<img src="https://secure.leadforensics.com/85165.png" alt="" style="display:none;">
Skip to content
Everything your engagement programme runs on, in one system, from register to report.
Every feature, mapped to how a South African participation process actually runs.
Log grievances, track issues and commitments, and report them by type.
ISO 27001, Cyber Essentials Plus, and a straight answer on POPIA, hosting and cross-border transfer.
Run comment windows and surveys, with every response held against the person who made it.
150+ pre-built reports and dashboards, including the comments and responses report.
A named Client Success Manager, unlimited support, and a four to six week implementation.
Map interested and affected parties against the categories the law actually names.
The public side of the process: documents, comments and self-registration, priced separately.
 dropdown-demo-2 
Learn why leading organisations trust Tractivity.
Social and labour plan consultation, mine communities, traditional councils, informal rights.
IDP and budget participation, ward committees, and the duty to report back.
Licence participation and a register you keep during processing and for two years after.
Transmission corridors, renewables and community trusts, across project lives measured in decades.
Corridor-scale engagement across rail, ports and third-party network access.
Run every client project from one system, with the evidence pack ready when the authority asks.
The EIA Regulations mapped to the system, from first notice to comments and responses report.
Notice, representations and reasons, recorded well enough to survive a PAJA review.
 dropdown-demo-2 
Learn why leading organisations trust Tractivity.
Read our customer success stories and discover how our clients are delivering impact with Tractivity.
The step-by-step guide to building an effective stakeholder engagement plan, with template.
Views and insights from engagement experts, recorded at our events and free to watch.
Helpful tips, guides and articles about stakeholder engagement, project management and more.
Learn how to identify, categorise and prioritise your stakeholders with our complete guide.
Empower sustainable engagement with AccountAbility's framework and Tractivity's system.
Free guides, whitepapers, templates and more to help you deliver sustainable outcomes.
Understand your stakeholders' needs, interests and influence with our practical framework.
What POPIA means for a register of interested and affected parties, answered in full.
 dropdown-demo-2 
Learn why leading organisations trust Tractivity.
Rate your organisation across five categories in minutes and get an instant, tailored score.
Calculate the time your team loses to manual admin into a defensible number for the board.
What POPIA means for a register of interested and affected parties, answered in full.
A six-part toolkit for planning, running and documenting your stakeholder engagement.
The legal test for fair public participation, and a self-audit to find where yours is weak.
Free, practical resources for managing engagement and running public participation well.
You’re the expert. We’re the software, and the home of stakeholder engagement.
dropdown-demo-2
Learn why leading organisations trust Tractivity.
Our annual Stakeholder Engagement Day, held in the United Kingdom and open to anyone working in engagement.
The 2026 event is coming soon. Held in the United Kingdom, with sessions worth watching wherever you are.
Talks and presentations from the 2025 event, free to watch online.
Keynotes and real-world case studies from the 2024 summit, online.
Sessions and insights from our first live event, online.

Security, data protection and procurement

The answers a South African procurement process will ask for, including the ones where the honest answer is “raise it with us early”.
Every South African public sector, state-owned enterprise and listed-company deal runs through a security questionnaire.
Most of what that questionnaire asks is below.

What Tractivity holds

  • ISO 27001:2022, the international information security standard
  • Cyber Essentials Plus, backed by the UK National Cyber Security Centre and required for many UK government contracts
  • NHS Data Security and Protection Toolkit, audited annually
  • Microsoft Azure hosting, SOC 2 compliant, in an environment meeting PCI DSS, HIPAA and ISO 27001 standards
  • Annual independent penetration testing by a CREST-approved organisation
  • Achilles UVDB Silver Plus membership
  • UK G-Cloud Framework listing, as a Government Commercial Agency supplier
  • WCAG 2.2 Level A today, on track for Level AA during 2026

Certificates, penetration test summaries and the SRM Service Definition document are available on request.

Data security

Enterprise-grade infrastructure, monitored 24/7

Tractivity runs in a cloud-based, highly secure Microsoft Azure environment, the same platform trusted for mission-critical workloads by health services, government departments and major infrastructure providers.

The platform is monitored 24/7/365, and there is no local software or plugin to install for administrators or for the public.

