Due diligence
Frequently asked questions
Is this a compliance certification?
No. The trust centre explains Fatti’s service model and assurance approach. POPIA and GDPR responsibilities depend on the processing purpose, roles, location, agreement and deployment. A client review should assess that specific context.
Does every Fatti deployment use the same controls?
No. Services can differ in component placement, customer-owned equipment, connectivity, high availability, portal configuration and reporting. Fatti confirms the relevant architecture and responsibilities for each engagement.
Is the location analytics data anonymous?
Fatti does not make a blanket anonymity claim. Device-linked observations and movement histories can be personal or pseudonymous. Aggregation and reporting must be assessed in context.
Are recovery times the same for all incidents?
No. Software restoration, central-service recovery and physical equipment replacement have different dependencies. Client responses should state the scenario, assumptions and contractual scope.
Can Fatti complete our security or privacy questionnaire?
Yes. Send the questionnaire to your Fatti contact with the service and venue scope, requested deadline and any required evidence format. Responses are prepared from Fatti’s controlled internal documentation and reviewed for the applicable engagement.
Security, privacy and technical questionnaires can be sent to sj@fatti.co.za and jaco@fatti.co.za.
Can we receive detailed evidence?
Approved evidence may be provided through an appropriate confidential review where it is relevant and safe to disclose. Internal vulnerabilities, detailed topology, credentials, personal information and unrelated client records are not public trust-centre content.
How current is this site?
The footer shows the latest content review date. Material changes are prepared in Fatti’s private master documentation and published through a reviewed pull request to the protected public repository.