Our commitment
Encircle is a governance intelligence platform trusted with sensitive compliance documents, board records, and governance assessments. Security is built in from the start. We apply the same governance standards we help our clients achieve.
Data encryption
- In transit: all data transmitted between your browser and Encircle servers is encrypted using TLS 1.2 or higher.
- At rest: everything Encircle holds, assessment responses, governance scores, and the record of which document satisfied which control, is encrypted at rest using AES-256. Your documents themselves are never uploaded to us; they stay in your connected drive or on your own machine.
Access control
- Role-based access controls restrict who within your organisation can view, upload, or manage evidence and reports.
- All user authentication requires strong passwords. Multi-factor authentication (MFA) is available and recommended for all accounts.
- Encircle staff access to customer data is restricted on a strict need-to-know basis and is subject to audit logging.
Audit trail
Every action taken within the Platform, document uploads, task completions, evidence submissions, user logins, and report generation, is logged with a timestamp and user identifier. Audit logs are immutable and available to your administrators.
Infrastructure
- Encircle is hosted on enterprise-grade cloud infrastructure with SOC 2 Type II and ISO 27001 certified providers.
- Data is stored in South Africa or within the African region where available, in line with our data residency commitments.
- Automated daily backups with point-in-time recovery ensure data durability.
- Infrastructure is monitored 24/7 with automated alerting for anomalous activity.
Application security
- The Platform undergoes regular security testing including vulnerability assessments.
- Dependencies are monitored for known vulnerabilities and updated promptly.
- We follow OWASP Top 10 guidelines in our development practices.
Incident response
We maintain a documented security incident response procedure. In the event of a data breach that affects your personal information, we will notify you and, where required, the Information Regulator of South Africa, within 72 hours of becoming aware of the breach, in line with POPIA §22.
Your responsibilities
Security is a shared responsibility. You can help protect your Encircle account by:
- Using a strong, unique password and enabling MFA.
- Not sharing login credentials.
- Promptly reporting suspected unauthorised access to security@encircle.co.za.
- Keeping your registered email address current so you receive security notifications.
Responsible disclosure
If you discover a security vulnerability in the Encircle Platform, please report it responsibly to security@encircle.co.za. We will acknowledge your report within 48 hours and keep you informed of our progress. We do not pursue legal action against researchers who follow responsible disclosure principles.