Security & compliance
We're not a US or EU vendor treating South African data protection law as a footnote. Here's what actually runs under the hood — no certifications we haven't earned, no claims we can't back up.
Production infrastructure runs on AWS eu-west-1 (Ireland) — not routed through a US region as an afterthought.
Every workspace enforces role-based permissions, so technicians only see and act on what their role allows.
Account, billing, and settings changes write to an audit trail your admins can review — not one your team can quietly edit.
MSP tenants keep each client's devices, tickets, and reports isolated. Clients log into a separate portal and never see another client's data.
Card details are tokenised through Paystack at signup. Allocentra never sees or stores your card number — Paystack does, as the payment processor.
Auth tokens are held in memory, never in localStorage. Sessions time out after 8 hours of inactivity, with a 5-minute warning before logout.
Allocentra (Pty) Ltd is a South African company and a POPIA responsible party in our own right — the same law our customers answer to applies to us directly, not just to the data you put in our product. If you need information for your own POPIA compliance review — data flows, retention, or a processing agreement — email privacy@allocentra.co.zaand we'll work through it with you directly, not via a support ticket queue.
Talk to sales before signup — we'll answer it directly instead of pointing you at a trust portal.