What we don't do

We don't do POPIA — here's who does

POPIA tooling in South Africa is already well served. There are tools that scan your systems and track consent from around R750 a month, and they do it better than a questionnaire could. What almost nobody covers is whether the AI your team uses every day is actually governed. That's our job.

If POPIA is what you need

Look for a dedicated POPIA tool. The local ones handle data mapping, consent records and subject requests, and several start under R1 000 a month. A law firm or privacy consultant is the right call for the legal questions. We'd rather point you there than sell you a thinner version of it.

Where AI and POPIA meet

The two aren't separate problems. The minute someone pastes a customer list, a CV or a support thread into an AI tool, it's a privacy question as well as an AI one. Our ISO/IEC 42001 assessment covers exactly that: what data may be used with AI, where it's stored, whether the supplier trains on it, who signed it off, and whether a person checks decisions that affect people. That work counts towards POPIA too, even though we don't assess POPIA itself.

What we do cover

AI management systems

ISO/IEC 42001 readiness

Check whether your business uses and builds AI tools in a responsible, well-managed way.

Take a look
Information security management

ISO/IEC 27001 readiness

See how close you are to the international standard for keeping business information safe.

Take a look