SECURITY & DATA HANDLING

The most sensitive thing you hold is what your customers said

Call transcripts and reviews carry names, account numbers and grievances in your customers' own voices. Synergi treats every batch accordingly: isolated to your workspace, redacted before analysis, encrypted in transit and at rest.

HOSTING REGION

Johannesburg, with one disclosed exception

Synergi runs in Johannesburg. All application compute, the database, object storage, cache and task queues are deployed in South Africa, and backups stay in the region — there are no off-region or off-shore copies of your content. Exactly one flow carries client content across the border: analytical inference by our language-model provider in the United States, over TLS, under a zero data retention agreement, on text that has already been redacted. We commit to prior written notice before any change to region or residency posture.

CERTIFICATIONS, STATED HONESTLY

What we hold, and what we do not

Immersion X does not hold ISO 27001 or SOC 2 certification in its own right, and does not claim otherwise. Assurance comes from three places instead: our cloud infrastructure provider is SOC 2 Type 2 audited and its hardware runs in ISO 27001-certified data centres; the application is tested by an independent South African security firm at least twice a year, including an annual authenticated grey-box engagement, with reports available to clients under NDA; and the platform is built and scanned against CIS Benchmarks as its named security baseline, aligned to ISO/IEC 27001:2022, NIST CSF 2.0 and OWASP ASVS as design references. A signed attestation of current security posture is available to any client on request.

HOW THE PLATFORM IS BUILT

Tenancy

Every workspace is its own tenant. Batches, findings and users belong to one organisation and are visible to no other. Every project, file and result carries a mandatory link to one organisation, membership is validated on every request, and storage keys are organisation-scoped — a user of one organisation cannot reach another's data, including by direct URL manipulation.

Access control

Accounts exist by invitation only, roles gate every screen and action, and two-step verification is mandatory for every account — enrolment is enforced at first sign-in, with no exemption for administrators. Passwords require a 12-character minimum with common-password blocking, and repeated failed sign-ins are rate-limited and temporarily blocked.

In transit and at rest

TLS 1.2+ only at the edge with HSTS preloaded; internal traffic runs on a WireGuard-encrypted private network and never crosses the public internet; database, object storage, cache and volumes are encrypted at rest; secrets live in the platform secret store, never in code.

Redaction before analysis

South African identifiers — ID numbers, phone numbers, bank accounts, policy numbers, names — are masked server-side before any model reads a record. A record dominated by personal identifiers is quarantined rather than analysed, and a quote that cannot be verified verbatim against the redacted source is never displayed as one.

THIRD-PARTY PROCESSING

What runs where, by function

Only one of the providers we rely on ever sees client content outside South Africa.

Cloud infrastructure Compute, database, private networking South Africa Yes — encrypted at rest
Object storage Uploaded batches and derived outputs South Africa Yes — encrypted at rest
Cache and task queue Job scheduling and short-lived state Same platform as compute Transient task payloads
Language-model inference Analysis of prepared records United States Redacted text only, zero data retention

Client data is never used to train, fine-tune or benchmark any model — by us or by any provider. We give clients prior written notice of any new provider or material change, with the right to object.

The named list comes with the engagement

Work with us and we share the full disclosure under NDA: every provider named, with its region, contract status and audit position, alongside a signed attestation of current posture. Request access, run a proof of concept, and it forms part of the review.

Request access →
INCIDENT RESPONSE

A named executive, not a mailbox

Accountability for incidents sits with a named executive, not a mailbox. Incidents are classified on a four-level severity scale, and any suspected compromise of client data confidentiality or integrity is treated at the highest severity regardless of availability impact. Affected clients receive initial written notice as soon as reasonably possible and in any event within 24 hours of us becoming aware of a suspected compromise, followed by a full scope assessment within 72 hours of scope being established — supporting each client's own obligations under section 22 of POPIA. Evidence is preserved for client-nominated investigators under NDA, and a written post-incident review is produced for every serious event. Recovery is rehearsed: daily database snapshots (24-hour recovery point objective), an 8-hour recovery time objective within our control boundary, quarterly restore verifications and an annual full recovery exercise under a standalone Disaster Recovery and Business Continuity Plan.

ALSO TRUE

Your data is yours

Clients own uploaded data and every derived output; we hold a limited processing licence for the engagement term and no rights of secondary use. Retention is set per engagement, not by default; deletion is a hard delete, and on termination clients choose export-then-destroy or immediate destruction, with a signed certificate of destruction.

No integration surface

No SSO federation, no inbound APIs, no webhooks, no standing pipelines into client environments — a compromise here has no network route into yours.

Change discipline

Every change is branch + review + full test gate; deploys rebuild the OS image from current patches; dependency advisories raise automatic pull requests; infrastructure is code, never console edits.

POPIA

We operate as Operator; the client is the Responsible Party. Processing happens only on documented instruction, and we maintain a written lawful-basis analysis for the single cross-border flow.