Security, Compliance & Trust
AzaniaSCM is built for organisations that handle public money and sensitive procurement data. Security and compliance aren't features we bolt on — they're the foundation every module is built on.
Why This Matters
South African procurement is under unprecedented scrutiny. The Auditor-General issues findings every year on missing documentation, unsigned records, and unverifiable processes. POPIA enforcement is tightening. The Public Procurement Act introduces new transparency and compliance obligations. Organisations that can't demonstrate proper controls face qualified audits, consequence management, and reputational damage.
AzaniaSCM was designed from the ground up to make compliance automatic, not aspirational. Every action on the platform is recorded, every rule is enforced, and every record is tamper-proof. This isn't about ticking boxes — it's about giving you the confidence that your procurement process can withstand any scrutiny.
POPIA Safeguards
The Protection of Personal Information Act requires organisations to implement appropriate technical and organisational measures to protect personal data. AzaniaSCM meets these requirements through multiple layers of protection:
Encryption at Rest
All data stored on AzaniaSCM — supplier documents, bid submissions, evaluation scores, contract details — is encrypted using AES-256, the same standard used by banks and government agencies. If someone gained unauthorised access to the database, the data would be unreadable without the encryption keys.
Encryption in Transit
Every connection to AzaniaSCM is encrypted using TLS 1.3 — the protocol that puts the "S" in HTTPS. Whether you're uploading a bid from your office or reviewing evaluations from home, the data is protected as it travels between your device and our servers.
Tenant Isolation
Each organisation's data is logically isolated. Your procurement data is never mixed with another tenant's data. A municipality in Gauteng cannot see a department's data in KwaZulu-Natal, and vice versa. This isolation is enforced at the database level, not just the application layer.
Role-Based Access Control
Not everyone should see everything. AzaniaSCM lets you define roles with granular permissions — who can create tenders, who can score bids, who can approve contracts, who can view financial data. A procurement clerk sees different information than a CFO. This is enforced, not optional.
Immutable Audit Logs
Every action on the platform — who did what, when, from where — is recorded in an immutable log. These records cannot be edited, backdated, or deleted. They are the evidence chain that proves your process was followed, and they are available to auditors at any time.
Data Retention & Minimisation
POPIA requires that personal information not be kept longer than necessary. AzaniaSCM supports configurable data retention policies — you define how long different categories of data are kept, and the system handles disposal automatically. You collect what you need, keep it for as long as required, and nothing more.
The Audit Vault & Evidence Chain
The concept is simple: every procurement action on AzaniaSCM — from the first demand through to the final payment — creates a permanent, time-stamped record. These records are linked together into an unbroken chain that tells the complete story of every procurement transaction.
Think of it as a flight recorder for your procurement process. If the Auditor-General asks "why was this supplier awarded the contract?", you don't need to reconstruct the process from emails and paper files. The answer is in the Audit Vault — with the original bid scores, the evaluation committee's conflict-of-interest declarations, the scoring justifications, and the award approval, all linked together and cryptographically sealed.
This isn't just about surviving audits. It's about running a procurement process that you can stand behind — one where every decision has a documented rationale, every action has a timestamp, and every record is tamper-proof.
Compliance by Design
AzaniaSCM doesn't just help you comply with regulations — it encodes the regulations into how the platform works. Here's what that means for the key frameworks governing South African procurement:
Preferential Procurement Policy Framework Act (PPPFA)
The PPPFA requires fair, equitable, transparent, competitive, and cost-effective procurement. AzaniaSCM enforces this by:
- Structuring evaluations against predefined, documented criteria — not ad hoc scoring
- Requiring conflict-of-interest declarations before scoring begins
- Locking evaluations once submitted — preventing retroactive changes
- Recording the complete evaluation audit trail for every bid
- Applying threshold-based procurement methods automatically
Broad-Based Black Economic Empowerment (B-BBEE)
B-BBEE verification is a reality for South African procurement. AzaniaSCM supports this by:
- Verifying B-BBEE certificates as part of the Supplier Passport — not just accepting uploaded documents
- Applying B-BBEE scoring points in evaluations where required by the PPPFA
- Flagging expired or mismatched B-BBEE documents before they can be used in tenders
- Maintaining a verified record of supplier B-BBEE status for audit purposes
Public Procurement Act
The Public Procurement Act introduces new requirements for transparency, disclosure, and competitive procurement. AzaniaSCM is built to meet these obligations:
- Transparency Portal for publishing awards, contracts, and performance data
- Full advertising audit trail showing where tenders were published
- Competitive procurement enforced through the rules engine — thresholds and methods are applied automatically
- Open data capability for the disclosure requirements the Act mandates
Public Finance Management Act (PFMA) & Municipal Finance Management Act (MFMA)
The PFMA and MFMA require documented contract management and financial controls. AzaniaSCM delivers this through:
- Three-way matching of purchase orders, goods receipts, and invoices — a fundamental internal control
- Contract milestone tracking with alerts for approaching deadlines and underperformance
- Complete evidence chain from procurement through to payment and contract close-out
- Audit Vault structured to align with Auditor-General reporting requirements
What This Means for You
Whether you're a compliance officer preparing for the Auditor-General, a procurement manager building your team's processes, or a CFO who needs to sleep at night knowing the organisation's procurement is defensible — AzaniaSCM gives you the evidence chain that proves compliance, not just claims it.
You don't need to be a technical expert to trust the platform. The security is built in, the compliance is enforced, and the audit trail is automatic. Your job is to run good procurement. Our job is to make sure the evidence is always there.