Security and POPIA
You are trusting us with contracts and personal information. Here is how that trust is kept, in plain terms.
Per-workspace isolation
Access is enforced in the database with row-level security. A query can only ever return rows belonging to your own workspace, so one customer's documents are structurally invisible to another.
No shared admin logins
Every person has their own account and their own role. We never issue or email shared administrator credentials, and roles are checked on the server for every request.
Your data stays in region
Documents and personal information are stored with a provider hosting in-region, in line with POPIA expectations for the processing of South African personal information.
Export and delete on request
You can export everything in your workspace, and you can delete your account and its data. We honour access and deletion requests as POPIA requires.
Encrypted in transit and at rest
All traffic runs over TLS, and stored data and documents are encrypted at rest by the hosting platform.
Audit trail
Create, edit, export, and delete actions are recorded with the user and a timestamp, giving you a clear record for your own governance.
A note on advice
Attest helps you draft and understand documents. It does not replace legal advice on a complex, disputed, or high-value matter. When the stakes are high, have an admitted attorney check the final document.