Information Security Policy

Last updated: August 2026

1. Purpose and Scope

This Information Security Policy describes the controls and practices Biexus ("we", "our", or "us") implements to protect the confidentiality, integrity, and availability of customer data processed through our automation platform. It applies to all Biexus systems, employees, contractors, and sub-processors involved in delivering the service.

2. Data Encryption

All data is protected in transit and at rest:

  • All network traffic is encrypted using TLS 1.2 or higher
  • Integration credentials and OAuth tokens are encrypted at rest using industry-standard encryption
  • Database backups are encrypted before transfer to secure storage

3. Access Control

Access to customer data and infrastructure is governed by the principle of least privilege:

  • Role-based access control (RBAC) limits administrative access to authorised personnel only
  • Multi-factor authentication (MFA) is enforced for all internal systems and infrastructure
  • Access rights are reviewed quarterly and revoked immediately upon role change or termination
  • Customer integration credentials are never accessed except to execute your configured automations

4. Infrastructure Security

Biexus is hosted on cloud infrastructure providers that maintain recognised security certifications (ISO 27001, SOC 2). Our infrastructure includes:

  • Network firewalls and intrusion detection systems
  • Automated security patching for all production systems
  • Regular vulnerability scanning and penetration testing
  • Segregation of production, staging, and development environments

5. Data Segregation and Isolation

Each customer's data is logically segregated. Row-level security (RLS) ensures that users and automations can only access data belonging to their own profile or organisation. No customer's automation can read, write, or modify another customer's records.

6. Incident Response

We maintain an incident response plan to detect, contain, and remediate security incidents. In the event of a confirmed data breach affecting customer data, we will notify affected customers without undue delay and in accordance with applicable legal requirements, including the Protection of Personal Information Act (POPIA).

7. Sub-Processor Management

We engage sub-processors (e.g. cloud hosting, payment processing, email delivery) only under written agreements that impose security obligations equivalent to our own. We assess sub-processor security before engagement and monitor their compliance on an ongoing basis.

8. Business Continuity

We maintain backups of customer configuration and automation data to support recovery in the event of system failure. Recovery time objectives (RTO) and recovery point objectives (RPO) are monitored and tested periodically.

9. Compliance

Biexus aligns its information security practices with internationally recognised frameworks and complies with applicable data protection legislation, including the Protection of Personal Information Act (POPIA) and the General Data Protection Regulation (GDPR) where applicable.

10. Policy Review

This policy is reviewed at least annually and updated as needed to reflect changes in our security practices or applicable regulations. For questions about this policy, please contact us.