Antivirus and malware protection

Intrusion detection

Web Application Firewall (WAF)

Regular vulnerability scanning

OS-level patch monitoring

Advanced database at rest encryption

OS file integrity monitoring


24/7/365 security operations monitoring

How the platform is secured and run

Section 19 of POPIA asks for appropriate, reasonable technical and organisational measures to protect personal information. Here's what that looks like in Tractivity, starting with the points South African teams raise most often.
Access control for special personal informationPermissions are set by role at project, module and record level. That matters under POPIA, because sections 26 to 33 treat special personal information, such as political persuasion, religious beliefs or health, as a separate category with stricter conditions for processing. Stakeholder records often hold exactly that kind of detail, so one general 'can view' permission isn't enough.
An audit trail for PAJA reviews and PAIA requestsEvery record is date-stamped and attributed, and can be filtered and exported. If a decision is challenged under PAJA, or a PAIA request comes in, this is the record you'll be asked for: who was consulted, what they said and how it was handled.
AI that stays off until you switch it onAI Sentiment and AI Summarise are switched off by default and activated only with your consent. They run inside Tractivity's Microsoft Azure environment, Azure OpenAI acts only as an operator (POPIA's term for a data processor), and customer data is never used to train or fine-tune models. Every feature is configurable, and all AI is included in the subscription.
Opt-in checked before every mailshot

Section 69 of POPIA covers direct marketing by electronic communication, including email, so buyers often ask about it. The Mailshot module checks every address and confirms the stakeholder has opted in before a mailshot goes out.

Security and operations at a glance

  • Encryption: Data is encrypted at rest and in transit.

  • Security operations: 24/7/365 monitoring, a web application firewall, intrusion detection, regular vulnerability scanning, and operating system file integrity and patch monitoring.

  • Availability: A 99.95% uptime guarantee.

  • Backups: Daily and encrypted, stored in a separate secure location for 30 days. Tested weekly by file integrity check and manual restore, signed off by a systems engineer and the Technical Director. Virtual machines can be restored within 60 minutes.

  • Maintenance and releases: Monthly maintenance out of hours, with staged testing, a documented process and a rollback plan. Critical updates are applied within 24 hours of release, also out of hours. Major feature releases every three to four months.

Where your data is hosted

Tractivity runs on Microsoft Azure, with UK data residency by default and other regions available.

There is no general data localisation requirement in South African law, but the National Policy on Data and Cloud pushes residency in policy terms, and state-owned enterprises increasingly write in-country hosting into ICT tenders. On published material reviewed August 2026, no vendor in this category offers in-country South African hosting. If in-country hosting is a requirement of your tender, raise it at the outset so the available options for your deployment can be confirmed in writing.

POPIA, in the terms a procurement process will ask about

Full analysis, including the eight conditions for lawful processing and the four ways POPIA differs from the GDPR, is on our POPIA and your stakeholder database page. In summary, six things get asked, and here are the answers.

Engineer reviewing engagement reports, with POPIA controls in Tractivity

POPIA questions that come up

Answered in the order a procurement officer usually asks them.

1

Roles

You are the responsible party. Tractivity is the operator. Section 20 requires us to process only with your knowledge or authorisation and to treat the information as confidential.

2

Lawful basis

A statutory participation register does not rest on consent. Section 11(1)(c) covers processing that complies with an obligation imposed by law, and section 11(1)(e) processing necessary for the proper performance of a public law duty by a public body.

3

Special personal information

Race or ethnic origin, political persuasion and trade union membership are prohibited by default under sections 26 to 33, and South African engagement records routinely contain all three. Permissions operate at project, module and record level so those fields can be restricted to the roles that need them.

4

Collection notices

Section 18 requires notification at the point of collection, including whether the information will be transferred out of South Africa and the level of protection there. Collection notices are configurable and versioned, and the version each data subject received is held on the record.

5

Direct marketing

Section 69 draws a hard line between a statutory notice and a promotional communication. Opt-in and objection state is held per recipient, and the Mailshot module validates every address and checks opt-in before a send goes out.

6

Breach notification

Section 22 places the duty on you to notify the Information Regulator and affected data subjects. Section 21 places the duty on us to notify you immediately where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person.

Procurement and tender questions

South African public procurement asks for things a UK vendor does not carry by default.

What we have. A UK G-Cloud listing and Government Commercial Agency supplier status, which is a meaningful signal for state-owned enterprises and government buyers assessing whether we have been through public sector assurance before. ISO 27001:2022 and Cyber Essentials Plus certificates, penetration test summaries, and the SRM Service Definition document, all available on request.

