TRUST

What is implemented, and what is aligned to.

You are going to have to defend this choice to an IT security review and probably to a regulator. So this page separates what the platform does today from what it is designed in line with, in a column, rather than blurring the two.

STATUS

How to read the tables below.

Implemented
Live in the platform today. We can demonstrate it in a session and describe how it works to your security team.
Available
Supported, but a deployment choice rather than a default. Which option applies to you is agreed during implementation and written into the contract.
Aligned to
The design follows the named standard or statute. It is not a certification and we do not present it as one. Where a certificate exists we will say so and give you the certificate.
Planned
On the roadmap, not built. Listed so you can plan around it, never counted as a control you can rely on today.

PLATFORM

Identity, access and encryption

Identity, access and encryption
Area Status Detail
Single sign-on Implemented Microsoft Entra ID. Your existing identity, groups, MFA and conditional access policies govern access. No second user directory to maintain, and a leaver loses access when you disable them in Entra.
Role-based access control Implemented Permissions by role and by scope, so a control owner sees their controls, an auditor sees the register read-only, and a committee member sees the reporting view without the working papers.
Audit trail Implemented Every create, edit, score change, approval, attestation and closure is recorded with user, timestamp and previous value. The trail cannot be edited or deleted from the application by any role.
Encryption in transit Implemented TLS on every connection to the application and to its API. HTTP requests are redirected, and HSTS is set.
Encryption at rest Implemented Database and file storage are encrypted at rest using the platform's managed encryption.

DATA

Hosting, data and recovery

Hosting, data and recovery
Area Status Detail
Hosting Implemented Microsoft Azure. The region for your tenant is agreed during implementation and stated in the contract; Azure regions are available across Africa, Europe, the Middle East, Asia-Pacific and the Americas.
Data residency options Available Where your regulator or your board requires data to remain in a particular jurisdiction, the region is selected at deployment and written into the contract. Ask us what is available for your jurisdiction before you assume it — we would rather tell you no early than discover it in month three.
Tenant separation Implemented Each client's data is logically separated. A dedicated environment is available at Enterprise where a security review requires it.
Backup and recovery Implemented Automated backups with point-in-time restore. Recovery point and recovery time objectives are agreed and stated in the contract rather than published as a headline figure here.
Export and exit Implemented You can export your register, controls, obligations, evidence and audit trail at any time in open formats. Exit terms, including the export you receive at the end of a contract, are in the agreement.

ASSURANCE

Standards, statutes and assurance

Standards, statutes and assurance
Area Status Detail
GDPR Aligned to Where the GDPR or the UK GDPR applies to your organisation, our processing terms address controller and processor duties, sub-processors, international transfer safeguards and breach notification.
Data Protection Act 2019 (Kenya) and equivalents Aligned to Sibasi Ltd is incorporated in Kenya, so the Act applies to us directly. The same processing terms are written to cover equivalent national regimes; tell us which apply to you and we will confirm how each is met.
ISO 31000 — risk management Aligned to The register, scoring, appetite and treatment model follow the ISO 31000 process. This is a design alignment. ISO 31000 is guidance and is not a certifiable standard, so no organisation can be certified against it.
ISO 37301 — compliance management Aligned to The obligations register, policy lifecycle and attestation model are designed in line with ISO 37301. Sibasi does not hold ISO 37301 certification and does not claim it.
ISO 27001 — information security Aligned to Our information security practices are designed in line with ISO 27001. Sibasi does not currently hold an ISO 27001 certificate. If that changes we will publish the certificate here rather than the claim.
Penetration testing Implemented Independent testing is commissioned and findings are remediated on a severity-based schedule. A summary report and current remediation status are shared with prospective clients under NDA.
SOC 2 Type II Planned Not held and not in progress. Listed here because procurement teams ask, and the honest answer is more useful to you than a page that stays silent on it.

DATA

Data protection.

In an eGRC deployment you are the data controller and Sibasi Ltd is a data processor acting on your documented instructions. That is set out in the data processing terms attached to the contract, which cover controller and processor duties, sub-processors and their locations, international transfer safeguards and breach notification — under whichever regime applies to you.

Sibasi Ltd is incorporated in Kenya, so the Data Protection Act 2019 applies to us directly. Where the GDPR, the UK GDPR or another national regime applies to your organisation, the same terms address it. Tell us which regimes you are subject to during procurement and we will confirm in writing how each is met.

In practice the personal data in a risk register is modest — mostly the names, job titles and work email addresses of risk owners, control owners and the staff who complete attestations. It is not customer or member data unless you choose to put it there. We will say so plainly to your Data Protection Officer, because over-stating the sensitivity of the data is as unhelpful as under-stating it.

  • Purpose and instruction

    We process personal data only to run the service for you, on your documented instructions, and we do not use your register content to train models.

  • Subject rights

    Access, correction and erasure requests are handled by you in the application; we support you with export and, where needed, deletion from backups on the agreed schedule.

  • Breach notification

    We notify you without undue delay so you can meet your own notification duty to your supervisory authority and to affected people, within the deadline your regime sets.

  • Sub-processors

    The list of sub-processors and their locations is provided during procurement and updated in writing when it changes.

This page describes how the platform supports your obligations. It is not legal advice, and your own counsel and Data Protection Officer should review it against the regimes that apply to you.

TESTING

Penetration testing and assurance.

We commission independent penetration testing of the platform and remediate findings on a severity-based schedule. We will share a summary report with a prospective client under NDA, and the remediation status of any finding relevant to your review.

We do not publish a test report on this website, and you should be wary of any vendor who does — a public report is either redacted to the point of meaninglessness or a map of the attack surface.

  • Your own testing

    You may test your own tenant. Scope and timing are agreed in advance so we do not treat it as an incident, and findings come back to us through the same remediation process.

  • Security questionnaires

    Send us yours. We complete client security questionnaires as part of procurement rather than asking you to accept a summary page as the answer.

ASKED

What security reviews ask us.

Is eGRC ISO 27001 certified?

No. Our information security practices are designed in line with ISO 27001, which is an alignment, not a certification, and we do not present it as one. Sibasi does not currently hold an ISO 27001 certificate. If that changes we will publish the certificate rather than the claim.

Where is our data hosted?

On Microsoft Azure. The specific region for your tenant is agreed during implementation and written into the contract, and Azure regions are available across Africa, Europe, the Middle East, Asia-Pacific and the Americas. If your regulator or board requires data to remain in a particular jurisdiction, tell us early and we will tell you what is available before you commit.

Under the Data Protection Act, who is the controller?

You are. Sibasi Ltd acts as a data processor on your documented instructions, set out in the data processing terms attached to the contract — which address the GDPR, the Kenya Data Protection Act 2019 and equivalent regimes. We do not use your register content to train models.

Can we see a penetration test report?

We share a summary report and the current remediation status with prospective clients under NDA. We do not publish one on this website, and we would be cautious of any vendor who does. You may also test your own tenant, with scope and timing agreed in advance.

Bring your security team to the first call.

It shortens everything. Most of what an information security review needs is a conversation with someone who can answer architecture questions directly, and we would rather have that early than after a commercial decision.