Access control
Administrative access is restricted according to role, operational responsibility and business need.
An overview of the practices, controls and operational principles used to protect customer services, systems and information.
Security concerns may be reported to security@hozit.co.za .
Hozit applies a risk-based approach to security, privacy, availability and operational resilience.
Layered technical and organisational safeguards designed to protect systems, accounts and customer information.
Learn more →Responsible handling of personal information aligned with applicable South African data-protection requirements.
Learn more →Backup, retention and restoration controls are applied according to the purchased service and customer requirements.
Learn more →Infrastructure monitoring, escalation and maintenance processes support reliable service delivery.
Learn more →Structured identification, containment, investigation, recovery and communication procedures.
Learn more →A clear channel for security researchers and customers to report suspected vulnerabilities responsibly.
Learn more →Security measures are selected according to the service, infrastructure, customer risk profile and applicable contractual requirements.
View the full Security Policy →Administrative access is restricted according to role, operational responsibility and business need.
Systems are configured using security-conscious defaults, appropriate firewall controls and hardened service settings.
Software and infrastructure updates are prioritised according to risk, severity and compatibility requirements.
Relevant infrastructure may be monitored for availability, abnormal activity, service failures and security events.
Encryption is used for supported services and transmission channels where technically appropriate.
Strong passwords, multi-factor authentication and controlled credential management are encouraged or enforced where available.
Hozit aims to process personal information lawfully, transparently and only for legitimate business and service purposes.
Read the Privacy Policy →Information should be collected and used for defined, legitimate and relevant purposes.
Only information reasonably required for the relevant activity should be processed.
Information should not be kept longer than required for legal, contractual or operational purposes.
Requests relating to access, correction, objection or deletion are handled according to applicable requirements.
Continuity measures are designed to reduce disruption and support structured service recovery.
Identify critical systems, dependencies, risks and recovery priorities.
Apply backups, access controls, monitoring and operational safeguards.
Escalate incidents, contain impact and coordinate technical response activities.
Restore services according to technical feasibility, contractual scope and business priority.
Backup frequency, retention, replication and restoration commitments depend on the purchased hosting or managed backup service. Customers should maintain independent backups of business-critical information.
Availability targets and support commitments are defined by the applicable service package, quotation or managed-service agreement.
Review the Service Level Agreement →Receive alerts, customer reports or observations and assess the potential severity.
Limit further exposure while preserving relevant operational and investigative information.
Determine the affected systems, cause, impact and required corrective action.
Restore services safely, monitor stability and reduce the likelihood of recurrence.
Provide notifications where required by law, contract or the circumstances of the incident.
Access the policies that govern security, privacy, acceptable use, service delivery and customer relationships.
Report suspected vulnerabilities, compromised systems or security concerns through our designated security channel.