuasion and trade union membership are prohibited by default under sections 26 to 33, and South African engagement records routinely contain all three. Permissions operate at project, module and record level so those fields can be restricted to the roles that need them.
Collection notices
Section 18 requires notification at the point of collection, including whether the information will be transferred out of South Africa and the level of protection there. Collection notices are configurable and versioned, and the version each data subject received is held on the record.
Direct marketing
Section 69 draws a hard line between a statutory notice and a promotional communication. Opt-in and objection state is held per recipient, and the Mailshot module validates every address and checks opt-in before a send goes out.
Breach notification
Section 22 places the duty on you to notify the Information Regulator and affected data subjects. Section 21 places the duty on us to notify you immediately where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person.
Procurement and tender questions
South African public procurement asks for things a UK vendor does not carry by default.
What we have. A UK G-Cloud listing and Government Commercial Agency supplier status, which is a meaningful signal for state-owned enterprises and government buyers assessing whether we have been through public sector assurance before. ISO 27001:2022 and Cyber Essentials Plus certificates, penetration test summaries, and the SRM Service Definition document, all available on request.
What we will need to work through with you
Central Supplier Database registration, tax clearance, and B-BBEE status. A foreign vendor with no South African entity scores nothing on B-BBEE, and on a scored tender that is a real deduction rather than a technicality. Where B-BBEE weighting is material, a South African partner or reseller arrangement is usually the answer, and we would rather discuss that at the start of a bid than discover it at evaluation.
Access to information requests (PAIA)
Public bodies compile and publish a manual under section 14 and private bodies under section 51. Records of engagement held by a public body, including attendance registers, minutes, comment logs and grievance files, are potentially requestable.
Field-level classification, redaction-friendly exports and a third-party notification workflow are built for that, and it is worth designing your own configuration with PAIA in mind rather than after the first request.
The operator agreement
Section 21 requires the operator relationship to be governed by a written contract obliging us to maintain the section 19 security measures and to notify you immediately on a suspected breach. Our standard data processing agreement is built to UK GDPR, which shares most of POPIA’s architecture. If your procurement process requires POPIA-specific operator wording, raise it at the outset and we will confirm what we can sign in writing.
Trusted with sensitive stakeholder data across government, health, energy and rail


















Security and procurement, answered
Tractivity runs on Microsoft Azure, with UK data residency by default and European, United States and other regions available. If in-country hosting is a requirement of your tender, raise it at the outset so the available options for your deployment can be confirmed in writing.
ISO 27001:2022, the international information security standard. Cyber Essentials Plus, backed by the UK National Cyber Security Centre. The NHS Data Security and Protection Toolkit, audited annually. Microsoft Azure hosting, which is SOC 2 compliant, in an environment meeting PCI DSS, HIPAA and ISO 27001 standards. Annual independent penetration testing by a CREST-approved organisation. Achilles UVDB Silver Plus membership, and a UK G-Cloud listing as a Government Commercial Agency supplier.
In a Tractivity deployment the client is the responsible party and Tractivity is the operator. Section 20 of POPIA requires an operator to process only with the responsible party’s knowledge or authorisation and to treat the information as confidential, and section 21 requires the relationship to be governed by a written contract obliging the operator to maintain the section 19 security measures and to notify the responsible party immediately where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person.
A 99.95 per cent uptime guarantee with 24/7/365 monitoring. Daily encrypted backups stored in a separate secure location for 30 days, tested weekly by file integrity check and manual restore and signed off by a systems engineer and the Technical Director, with virtual machines restorable within 60 minutes. Security operations include 24/7/365 monitoring, a web application firewall, intrusion detection, regular vulnerability scanning and operating system file integrity and patch monitoring.
Tractivity meets WCAG 2.2 Level A today and is on track for Level AA during 2026. The platform is browser-based with no local software or plugins required for administrators or public users, and it uses no intrusive or non-essential cookies.
Sections 26 to 33 prohibit processing race or ethnic origin, political persuasion and trade union membership by default, and South African engagement records routinely contain all three. Permissions operate at project, module and record level, so those fields can be restricted to the roles that need them rather than being visible to everyone with access to the record.
No. AI features are off by default and activated only with your consent. All AI runs inside Tractivity’s Microsoft Azure environment, Azure OpenAI acts solely as a data processor, customer data is never used for model training or fine-tuning, every feature is configurable, and all AI is included in the subscription.
A foreign vendor with no South African entity scores nothing on B-BBEE, and on a scored tender that is a real deduction rather than a technicality. Where B-BBEE weighting is material, a South African partner or reseller arrangement is usually the answer. Raise it at the start of a bid rather than at evaluation.
Potentially, yes. Records of engagement held by a public body, including attendance registers, minutes, comment logs and grievance files, fall within the scope of a PAIA request. Field-level classification, redaction-friendly exports and a third-party notification workflow are built for that, and it is worth designing your configuration with PAIA in mind rather than after the first request.
Send us the questionnaire
If you are running a security or procurement assessment, send it over and we will answer it in writing, including the parts where the answer is not yet. That is usually faster than three rounds of email.
Worth reading next: POPIA and your stakeholder database and the stakeholder management platform.
