Security & POPIA

How Stubie protects your price list and your customers’ data.

Stubie holds what your customers said, what you charge and what they owe. Here is how that is protected, and what happens when something goes wrong.

The controls

What protects your desk.

Encrypted end to end of the pipe

TLS 1.2 or better in transit, AES-256 at rest, including backups. Bank details and access tokens are stored in a separate secrets vault.

One tenant cannot see another

Every record carries its tenant. Queries are scoped at the database, not in the application, so a bug cannot leak another shop's price list.

Staff access is the exception

LinxAI staff cannot read your messages by default. Support access is time-boxed, tied to a ticket, logged, and shown to you in your audit trail.

Every approval is on record

Who approved which quote, at what price, at what time, kept for five years. Useful in a dispute, and the reason status only moves forward.

Backed up, and tested

Encrypted backups on a 35-day cycle, restored into a test environment quarterly. A backup nobody has restored is not a backup.

Your money never touches us

Customers pay into your own account against your reference. Stubie holds no funds, so there is nothing of yours to lose here.

POPIA

Under POPIA, you’re the responsible party and we’re your operator.

Your customers’ information belongs to your business. LinxAI processes it on your instruction, under a written operator agreement, and for no purpose of our own. Ask and we will send the agreement before you sign anything.

  • Section 19 security safeguards, documented and reviewed annually
  • Section 21 operator agreement, signed at onboarding
  • Section 22 breach notification: to you first, then the Regulator
  • Section 72 terms wherever a processor sits outside South Africa
If there is a breach

The clock we hold ourselves to.

≤ 24 hYou are told what happened, what data was involved and what we have already done.
≤ 72 hA written report you can forward to your own customers, and to the Information Regulator.
≤ 14 dRoot cause, the fix, and what changed so it does not happen twice.
alwaysNo quiet fixes. If your data was involved, you hear it from us first.
Asked in every security review

Security questions

Do you train AI models on my customers' messages?

No. Content sent to language-model providers is covered by terms that exclude it from training, and we do not train models of our own on your data.

Does my data leave South Africa?

Your desk is supported from Krugersdorp. Some of the infrastructure, messaging and language-model providers that run it process data outside South Africa. Where that happens, section 72 of POPIA applies and the recipient is contractually held to an equivalent standard.

Can a LinxAI employee read my quotes?

Not by default. Support access requires an open ticket, expires automatically, is logged, and appears in the audit trail on your own desk.

What happens to my data if I leave?

You get an export of quotes, orders, customers and your price list. Message content is deleted 90 days after closure; financial records are held five years because tax law requires it.

Can Stubie send something to a customer by mistake?

Nothing sends without an approval step. Reminders only go out against orders you have already approved, inside working hours, and can be paused per order.

Send us your security questionnaire.

We answer it in full, in writing, before you commit to anything. support@stubie.co.za

Talk to us