Security

Built for the regulated world.

Huka handles client data, financial records, and municipal submission history. We take that responsibility seriously.

South African data residency

All tenant data — projects, documents, financials — is stored in South African cloud regions. Nothing leaves the country by default.

POPIA compliance

We operate under the Protection of Personal Information Act. A Data Processing Agreement (DPA) is available on request for any tier.

Encryption at rest and in transit

Data is encrypted at rest with AES-256 and in transit over TLS 1.3. Supabase-managed database encryption is enabled for all tenants.

Role-based access control

Three roles — admin, planner, and viewer — scope every action. The MCP server is read-only by default; write actions require explicit opt-in.

Audit log retention

Every data change is recorded. Studio retains 90 days, Practice 2 years, Enterprise is configurable. Logs are exportable on request.

Annual penetration testing

An independent third-party security assessment is conducted annually. Findings are remediated before the next release cycle.

By plan

Security features per tier.

Feature
Studio
Practice
Enterprise
Audit log retention
90 days
2 years
Custom
Data Processing Agreement
On request
On request
Included
SSO / SAML
Add-on
Included
Dedicated tenant database
Annual pen-test report
Summary
Full report
Full report

Need a Data Processing Agreement?

We sign a DPA on request for all tiers. Contact us and we'll send it within one business day.

Request our DPA