Skip to content

Security

Built for information you are legally obliged to protect

This page is maintained by Atora to answer common security and privacy questions. It describes current practices and platform controls — it is not an independent certification.

POPIA compliant

Placeholder copy. Processing agreements, data subject request handling and retention controls designed around South African law.

Secure authentication

Placeholder copy. Mandatory two-factor authentication for administrators, session controls and role-based permissions.

Encrypted data

Placeholder copy. TLS 1.3 in transit and AES-256 at rest, with encrypted, access-logged backups.

Cloud infrastructure

Placeholder copy. Enterprise cloud hosting with isolation between firms, monitoring and tested recovery procedures.

Trust

Controls at a glance

Placeholder trust badges — replace with verified marks once assessments are complete.

POPIAAES-256TLS 1.32FA EnforcedDaily BackupsAudit Logs

Shared responsibility

Placeholder copy. Atora is responsible for the platform: hosting, encryption, authentication controls and availability. Your firm remains responsible for who you grant access to, the accuracy of the data you record, and your own obligations to clients and regulators.

Reporting a vulnerability

Placeholder copy. Email security@atora.co.za with details of any suspected issue. We acknowledge reports within one business day.

Ready to see it inside your own practice?

Start your 7-day free trial today. A card is required to begin, but nothing is charged until day 7.