Security & Safety
Last updated: 24 August 2026
This overview explains how SENTRIX™, operated by KTH Projects (Pty) Ltd t/a KTH-Tech (Registration No. 2025/627290/07), protects your data and how the platform is built to be used safely. It is written plainly and honestly: it describes the controls that are in place today, and — separately and clearly — the ones that are on our roadmap and not yet in place. We do not claim certifications we do not hold.
Security controls in place today
These are live in the platform now:
- Encryption in transit and at rest. Every connection uses TLS 1.3. Data is encrypted at rest (AES-256) by our managed database host.
- Password security. Passwords are never stored in plain text — they are hashed with bcrypt (work factor 12). We cannot see or recover your password.
- Authenticated sessions. Access uses signed, expiring JSON Web Tokens; every API request is verified server-side.
- Role-based access control (RBAC). Ten roles (CEO, director, PM, finance, risk, tech, auditor, sponsor, contractor, admin) with least-privilege permissions enforced on the server, not merely hidden in the interface. Each organisation’s data is fully isolated from every other organisation (multi-tenant separation on every query).
- Append-only audit trail. Material actions are logged, timestamped and attributed to a user. The trail is designed to be added-to, not edited, and can be exported as an evidence pack.
- Hardened defaults. HTTP security response headers, request rate-limiting, and a strict cross-origin policy are active from the first request.
- Least-data-by-design. We collect only what the platform needs to do its job, and scope access to it by role and organisation.
Data protection & POPIA
SENTRIX is built POPIA-first. We capture consent, honour data-subject rights (access, correction, deletion, objection), maintain an appointed Information Officer and a PAIA manual, keep operator agreements with our sub-processors, and follow purpose-limitation and retention discipline. Full detail — including how to exercise your rights — is in our Privacy Policy. Governance reporting in the product is aligned to King IV and PFMA expectations.
Hosting & data residency
SENTRIX runs on managed cloud infrastructure with encryption, network isolation and provider-side backups. For government and public-sector engagements, hosting can be pinned to a South African region so that data stays in-country. Residency, backup and retention specifics are confirmed per engagement in the service agreement — talk to us before contracting if in-country residency is a firm requirement for you.
Using SENTRIX safely (decision-support, not decisions)
SENTRIX is a decision-support tool. It is important to understand what that means:
- AI insights are guidance, not verdicts. The forecasts and recommendations are generated from your project data using transparent, rule-based logic. They are probabilistic and are meant to inform a human decision, not replace one.
- Project Fingerprint™ is benchmarking, not a guarantee. Matching your programme against the benchmark corpus surfaces comparable precedents to learn from. Similar past projects do not guarantee a future outcome.
- Keep a human in the loop. SENTRIX does not take automated actions with legal or financial consequences on your behalf. Material decisions — budget, contracts, escalations — remain yours.
- Your data drives your results. The quality of insights depends on the accuracy of what is entered. Treat outputs as one input to good governance, alongside your own judgement and controls.
On our roadmap (planned — not yet in place)
In the interest of honesty, the following are planned improvements we have not yet implemented or certified. We will update this page as each lands:
- Independent third-party penetration test and remediation report.
- SOC 2 Type II and ISO 27001 certification (these require completed external audits over time; we do not claim them today).
- Single sign-on (SAML 2.0 / OIDC), SCIM provisioning, and multi-factor authentication (MFA).
- Formally documented disaster-recovery and backup RTO/RPO targets.
- Air-gapped / on-premises deployment option for high-assurance government environments.
If any of these are a procurement requirement for you now, please raise it with us directly rather than assuming it is already in place.
Reporting a security issue (responsible disclosure)
If you believe you have found a security vulnerability in SENTRIX, please tell us before disclosing it publicly. Email sentrix@kth-tech.com with the words “Security Disclosure” in the subject and enough detail to reproduce the issue. We will acknowledge your report, investigate, and keep you updated. We will not pursue or support legal action against good-faith researchers who follow this process, avoid privacy violations and data destruction, and give us reasonable time to fix the issue.
Incident & breach response
If a security compromise affects personal information, we follow POPIA breach-notification obligations: we investigate and contain the incident, notify the Information Regulator, and notify affected data subjects as soon as reasonably possible where required. Our Information Officer coordinates this response (contact details in the Privacy Policy).
Questions
For any security, safety or data-protection question, contact us at sentrix@kth-tech.com. See also our Privacy Policy and Terms of Service.