Patch management and network discovery are live — See pricing →

Built by a South African company, subject to POPIA ourselves.

We're not a US or EU vendor treating South African data protection law as a footnote. Here's what actually runs under the hood — no certifications we haven't earned, no claims we can't back up.

Data residency

Production infrastructure runs on AWS eu-west-1 (Ireland) — not routed through a US region as an afterthought.

Role-based access

Every workspace enforces role-based permissions, so technicians only see and act on what their role allows.

Immutable audit log

Account, billing, and settings changes write to an audit trail your admins can review — not one your team can quietly edit.

Per-client data isolation

MSP tenants keep each client's devices, tickets, and reports isolated. Clients log into a separate portal and never see another client's data.

No stored card numbers

Card details are tokenised through Paystack at signup. Allocentra never sees or stores your card number — Paystack does, as the payment processor.

Session handling

Auth tokens are held in memory, never in localStorage. Sessions time out after 8 hours of inactivity, with a 5-minute warning before logout.

On POPIA, specifically

Allocentra (Pty) Ltd is a South African company and a POPIA responsible party in our own right — the same law our customers answer to applies to us directly, not just to the data you put in our product. If you need information for your own POPIA compliance review — data flows, retention, or a processing agreement — email privacy@allocentra.co.zaand we'll work through it with you directly, not via a support ticket queue.

Have a security questionnaire to get through?

Talk to sales before signup — we'll answer it directly instead of pointing you at a trust portal.

Contact salesBook a demo