INFORMATION SECURITY

Security you can verify,
not just trust.

Independently audited, internationally certified information security ,
protecting the operational data that moves through our platforms every day.

Our Commitment

Information security is foundational to everything we build.

Inhance builds and operates supply chain technology for some of South Africa's largest retailers and logistics operators. That responsibility demands more than good intentions , it demands independently audited, internationally certified information security.

ISO/IEC 27001:2022 Certified

Our Information Security Management System has been independently assessed against the international standard.

BSI Certification

Inhance Supply Chain Solutions (Pty) Ltd

CERTIFICATE NUMBER IS 846352
CERTIFICATION BODY BSI (British Standards Institution)
STANDARD ISO/IEC 27001:2022

CERTIFICATION SCOPE

Management and protection of all information assets supporting the provision
of supply chain solutions, business systems, consulting and design services
and 4PL and outsourced services.

0
Nonconformities
at our initial certification audit
This result reflects how deeply security management is embedded in our operations, rather than bolted on for compliance.

WHAT OUR ISMS COVERS

Security managed across the business

Our ISMS governs how we identify, assess, and treat information security risk.

Governance and accountability

Security is directed at board level and aligned with the King IV governance framework. Policies, risk registers, and controls are reviewed on a defined cycle, with clear ownership and executive accountability.

Risk-based controls

We apply the ISO 27001 Annex A control set across organisational, people, physical, and technological domains from access management and secure development practices to supplier security and incident response.

Continuous improvement

Certification is not a one-off event. Our ISMS operates on a continual improvement cycle with internal audits, management reviews, and annual surveillance audits by BSI.

POPIA

DATA PROTECTION

POPIA built into our
architecture and operations.

As a South African company processing data for both South African and Global enterprises, compliance with the Protection of Personal Information Act is not treated as an afterthought.

Personal information is processed lawfully, minimally, and for defined purposes under documented operator agreements
Data residency and cross-border transfer considerations are addressed at architecture level
AI deployment models prioritise keeping sensitive data within controlled, compliant environments

SECURITY IN PRACTICE

Resilient infrastructure
Secure development

INFRASTRUCTURE

Enterprise-grade cloud resilience

Our cloud-native platforms operate across Amazon Web Services and Microsoft Azure.

Geographically separated primary and disaster recovery environments, with defined recovery objectives
All data moving between users, integrations, and our platforms is encrypted using TLS 1.2 or higher
Data is encrypted at rest using AES-256, with managed key services
Environment segregation, least-privilege access, and production logging and monitoring
Business continuity and disaster recovery procedures tested as part of our ISMS
SECURE DEVELOPMENT

Security integrated into delivery

Controls are applied throughout how our teams design, build, test, and release software.

Defined secure development lifecycle with code review and release controls
Segregated development, testing, and production environments
Vulnerability management and dependency monitoring
Change management governing all production releases
Reviewed Accountable Controlled
WORKING WITH OUR SECURITY TEAM

Need help completing a security assessment?

We regularly support customer due diligence, vendor risk assessments and security questionnaires. Contact us for a copy of our certificate, our scope statement or assistance with an assessment.

Quick Contact
close slider