LockLayerCyber
SECURITY AT LOCKLAYER

Your GRC data deserves serious protection.

LockLayer ONE is being built with security and privacy at the foundation, helping organisations manage sensitive governance, risk and compliance information within a secure and controlled environment.

Authentication
Tenant Isolation
Data Protection
Access Control
Auditability
SECURITY BY DESIGN

Protection built into the foundation

Security isn't an add-on to LockLayer ONE. The platform is being designed around principles that help protect organisational information and maintain clear boundaries between customer environments.

SECURE AUTHENTICATION

LockLayer ONE uses secure authentication mechanisms to control access to the platform and help ensure that only authorised users can sign in.

TENANT ISOLATION

Organisation data is logically separated using tenant-based architecture so customer environments remain isolated from one another.

ACCESS CONTROL

The platform is being designed to support controlled access to GRC information so users can access the information appropriate to their responsibilities.

SECURE APPLICATION ARCHITECTURE

Security considerations are incorporated into the application's architecture, data access patterns and development practices.

DATA PROTECTION

Protecting the information behind your GRC programme

GRC platforms can contain highly sensitive information about organisational risks, incidents, controls, suppliers and audit findings. LockLayer ONE is being designed with this sensitivity in mind.

DATA SEPARATION

Customer information is associated with the appropriate organisation context to maintain tenant boundaries.

CONTROLLED DATA ACCESS

Application data access is designed around authenticated and organisation-scoped requests.

SECURE DEVELOPMENT

Security will continue to be reviewed as the platform evolves, including application dependencies, access patterns and security testing.

USER
SECURE AUTHENTICATION
LOCKLAYER ONE
TENANT-SCOPED ACCESS
ORGANISATION DATA
PRIVACY

Privacy matters by design.

As a South African technology company, LockLayer Cyber recognises the importance of responsible personal information management and the principles established by the Protection of Personal Information Act (POPIA).

LockLayer ONE is being developed with privacy-conscious data handling and responsible information management in mind.

PURPOSEFUL DATA HANDLING

Collect and process information in ways that support legitimate platform and GRC activities.

ACCESS & ACCOUNTABILITY

Maintain appropriate controls around who can access organisational information.

DATA MINIMISATION

Avoid collecting unnecessary information where it is not required for the operation of the platform.

SECURITY & COMPLIANCE ROADMAP

Building toward recognised security practices

LockLayer Cyber's security programme will continue to mature alongside the LockLayer ONE platform, with recognised security and governance practices informing our roadmap.

FRAMEWORKS & PRACTICES INFORMING OUR ROADMAP
ISO/IEC 27001
NIST Cybersecurity Framework
SOC 2
POPIA

Security grows with the platform.

LockLayer ONE is an early-stage platform. As we continue development, our security controls, testing processes, documentation and assurance programme will mature with it.

We believe organisations evaluating GRC technology should receive clear information about how their data is handled and protected — without exaggerated security claims.

SECURITY ROADMAP

Security capabilities will continue to evolve as the platform moves toward production readiness.

CONTINUOUS IMPROVEMENT

Application security will be reviewed as features, infrastructure and integrations are introduced.

TRANSPARENCY

We aim to communicate our security posture clearly and distinguish implemented controls from planned capabilities.

Security questions

How is customer data separated in LockLayer ONE?
LockLayer ONE uses organisation-based tenant scoping so application data is associated with and accessed within the appropriate organisational context.
How do users access LockLayer ONE?
Access to the platform requires authenticated user accounts. Additional access-control capabilities will continue to evolve as the product develops.
Is LockLayer Cyber ISO 27001 certified?
Not currently. ISO/IEC 27001 is among the recognised security practices informing our security roadmap, but LockLayer Cyber does not currently claim ISO/IEC 27001 certification.
Is LockLayer ONE SOC 2 certified?
Not currently. Formal assurance activities will be considered as the platform and company mature.
How does LockLayer approach POPIA?
LockLayer Cyber is developing LockLayer ONE with privacy-conscious information handling and South African data protection requirements in mind. Formal legal and compliance assessments will form part of the company's maturity journey.

Have a security question?

Security and trust matter when choosing a GRC platform. Talk to us about LockLayer ONE, our security approach and the platform roadmap.