SalesCollab

Security & trust

Your asset data, protected at every layer.

AssetTrack is built for IT teams who need to prove who has what, where, and what changed. Here is exactly how we keep your company data safe — what we control, what our infrastructure inherits, and what we will never claim.

AES-256
Encryption at rest
TLS 1.2+
Encryption in transit
RLS
Per-org isolation
72 hr
Breach notification

How we protect your data

Six controls that cover the questions prospects and procurement teams ask most often.

Encrypted end to end

Your data is encrypted on the wire and on disk — never stored in the clear.

  • TLS 1.2+ on every connection; HTTPS-only with HSTS on the published site.
  • AES-256 encryption at rest on the Postgres database and every storage bucket (asset photos, documents, job-card attachments).
  • Encrypted automated backups managed by our infrastructure provider, with the same AES-256 keys.

Your data is isolated from every other customer

Workspace isolation is enforced at the database layer, not by UI checks.

  • Every query is scoped to your organisation by row-level security policies in Postgres.
  • Members of one workspace cannot read or write another workspace’s rows — even with a valid API key.
  • Multi-customer MSP workspaces use the same per-tenant RLS model, with cross-tenant access only when explicitly granted.
  • Realtime updates are server-side filtered to the caller’s organisation.

Strong access control

Roles and 2FA stop the most common breach paths cold.

  • Roles: owner, admin, moderator, user — enforced in the database, not just hidden in the UI.
  • Two-factor authentication (TOTP — works with 1Password, Authy, Google Authenticator) available on every plan.
  • Org-wide 2FA enforcement on Pro, Business and MSP plans.
  • Sign in with Google OAuth or email + password; SAML SSO available on request.
  • Session tokens are httpOnly, rotated, and revocable from Settings → Security.

Full audit trail

Every change is recorded — for compliance, for forensics, for trust.

  • Create, update, delete and assignment events log the actor, timestamp and before/after diff.
  • Signed job cards are cryptographically immutable once locked.
  • Export the audit log as CSV or PDF for POPIA, GDPR or SOX-style evidence packs.
  • Assignment history is preserved permanently — you can answer “who held this device on 1 March 2024” years later.

Operational security

The boring stuff that prevents the loud incidents.

  • Automated daily security scans cover RLS coverage, public buckets, realtime exposure and SECURITY DEFINER functions.
  • Dependency vulnerability monitoring on every build.
  • Least-privilege service-role keys; production secrets stored in an encrypted secret manager — never in source control.
  • Production access by named personnel only, with audit trail.

Incident response

If something goes wrong, you find out quickly.

  • Customer notification of any unauthorised access or loss of personal information within 72 hours — per POPIA §22 and GDPR Article 33.
  • Documented response runbooks, with severity-based escalation to engineering and our infrastructure provider.
  • Post-incident report shared with affected customers, including root cause and remediation.

Regulatory and compliance posture

We are deliberate about what we claim. Aligned means we implement the controls the framework requires. Inherited via infrastructure means our hosting providers hold the certification and we depend on it. We will never claim a certification SalesCollab itself has not earned.

FrameworkStatusWhat this means for you
POPIA (South Africa) AlignedFull operator obligations covered in our Data Processing Addendum. Lawful basis, data subject rights, security safeguards and 72-hour breach notification all addressed.
GDPR (EU / UK) AlignedWe act as a processor on the customer’s behalf. Standard Contractual Clauses cover any EU → SA transfers; full Article 28 processor terms are in the DPA.
CCPA / CPRA (California) AlignedCustomers can export and delete personal data on request — the audit log proves the deletion. We do not sell personal data and never have.
ISO 27001 (Annex A controls) AlignedOur internal controls — least privilege, change auditing, encrypted backups, vulnerability scanning, incident response — are designed against the ISO 27001 Annex A control set. SalesCollab itself is not separately certified at this time; hosting infrastructure is (see sub-processors below).
SOC 2 Type II Inherited via infrastructureWe host on infrastructure that is independently audited to SOC 2 Type II (Supabase, Cloudflare). SalesCollab is not separately audited at this time; this is on our roadmap.
PCI DSS Inherited via infrastructureWe do not store card numbers. All payments are processed by Paystack, which is PCI DSS Level 1 certified.
HIPAANot offeredAssetTrack is not intended for protected health information (PHI). We do not currently offer a Business Associate Agreement.

Sub-processors

We use a small, deliberate set of sub-processors. Every one is independently audited and publishes its own trust documentation — links below. We give 30 days’ notice of any addition or replacement; see the DPA for the customer’s right to object.

Supabase (Lovable Cloud)

Trust page

Primary Postgres database, authentication, object storage, edge functions

SOC 2 Type II · ISO 27001 · HIPAA available

Cloudflare

Trust page

Edge delivery, web application firewall, DDoS protection, DNS

SOC 2 Type II · ISO 27001 · ISO 27018 · PCI DSS

Paystack

Trust page

Card and EFT payment processing for subscriptions

PCI DSS Level 1

Transactional email delivery (invites, alerts, receipts)

SOC 2 Type II · GDPR DPA

What we ask of you

Security is a shared model. The platform gives you the controls — you decide how to use them. We recommend every customer:

  • Enable two-factor authentication, and enforce it org-wide on Pro and above.
  • Use the smallest role (owner / admin / moderator / user) that lets each person do their job.
  • Revoke access promptly when someone leaves — assignment history is preserved automatically.
  • Classify the documents you upload and avoid storing data the platform is not intended for (e.g. PHI, raw payment data).
  • Keep your billing email and a security contact up to date so we can reach you.

Report a security concern

Found a vulnerability, or have a question for our security team? Email us — we triage within one business day.

marketing@salescollab.co.za

For procurement documents — signed DPA, sub-processor list, security questionnaire — put “Procurement” in the subject and we will send the latest pack.