Security & Compliance
Last updated: 3 September 2026
How we run things
eHawu Security is a trading name of Olorun Cloud. We build and operate the same infrastructure we sell, which means our security claims are things we hold ourselves to daily, not marketing copy. Our platforms host client workloads on African soil, and that sovereignty is a design constraint, not an afterthought.
Frameworks we align to
Our control set maps to three frameworks:
- POPIA (Protection of Personal Information Act 4 of 2013). We are registered with the Information Regulator, an information officer is appointed, and personal data handling follows the seven processing conditions. Our PAIA Manual explains your access rights.
- ISO/IEC 27001:2022. Our ISMS follows the Annex A controls: access control, cryptography, incident management, supplier security and continuous monitoring. Certification is on our roadmap; the control practices are already live.
- CIS Benchmarks. Servers are hardened against the relevant CIS level 1 profile, patched on a monthly cycle, and critical CVEs within 72 hours.
Encryption
All traffic between you and our services runs over TLS 1.3. Data at rest is encrypted with AES-256. VPN clients use modern cipher suites with perfect forward secrecy, and we rotate keys on a documented schedule. Card payments never touch our servers; they are handled end-to-end by PayFast (Network International), a PCI DSS Level 1 acquirer.
Access and monitoring
Administrative access follows least privilege. Production systems sit behind zero-trust gateways: no management port is exposed to the public internet, and every session is authenticated, logged and attributable to a named engineer. We run our own managed SOC, so log review and alert triage happen continuously rather than quarterly.
Incident response
Our target is a 15-minute average response to a confirmed security incident. If a breach affects your personal information, we notify you and the Information Regulator as section 22 of POPIA requires. We don’t wait for a regulator to tell us to do that.
Responsible disclosure
Found a weakness in something we run? Email support@ehawu.africa. We’ll acknowledge within one business day, and we won’t pursue legal action against good-faith research reported this way. Give us a reasonable window to fix it before going public, and we’ll do our part fast.
Audit requests
Enterprise clients can request our security documentation, penetration test summaries and sub-processor list under NDA. Ask through your account manager or the contact page.