Trust

Security Center

SaintsLink builds security into the products and services we deliver. Our approach focuses on protecting customer data, maintaining platform integrity, and enabling resilient operations.

Company Security Philosophy

Security is a responsibility that spans our entire organisation. We design systems with privacy, reliability, and accountability in mind while keeping user trust at the centre of every decision.

Infrastructure Security

We use modern infrastructure controls to isolate production environments, reduce exposure, and prevent unauthorized access to customer data.

Secure Cloud Hosting

SaintsLink services are hosted on trusted cloud platforms that provide strong physical, network, and operational protections. We choose cloud providers based on security controls, global reach, and compliance support.

Encryption in Transit

Data moving between your browser, devices, and SaintsLink services is protected using industry-standard TLS encryption. This prevents interception and keeps connections confidential.

Encryption at Rest

Where available, we use encryption to protect stored data. This includes database records, backups, and sensitive configuration data, helping ensure information remains secure even if storage media are accessed improperly.

Authentication

Access control begins with strong authentication. We support secure login methods and encourage multi-factor authentication for customers and employees.

Password Protection

Passwords are stored securely using modern hashing techniques and are never kept in plain text. Our systems monitor for weak and reused passwords and recommend stronger credentials.

Email Verification

We validate email addresses during account setup and use verification steps to reduce the risk of unauthorized registration or account takeover.

Role-Based Access Control

SaintsLink uses role-based access control to ensure individuals and systems can only access the data and features needed for their role.

Row-Level Security

For eligible products, row-level security limits data visibility within a shared environment. This helps organisations enforce access boundaries by user, team, or business unit.

Secure APIs

APIs are protected by authentication, authorization, and rate limiting. We also apply input validation and monitoring to help prevent abuse and maintain service stability.

Monitoring

We continuously monitor our environment for threats, anomalies, and operational issues. Monitoring helps us detect potential incidents early and respond effectively.

Logging

Audit logs capture security events, access attempts, and system changes. Logs are retained securely and used to investigate issues, support troubleshooting, and improve our controls.

Backups

Regular backups are part of our data protection strategy. We store backups securely and verify recovery processes to minimise disruption.

Disaster Recovery

SaintsLink maintains disaster recovery plans to restore services in the event of failure. Our recovery processes are designed to prioritise business continuity and customer impact.

Business Continuity

Business continuity planning supports our ability to operate during outages, incidents, and other disruptions. We test critical processes to maintain service availability.

Software Development Practices

Security is embedded in our development lifecycle. We apply secure design principles, code reviews, and testing to reduce vulnerabilities before deployment.

Secure Coding

Our engineering teams follow secure coding guidelines that focus on input validation, error handling, and protection against common threats.

Dependency Management

We track and manage third-party libraries and dependencies to ensure they are up to date and free from known vulnerabilities.

Vulnerability Management

We operate a vulnerability management program that identifies, prioritises, and remediates security issues in our environment and software.

Penetration Testing

We regularly assess our systems through internal and external security testing. Penetration testing helps validate controls and uncover areas for improvement.

Incident Response

SaintsLink maintains an incident response plan to coordinate detection, investigation, containment, and recovery. We strive to resolve incidents quickly while keeping customers informed.

Responsible Disclosure

We welcome security research and responsible disclosures. If you discover a potential vulnerability, please contact us so we can address it promptly.

Security Contact

If you have a security concern or wish to report an issue, email us at:

Email: security@saintslink.com

Third-Party Providers

We work with third-party providers that meet our security requirements. We evaluate their controls and monitor how they handle customer data.

Compliance

SaintsLink aligns security practices with relevant privacy and regulatory requirements, including POPIA, GDPR principles, and recognised data protection standards.

Privacy

Protecting privacy is part of our security approach. We limit access to personal information, enforce data minimisation, and keep processing transparent.

Employee Access Controls

Internal access is granted on a need-to-know basis. We require employee training, periodic access reviews, and strong authentication for internal systems.

Physical Security

Our cloud providers operate secure data centers with access controls, monitoring, and environmental protections. We also protect our own operations with physical security best practices where applicable.

Future Security Roadmap

SaintsLink is committed to continually improving security. Our roadmap includes enhanced threat detection, stronger identity controls, expanded compliance capabilities, and deeper resilience for customers.

Back to Home