MySentinel Talk to us

Trust & POPIA

A safety platform that can answer for the data it holds.

South African schools hold deeply sensitive information about minors and their families. MySentinel is built so the school's POPIA officer, IT contact, and governing body can each get a straight answer — encryption, an audit trail, and a working subject-rights console, not a promise.

Encryption at rest

Sensitive data is encrypted before it is stored

Learner and visitor photos are encrypted with a per-school AES-GCM key before they ever reach storage, so one school's images can never be read with another school's key. The same posture covers the rest of the sensitive record set.

  • Per-school AES-GCM encryption for learner and visitor photos.
  • Device-bound offline pack — when an officer works through a connectivity drop, the queued check-in / check-out data is sealed to that device, not left in the clear.
  • TLS in flight on every request between the officer's phone, the admin dashboard, and the platform.

Audit trail

Every state change is recorded with who, when, and what

A badge scan, a guardian assignment, an emergency broadcast, a lockdown, a POPIA action — each writes an immutable audit entry naming the actor, the timestamp, and exactly what changed. That record is what settles a dispute between a parent and the school, and what an investigation works from.

  • Actor, timestamp, and the precise change captured for every mutation.
  • Built for both security investigations and parent disputes.
  • Privileged operator actions are logged the same way as school staff actions.

Data residency

Your school's data stays on Cloudflare

MySentinel runs entirely on Cloudflare — Workers, D1, R2, Queues, and Durable Objects. There is no separate reporting warehouse, no third-party advertising pixel, and no background telemetry. We collect only what is needed to record check-ins and check-outs and to notify guardians.

  • Single Cloudflare platform — no off-platform data copies for reporting or ads.
  • Strict multi-tenant isolation: a learner, guardian, or visitor from School A is invisible to School B.
  • Data minimisation by design — no tracking we do not need to run the service.

POPIA console

The subject-rights console your POPIA officer actually uses

The school's designated POPIA officer works from a dedicated console. Subject Access Requests, erasure, and retention edits each require a WebAuthn passkey step-up before the change runs — so the most sensitive actions are tied to a verified person, not just a logged-in session.

Subject Access Requests

The school's POPIA officer assembles a Subject Access Request export on demand, packaged for handover — without anyone needing direct database access.

Correction requests

A request to correct a record is logged and tracked through the console, so the school can show it was actioned.

Erasure with a 30-day cool-off

An erasure always enters a mandatory 30-day cool-off before anything is deleted, and can be cancelled during that window. Each data store reports its own progress — completed, still scheduled, or needs attention — so the officer can see exactly where the request stands.

Retention policy

The POPIA officer edits per-school retention windows for movement records, so each school holds data only as long as its own policy allows.

Visitor design

Screen visitors without becoming a database of ID numbers

The visitor register is designed to support a school's own ban and custody lists — the kind of screening a school keeps to manage who comes through the gate — while deliberately never holding a raw identity number. It matches on a one-way HMAC of the ID's last four digits, so the register can recognise a flagged person without ever storing data that would be dangerous in a breach.

  • No raw South African ID number is ever stored — the register keeps only an HMAC of the ID's last four digits, enough to match against a school-local list but useless to anyone who obtains the database.
  • Visitor photos are encrypted before they are persisted, the same way learner photos are.
  • School-local ban and custody lists let a school flag a person who must not be admitted or who may not collect a particular learner — held locally to that school, never shared across schools.
  • Visitor sign-in is officer-mediated, school-scoped, blocked during a lockdown, and written to the audit trail like every other action.

Breach posture

Built so a breach exposes as little as possible

The design assumption is that the safest data is the data you never store in the clear. Photos are encrypted per school, visitor identity is reduced to a one-way HMAC, and tenants are isolated so a single compromised school can never reach another school's records.

Because every state change is in the audit trail, a school and its POPIA officer can reconstruct exactly what was accessed and when — the record you need to meet a POPIA notification obligation, rather than a guess. As the data controller, the school directs subject-rights and erasure actions through the console; MySentinel, as processor, executes them and records the evidence.

Procurement

Need the POPIA story for your governing body?

We'll walk your POPIA officer and IT contact through encryption, the audit trail, and the subject-rights console on a short call. Email am@binary-solutions.co.za to set it up.

Talk to us

Prefer a quick chat?

Send us a message and we'll line up a walkthrough at a time that suits your school.