Built for enterprise procurement
Cyntech serves regulated clients across renewables and oil & gas in South Africa, the EU, UK and United States. This page is our living record of how we secure and govern the data you trust us with.
Security posture
Technical and organisational measures aligned to ISO 27001 Annex A, NIST CSF 2.0 and IEC 62443 for our energy-sector exposure.
TLS 1.2+ in transit, AES-256 at rest for managed storage and database.
Role-based access (RBAC) at database and application layer; mandatory MFA on admin accounts.
Row-level security on all multi-tenant tables; per-tenant scoped access policies.
Administrative actions, auth events and data exports logged with retention.
Primary data hosted in EU region with documented chain of access from South Africa operations.
Continuous dependency scanning, scheduled pen-tests, coordinated disclosure programme.
Compliance by jurisdiction
How we meet obligations across our home jurisdiction and client regions.
- ›POPIA — Information Officer registered
- ›PAIA manual on request
- ›Cybercrimes Act incident-reporting playbook
- ›ECT Act electronic contracting
- ›GDPR + UK GDPR processor obligations
- ›2021 SCCs Module 2 in DPA
- ›UK IDTA / Addendum B.1.0
- ›NIS2 / DORA flow-down ready
- ›CCPA / CPRA processor terms
- ›CIRCIA incident-reporting workflow
- ›State breach-notification matrix
- ›IEC 62443 control-system security alignment
- ›ISO 27019 energy-sector controls (roadmap)
- ›IOGP 627 / 645 alignment
- ›TSA / NERC CIP flow-down ready
Authorised sub-processors
Updated as engagements change. Existing customers receive 30 days' notice of additions or replacements.
| Sub-processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Supabase (managed Postgres, Auth, Storage) | Primary application database, authentication, file storage | EU (Ireland) / customer-elected region | SCCs Module 2 + UK Addendum |
| Cloudflare | Edge compute, DNS, DDoS mitigation, TLS termination | Global edge | SCCs Module 2 + UK Addendum |
| Resend | Transactional email delivery (invites, password resets, notifications) | United States / EU | SCCs Module 2 + UK Addendum |
| Lovable Cloud | Application hosting and deployment pipeline | Global edge | SCCs Module 2 + UK Addendum |
| Stripe (if billing enabled) | Card payment processing for subscription billing | United States / EU / UK | SCCs Module 2 + UK Addendum + PCI DSS L1 |
Last reviewed: 5 June 2026. To subscribe to sub-processor change notifications, email privacy@cyntech.co.za.
Roadmap to attestation
We document what we already do today, what is in flight, and what we are building toward — no green-washing of certifications we have not earned.
- RLS-enforced multi-tenant DB
- MFA on admin accounts
- Encrypted backups
- Vulnerability disclosure policy
- DPA template available
- ISO 27001:2022 certification
- ISO 27701 privacy extension
- SOC 2 Type II report
- ISO 27019 energy-sector controls
- IEC 62443-2-4 alignment
- Independent penetration test cadence
Working with our security team
We respond to SIG, CAIQ and bespoke security questionnaires. Typical turnaround is 5 business days for an initial draft.
security@cyntech.co.zaOur Information Officer handles DPA execution, sub-processor objections and data-subject request flow-downs.
privacy@cyntech.co.zaSee also our Privacy Policy, POPIA Notice, PAIA Manual, Incident Response, E-Signature Notice, Cookie Policy and Terms of Use.
