Security and POPIA
The page for whoever has to approve this.
If you are the person being asked whether the practice can let an outside team near its documents, this page is written for you. It states what is true, and it is explicit about what we do not claim.
The shape of it
Four things you will want to establish.
Who can reach a document
Access is by role and by collection, configured to rules you set and maintained as people join and leave.
Who actually did
Every access, every version and every change is recorded. This is verified in the platform and is not a policy statement.
Where it lives
Decided with you at the assessment and written into the service agreement, rather than left to a supplier default.
What happens if you leave
A structured export with the index intact, on a timescale written into the agreement.
In detail
What we do, specifically.
Access
Permissions are set per collection and per role, and they are maintained as part of the service rather than at your IT team's expense. Staff changes are handled the week they happen, because the controller is already working in the system daily.
The audit trail
Every document carries its full history: every version, who added it, what changed, and every access. That trail is what makes a document defensible rather than merely stored, and it is the single most useful thing to be able to show during an investigation or a complaint.
Where documents live
There is no single answer, and any supplier who gives you one before seeing your practice is guessing. The platform supports on-premise, a dedicated environment, and a shared environment. Which of those suits you depends on your volumes, your sensitivity and your budget, and it is one of the decisions the assessment settles. Whatever is agreed is written into the service agreement.
Backup and recovery
Backup, restore testing and recovery expectations are agreed per engagement and stated in the service agreement, including how far back you can go and how long a restore takes. A backup you have never tested is a hope rather than a control, so restore testing is part of the service and appears in the monthly report.
People
The people who touch your documents are named, they sign confidentiality undertakings, and you are told when they change. During the assessment nothing leaves your premises without your written agreement.
Incidents
If something goes wrong we tell you, in writing, with what happened and what we are doing. POPIA has its own notification requirements for a compromise of personal information, and the practical value of the audit trail is that it lets us tell you exactly what was affected instead of guessing at the scope.
The honest part
What we do not claim.
Every one of these is something you may have been offered elsewhere. We would rather lose the deal than write a sentence you could not defend to an auditor.
- We do not enforce your retention schedule.
- We show you what you hold and everything that has happened to it. Deciding what may be destroyed, and when, stays with you and your attorney. We do not automate destruction.
- We are not an AI product.
- Classification and extraction are rules based. That makes them deterministic, explainable and auditable: if a document was filed a particular way, we can show you exactly why. In regulated work that is an advantage, not a limitation.
- There is no machine learning model deciding where your documents go.
- Nothing is trained on your documents, because nothing here learns.
- We do not route approvals automatically.
- Your document controller runs the process and records the outcome. The platform holds the record.
- We hold no certifications on your behalf.
- Provelis is not ISO certified and we will not imply that using us makes you compliant with anything. Compliance stays yours; what we remove is the practical failure of not being able to produce a record.
The questions IT asks
Technical answers.
Can our documents stay in South Africa?
Yes, and for most practices that is what we recommend. It is a decision taken at the assessment and written into the agreement, not a default we apply silently.
Can we host it ourselves?
Yes. On-premise is supported, and some clients prefer it. It changes the cost shape rather than the service.
What integrations are available?
There is a REST API, and capture from mailboxes, scanners and file shares. Specific connectors to your existing systems are a scoping question rather than a yes: if we have not built one, integrating is development work with a cost, and we will say so rather than implying it is included.
Who has administrative access?
Named individuals on our side, listed in the agreement, and whoever you nominate on yours. Administrative actions appear in the same audit trail as everything else.
What does the exit look like?
A structured export of your documents with the index intact, in a format we agree up front, within a period stated in the agreement. Ask every supplier this question and compare the answers.
Start here
Find out what you actually hold.
Two weeks, a fixed price, and three things you keep: a register of your documents, a list of what you cannot produce, and a costed plan to put it right.
Book an assessment