MySentinel

Trust & POPIA

A safety platform that can answer for the data it holds.

South African schools hold deeply sensitive information about minors and their families. MySentinel is built so the school's POPIA officer, IT contact, and governing body can each get a straight answer — encryption, an audit trail, and a working subject-rights console, not a promise.

The responsible party is Binary Solutions, a registered South African company. MySentinel is its product, it is operated from South Africa, and the company details, registration and contact route are on the company site. A POPIA request has a real legal entity to reach.

Encryption at rest

Sensitive data is encrypted before it is stored

Learner and visitor photos are encrypted before they are ever stored, with a key that belongs to your school alone. Another school's key cannot open your images, and neither can anyone who reaches the storage without it. The same protection covers the rest of the sensitive record.

  • Learner and visitor photos are encrypted with a key unique to your school.
  • If the signal drops at the gate, the check-ins waiting to send are locked to that one phone — unreadable to anyone else, including if the phone is lost.
  • Every connection between the officer's phone, your dashboard and MySentinel is encrypted in transit.

Audit trail

Every state change is recorded with who, when, and what

A badge scan, a guardian assignment, an emergency broadcast, a lockdown, a POPIA action — each writes an immutable audit entry naming the actor, the timestamp, and exactly what changed. That record is what settles a dispute between a parent and the school, and what an investigation works from.

  • Actor, timestamp, and the precise change captured for every mutation.
  • Built for both security investigations and parent disputes.
  • Privileged operator actions are logged the same way as school staff actions.

Where your data goes

Your school's data is not copied anywhere else

There is no second copy of your school's information sitting in a reporting warehouse, no advertising trackers, and nothing quietly measuring your school in the background. We hold only what is needed to record a check-in or check-out and to tell guardians — nothing is gathered to be sold, shared, or mined.

  • One system — your data is never copied out for reporting, measurement, or advertising.
  • Every school is walled off from every other: a learner, guardian or visitor at one school is invisible to the next.
  • We collect the minimum the service needs to work, and nothing beyond it.

POPIA console

The subject-rights console your POPIA officer actually uses

The school's designated POPIA officer works from a dedicated console. Subject Access Requests, erasure and retention changes each ask the officer to confirm again on their own device — a fingerprint or face check — before anything runs. The most sensitive actions are tied to a person who is physically there, not merely to a login someone left open.

Subject Access Requests

The school's POPIA officer assembles a Subject Access Request export on demand, packaged for handover — without anyone needing direct database access.

Correction requests

A request to correct a record is logged and tracked through the console, so the school can show it was actioned.

Erasure with a 30-day cool-off

An erasure always enters a mandatory 30-day cool-off before anything is deleted, and can be cancelled during that window. Each data store reports its own progress — completed, still scheduled, or needs attention — so the officer can see exactly where the request stands.

Retention policy

The POPIA officer edits per-school retention windows for movement records, so each school holds data only as long as its own policy allows.

Visitor design

Screen visitors without becoming a database of ID numbers

The visitor register is designed to support a school's own ban and custody lists — the kind of screening a school keeps to manage who comes through the gate — while deliberately never holding a raw identity number. It matches on a one-way fingerprint of the ID's last four digits, so the register can recognise a flagged person without ever holding information that would be dangerous if it escaped.

  • A South African ID number is never stored. The register keeps only a one-way fingerprint of the last four digits — enough to recognise someone your school has flagged, and impossible to turn back into an ID number, even by us.
  • Visitor photos are encrypted before they are persisted, the same way learner photos are.
  • School-local ban and custody lists let a school flag a person who must not be admitted or who may not collect a particular learner — held locally to that school, never shared across schools.
  • Visitor sign-in is officer-mediated, school-scoped, blocked during a lockdown, and written to the audit trail like every other action.

Breach posture

Built so a breach exposes as little as possible

The design assumption is that the safest data is the data you never store in the clear. Photos are encrypted with your school's own key, a visitor's identity is reduced to a fingerprint that cannot be reversed, and each school is sealed off so a problem at one can never reach another's records.

Because every state change is in the audit trail, a school and its POPIA officer can reconstruct exactly what was accessed and when — the record you need to meet a POPIA notification obligation, rather than a guess. As the data controller, the school directs subject-rights and erasure actions through the console; MySentinel, as processor, executes them and records the evidence.

Procurement

Need the POPIA story for your governing body?

We'll walk your POPIA officer and IT contact through how the data is protected, the audit trail, and the subject-rights console on a short call. Email am@binary-solutions.co.za to set it up.

Talk to us

Prefer a quick chat?

Send us a message and we'll line up a walkthrough at a time that suits your school.