Straight Answers

The questions South African businesses actually ask.

Clear, honest answers on POPIA, cybersecurity, websites and AI — no jargon walls, no sales fog. Read what you need, and when you're ready, a real person picks up.

Behind these answers is a small South African engineering team — real people who reply, usually within a few hours. Message a human on WhatsApp →

POPIA

South Africa's data-protection law — what it is, and what it actually asks of your business.

What does POPIA stand for?

POPIA stands for the Protection of Personal Information Act (Act 4 of 2013) — South Africa's data-protection law. It governs how organisations may collect, use, store and share the personal information of customers, staff and the public.

What is POPIA compliance?

Being POPIA-compliant means processing personal information lawfully across the Act's eight conditions, appointing and registering an Information Officer, genuinely securing the data you hold, and being able to prove all of it if the Information Regulator asks. It's a documented, defensible position — not a box to tick once. See our POPIA compliance audit →

What are the eight conditions of POPIA?

They are: Accountability, Processing Limitation, Purpose Specification, Further Processing Limitation, Information Quality, Openness, Security Safeguards, and Data Subject Participation. Every one has to be met — not just the convenient ones.

When did POPIA come into effect?

POPIA's main provisions commenced on 1 July 2020 with a one-year grace period, becoming fully enforceable on 1 July 2021. It is in force now, and the Information Regulator actively investigates complaints.

How long can you keep personal information under POPIA?

Only for as long as it's genuinely needed for the purpose it was collected — unless a law requires you to keep it longer, or the person consented. Once the purpose ends, the information should be deleted or de-identified rather than kept "just in case".

What are your rights under POPIA?

You can ask what information an organisation holds about you, have it corrected or deleted, object to certain processing, and complain to the Information Regulator. Organisations are required to make these rights easy to exercise, not buried.

What must a business do after a data breach under POPIA?

Notify the Information Regulator and the affected people as soon as reasonably possible after discovering a breach that compromises personal information — in practice, treat it as a 72-hour clock. Move fast, document everything, and contain the exposure. See data breach response →

What are the penalties for breaking POPIA?

The Information Regulator can issue enforcement notices and administrative fines of up to R10 million, and serious offences can carry imprisonment — on top of the reputational damage of a public breach.

Get POPIA-compliant →

Cybersecurity & Testing

Finding out where you're exposed — before someone else does.

What is penetration testing?

A penetration test is an authorised, simulated attack on your systems by security engineers, run to find and prove exploitable weaknesses before criminals do. You get a prioritised report of real, proven gaps — ranked by business impact — plus the fixes and a retest. See penetration testing →

How much does a penetration test cost in South Africa?

For small businesses and clearly-defined scopes, indicative ranges start from around R15,000; larger corporate and specialised (OT/ICS) engagements are scoped on request. Every engagement is a fixed written quote after a short scoping call — no hourly surprises. See pricing and engagements →

What is network penetration testing?

Testing focused on your network — the external perimeter facing the internet, or the internal network — to find exposed services, weak configurations and the paths an attacker could use to move through your systems and reach your data.

What does a cybersecurity consultant do?

Assesses where you're exposed, maps it to real business risk, and helps you close the gaps — from POPIA and testing to incident response — in language leadership can act on, not just technical jargon. See cyber defence & compliance →

Isn't having antivirus enough?

No. Modern attacks arrive through a convincing email, a reused password or an unpatched service that antivirus never sees — and the first you hear of it is a ransom note. An assessment finds those open doors while they're still cheap to close. See a cybersecurity assessment →

How do I know how exposed we are right now?

Take our free, private security posture self-check — it scores your exposure in about a minute across backups, MFA, patching, training, POPIA readiness and testing, then shows exactly where the gaps are.

Test your defences →

Websites & Systems

Building assets you own — not templates you rent.

How much does a website cost in South Africa?

It ranges from a few hundred rand for a DIY builder to R12,000+ for an engineered, fully-owned custom site. The honest question isn't the price — it's whether you're renting a template or owning a business asset. See the honest 2026 pricing guide →

Do I own the website you build?

Completely. At handover you receive the source code, hosting and data — a permanent asset on your side of the table, never rented or held hostage. See our websites →

What is a business system or client portal?

A custom platform built around how your business actually runs — bookings, secure client portals, documents, dashboards and automation — rather than an off-the-shelf tool you have to bend to fit. See our business systems →

Can I see what you build before committing?

Yes — that's exactly what our live demos are for. Click through a working client portal, re-brand a sample site live, and try a WhatsApp assistant, all in your browser.

See what we build →

AI for Business

Real value from AI — safely, with a human where it matters.

Can AI really handle my customer service?

For a large share of everyday queries — bookings, FAQs, order status, first-line support — yes, 24/7, with a clean handover to a real person the moment it matters. Try the live assistant →

What is "AI slop", and should I worry about it?

It's AI-generated code or systems that look finished but hide missing security, exposed data or broken logic. If anything in your business was built with AI and never independently reviewed, it's worth checking before it becomes a breach. See AI oversight & remediation →

Is it safe to build my business tools with AI?

Fast, yes; safe, only with oversight. AI ships exposure as easily as it ships features — the value is in an experienced review before it goes live, not after it leaks. See AI consulting & guardrails →

Get AI oversight →

Didn't find your answer? Ask a real person.

You've read the honest version. The next step is a short conversation with an actual engineer — not a call centre, not a bot — who'll tell you straight what you need and what it takes.