Security, privacy and responsible technology by design.
Mazentric builds AI, data and software systems for businesses. Protecting information, managing technology risk and designing responsible systems form part of how we approach solution architecture and delivery.
Privacy & Data Protection
Mazentric considers privacy and appropriate data handling throughout the technology lifecycle. We design solutions with applicable data protection requirements, including South Africa's POPIA, in mind. The specific obligations and controls depend on the client, use case, data, jurisdictions and agreed responsibilities.
Information Security
Security controls are selected according to the architecture, risk and requirements of each engagement. Depending on that context, relevant principles may include:
- least privilege and appropriate access control
- authentication and secure handling of secrets
- encryption where appropriate to the data and architecture
- separation of development, testing and production environments
- logging, monitoring and operational visibility
- backups and recovery planning
- vulnerability management
- secure software engineering practices
Secure Engineering
Our engineering approach is to consider security during architecture, development, testing and deployment. This includes considering trust boundaries, access paths, dependencies, configuration, data flows and operational risks before and during delivery, rather than treating security only as a final review step.
AI & Data Governance
AI and data systems require governance suited to their intended use and potential impact. Relevant considerations may include appropriate data usage, privacy, data minimisation, human oversight, explainability where appropriate, model and system risk, third-party AI providers, retention, access control and responsible use. The approach is tailored to the solution and its business context.
Client Data
When Mazentric processes information on behalf of a client, data handling, access, retention, infrastructure and use of third-party providers can be governed through the relevant engagement agreements and technical architecture. Data location and residency requirements are assessed for the specific engagement rather than assumed to be the same for every solution.
Third-Party Technology
Technology solutions can involve selected cloud, infrastructure, database, communications and AI providers, depending on the engagement. Third-party services should be evaluated according to project requirements, security considerations, privacy requirements and contractual obligations.
Incident Management
Mazentric's approach includes identifying, escalating, containing and responding to suspected security incidents. Where required by applicable obligations, relevant agreements and the circumstances, we communicate with affected clients and support appropriate investigation and remediation.
Client-Specific Security Requirements
Enterprise engagements can incorporate client-specific requirements for architecture, identity, hosting, networking, data residency, auditability and security controls during solution design. Requirements should be agreed early enough to inform technical and commercial decisions.
Compliance Documentation
Appropriate contractual and compliance documentation may form part of an engagement. Where relevant, this can include confidentiality agreements, data processing or operator agreements, security requirements, project-specific data handling requirements, architecture documentation, and risk or privacy assessments. Availability and scope depend on the engagement and agreed responsibilities.
Security Enquiries
For privacy, security or enterprise assurance enquiries, contact info@mazentric.co.za.