SmartHelix Trust Centre

Responsible technology needs clear ownership and evidence.

Our public assurance position explains how trust considerations are approached and what must be confirmed for each solution.

Trust by design

Clear commitments. Evidence matched to the engagement.

SmartHelix combines architecture, delivery controls and operational ownership. This centre explains the public assurance position and identifies what is confirmed during solution design and due diligence.

Public

Privacy Notice

How website and enquiry information is handled.

Read the notice
Public

Terms of use

The conditions that apply when using the SmartHelix website.

Read the terms
Engagement-specific

Technical assurance

Architecture, controls, hosting, integration and support evidence are aligned to the contracted solution.

Request a discussion

Privacy and data

Use only what the operating purpose requires.

Purpose and minimisation

Define why information is needed, limit collection to that purpose and avoid unnecessary sensitive data.

Access and accountability

Design role-based access, ownership, logging and retention around the agreed operating and legal requirements.

Deployment boundaries

Confirm where data is processed, stored and supported for the specific edge, on-premises, cloud or hybrid design.

Customer context

Data roles, integrations, retention and cross-border considerations are documented for the engagement rather than assumed.

Responsible AI

Human accountability remains part of the system.

AI-enabled solutions are designed around an authorised purpose, proportionate data use, measurable performance and a defined human decision path.

01

Defined purpose

Link the model and its outputs to a clear operating need, decision and accountable owner.

02

Human oversight

Identify which outputs inform people, which actions require review and where escalation is needed.

03

Performance evidence

Test relevant scenarios, document limitations and monitor performance in the intended environment.

04

Traceability

Retain the technical and operational evidence needed to understand material outputs and changes.

05

Privacy and security

Apply data, access and system controls that reflect the use case and its risk.

06

Controlled change

Review material model, data, configuration and workflow changes before they affect operations.

Cybersecurity

Security is an architecture and operating responsibility.

Controls are selected according to the solution, threat model, data, integration boundaries and support model.

DesignThreats, trust boundaries, identities, interfaces and failure modes.
BuildConfiguration control, least privilege, dependency awareness and test evidence.
DeployEnvironment separation, secure configuration, acceptance criteria and accountable handover.
OperateMonitoring, incident paths, access review, continuity and controlled improvement.

Resilience and service

Design for the day after go-live.

Support, monitoring, continuity and recovery are shaped with the architecture so ownership remains clear when conditions change.

Assurance topicConfirmed during the engagement
Availability and recoveryService dependencies, recovery objectives, backup approach and accepted recovery tests.
Monitoring and supportWhat is monitored, escalation paths, service hours, responsibilities and reporting.
Change and releaseApproval boundaries, test evidence, rollback requirements and production handover.
Supplier and platform dependenciesThird-party responsibilities, material limitations and evidence available for review.

Accessibility

Digital services should remain usable across people, devices and contexts.

SmartHelix aims to build interfaces with semantic structure, keyboard operation, visible focus, readable contrast, responsive layouts and reduced-motion support. Accessibility requirements and testing depth are agreed for each product or engagement.

This statement describes an approach, not a blanket conformance certification for every SmartHelix product.

Security reporting

Report a suspected SmartHelix security issue responsibly.

Email security@smarthelix.co.za with the subject Security disclosure. Describe the affected public service, the observed issue and a safe way to reproduce it.

Please do not:
  • access, alter or download data that is not yours;
  • disrupt a service or use destructive testing;
  • send credentials, personal information or exploit code by ordinary email.

SmartHelix will route the report for review. Response timing and any testing authorisation must be agreed directly.

Procurement and due diligence

Bring the assurance questions that matter to your environment.

We can align the discussion to the proposed architecture, data, integrations, operating model and procurement requirements.

Request an assurance discussion