Last updated: August 2026
This Information Security Policy describes the controls and practices Biexus ("we", "our", or "us") implements to protect the confidentiality, integrity, and availability of customer data processed through our automation platform. It applies to all Biexus systems, employees, contractors, and sub-processors involved in delivering the service.
All data is protected in transit and at rest:
Access to customer data and infrastructure is governed by the principle of least privilege:
Biexus is hosted on cloud infrastructure providers that maintain recognised security certifications (ISO 27001, SOC 2). Our infrastructure includes:
Each customer's data is logically segregated. Row-level security (RLS) ensures that users and automations can only access data belonging to their own profile or organisation. No customer's automation can read, write, or modify another customer's records.
We maintain an incident response plan to detect, contain, and remediate security incidents. In the event of a confirmed data breach affecting customer data, we will notify affected customers without undue delay and in accordance with applicable legal requirements, including the Protection of Personal Information Act (POPIA).
We engage sub-processors (e.g. cloud hosting, payment processing, email delivery) only under written agreements that impose security obligations equivalent to our own. We assess sub-processor security before engagement and monitor their compliance on an ongoing basis.
We maintain backups of customer configuration and automation data to support recovery in the event of system failure. Recovery time objectives (RTO) and recovery point objectives (RPO) are monitored and tested periodically.
Biexus aligns its information security practices with internationally recognised frameworks and complies with applicable data protection legislation, including the Protection of Personal Information Act (POPIA) and the General Data Protection Regulation (GDPR) where applicable.
This policy is reviewed at least annually and updated as needed to reflect changes in our security practices or applicable regulations. For questions about this policy, please contact us.