What we will need to work through with you

Central Supplier Database registration, tax clearance, and B-BBEE status. A foreign vendor with no South African entity scores nothing on B-BBEE, and on a scored tender that is a real deduction rather than a technicality. Where B-BBEE weighting is material, a South African partner or reseller arrangement is usually the answer, and we would rather discuss that at the start of a bid than discover it at evaluation.

icon_political-data-1Access to information requests (PAIA)

Public bodies compile and publish a manual under section 14 and private bodies under section 51. Records of engagement held by a public body, including attendance registers, minutes, comment logs and grievance files, are potentially requestable.

Field-level classification, redaction-friendly exports and a third-party notification workflow are built for that, and it is worth designing your own configuration with PAIA in mind rather than after the first request.

The operator agreement

Section 21 requires the operator relationship to be governed by a written contract obliging us to maintain the section 19 security measures and to notify you immediately on a suspected breach. Our standard data processing agreement is built to UK GDPR, which shares most of POPIA’s architecture. If your procurement process requires POPIA-specific operator wording, raise it at the outset and we will confirm what we can sign in writing.

Trusted with sensitive stakeholder data across government, health, energy and rail

Security and procurement, answered

Where is Tractivity data hosted?

Tractivity runs on Microsoft Azure, with UK data residency by default and European, United States and other regions available. If in-country hosting is a requirement of your tender, raise it at the outset so the available options for your deployment can be confirmed in writing.

What security certifications does Tractivity hold?

ISO 27001:2022, the international information security standard. Cyber Essentials Plus, backed by the UK National Cyber Security Centre. The NHS Data Security and Protection Toolkit, audited annually. Microsoft Azure hosting, which is SOC 2 compliant, in an environment meeting PCI DSS, HIPAA and ISO 27001 standards. Annual independent penetration testing by a CREST-approved organisation. Achilles UVDB Silver Plus membership, and a UK G-Cloud listing as a Government Commercial Agency supplier.

Who is the responsible party and who is the operator under POPIA?

In a Tractivity deployment the client is the responsible party and Tractivity is the operator. Section 20 of POPIA requires an operator to process only with the responsible party’s knowledge or authorisation and to treat the information as confidential, and section 21 requires the relationship to be governed by a written contract obliging the operator to maintain the section 19 security measures and to notify the responsible party immediately where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person.

What are the uptime and backup arrangements?

A 99.95 per cent uptime guarantee with 24/7/365 monitoring. Daily encrypted backups stored in a separate secure location for 30 days, tested weekly by file integrity check and manual restore and signed off by a systems engineer and the Technical Director, with virtual machines restorable within 60 minutes. Security operations include 24/7/365 monitoring, a web application firewall, intrusion detection, regular vulnerability scanning and operating system file integrity and patch monitoring.

Is Tractivity accessible?

Tractivity meets WCAG 2.2 Level A today and is on track for Level AA during 2026. The platform is browser-based with no local software or plugins required for administrators or public users, and it uses no intrusive or non-essential cookies.

How does Tractivity handle special personal information under POPIA?

Sections 26 to 33 prohibit processing race or ethnic origin, political persuasion and trade union membership by default, and South African engagement records routinely contain all three. Permissions operate at project, module and record level, so those fields can be restricted to the roles that need them rather than being visible to everyone with access to the record.

Are AI features switched on by default?

No. AI features are off by default and activated only with your consent. All AI runs inside Tractivity’s Microsoft Azure environment, Azure OpenAI acts solely as a data processor, customer data is never used for model training or fine-tuning, every feature is configurable, and all AI is included in the subscription.

What does Tractivity’s B-BBEE status mean for a scored tender?

A foreign vendor with no South African entity scores nothing on B-BBEE, and on a scored tender that is a real deduction rather than a technicality. Where B-BBEE weighting is material, a South African partner or reseller arrangement is usually the answer. Raise it at the start of a bid rather than at evaluation.

Can engagement records be released under PAIA?

Potentially, yes. Records of engagement held by a public body, including attendance registers, minutes, comment logs and grievance files, fall within the scope of a PAIA request. Field-level classification, redaction-friendly exports and a third-party notification workflow are built for that, and it is worth designing your configuration with PAIA in mind rather than after the first request.

Send us the questionnaire

If you are running a security or procurement assessment, send it over and we will answer it in writing, including the parts where the answer is not yet. That is usually faster than three rounds of email.

Worth reading next: POPIA and your stakeholder database and the stakeholder management platform.

Ready to see the platform in action?

Bring your security and compliance questions to a live demo and we would be happy to show you how access control, encryption and audit trail work in practice.

Book a demo