Information Security Policy
VOIMAR-POL-003 · Version 1.0 · Effective 9 October 2026 · Approved by VOIMAR (Pty) Ltd
Purpose
VOIMAR protects the confidentiality, integrity and availability of its own and its clients' information and systems. The policy follows the control themes of ISO/IEC 27001:2022 (organisational, people, physical and technological controls). VOIMAR is not ISO/IEC 27001 certified.
Scope
All VOIMAR systems, networks and platforms (including Heita, GYTE and Kesho), the data centres where they run, and all VOIMAR employees, contractors and partners. It also covers client environments that VOIMAR operates.
Governance
Security responsibilities, approvals and risk tiers follow VOIMAR's IT governance protocols. Any change that can affect customers is approved by the approver in their own words before it is made. The VOIMAR Change Control and Integrity Policy explains how.
Sovereign hosting
VOIMAR runs its platforms on its own infrastructure in South African data centres, and uses no foreign cloud for customer or company data. Platforms that VOIMAR builds on client premises stay inside the client's own environment and network.
Access control
- Least access: access is given for a purpose, and only the access a role needs.
- Administrative access uses personal keys or multi-factor authentication, from approved networks only. Shared accounts are being phased out.
- Access is reviewed every quarter, and removed on the same day a person leaves or changes role.
- Passwords and keys are kept in VOIMAR's secrets vault, and never in code, e-mail, chat or documents.
- Emergency (break-glass) access is sealed, recorded each time it is used, and reviewed.
Monitoring and detection
- Network, server and service monitoring with alerts to the NOC.
- Automated security anomaly detection on servers every 15 minutes.
- Repeated failed logins on management systems are blocked automatically.
- Device configuration changes are captured centrally, and logs are protected from tampering.
Vulnerability and patch management
- Systems run on supported versions.
- Security updates for servers are applied automatically, and other updates monthly in a maintenance window.
- Network operating systems are reviewed monthly and upgraded in a window, with a backup and automatic undo.
- A critical vulnerability on an exposed system (actively exploited, or CVSS 9 and above) is fixed or mitigated within 72 hours.
Secure development
All code is kept in private repositories, mirrored every hour to VOIMAR's own self-hosted code vault in South Africa. Changes to sensitive areas (authentication, billing, secrets and voice signalling) and every significant release pass an independent code and security review before they go live. No secrets are kept in code.
AI-assisted operations
VOIMAR uses AI assistants under the same rules as people, plus extra limits. AI assistants never handle passwords or keys, move money, permanently delete data or switch off security controls. Their actions are logged separately, and every change they make that can affect customers needs a person's approval.
Backup and recovery
Backups follow the VOIMAR Business Continuity and Disaster Recovery Policy, and restores are tested every quarter.
Suppliers and partners
Suppliers and partners with access to VOIMAR or client systems agree to VOIMAR's security requirements, receive only the access they need, and are reviewed.
People
Employees and contractors are screened as their role and the client require (for example, government security clearance), trained in security, and bound by confidentiality.
Physical security
Equipment is housed in access-controlled data centres and offices. Equipment that holds data is wiped or destroyed securely when it is retired.
Incidents
Security incidents are reported immediately, contained and investigated. A root-cause review is written within 5 working days, and clients and the Information Regulator are notified where required.
Review
This policy is reviewed every year, and after any significant incident or change.
