Skip to main content
South Africa

Intelligence, fraud detection and cyber defense for South Africa

Dark Pools has offices in Cape Town and Johannesburg and runs security operations from both cities. Gov AI monitors social media in English, Afrikaans, isiZulu, isiXhosa, Sesotho and Setswana, FinCrimes detects fraud and money laundering for institutions that report under the FIC Act, and our SOC provides 24/7 monitoring and incident response. Every deployment can keep data inside South Africa.

Regulatory context
Cape TownJohannesburgMbabaneDurbanGqeberhaBloemfontein
Priorities

What we do in South Africa

Regulatory context

The rules your program answers to

A plain summary for orientation, not legal advice. Your own counsel and compliance function decide how each applies.

POPIA (Protection of Personal Information Act, 2013)
Sets the conditions for lawful processing of personal information, enforced by the Information Regulator, with extra limits on special personal information such as criminal behavior and biometrics, and on transfers outside South Africa. It governs what a monitoring or fraud platform may collect, how long records are kept and where they are hosted.
FIC Act (Financial Intelligence Centre Act, 2001)
Requires accountable institutions, including banks and long-term insurers, to verify customers, keep records, run a risk management and compliance program, and report suspicious and unusual transactions to the Financial Intelligence Centre. Reports are submitted through the Centre’s goAML system.
Cybercrimes Act (2020)
Defines offenses such as unlawful access, interception of data and cyber fraud, sets out how evidence is searched for and preserved, and places reporting duties on electronic communications service providers and financial institutions. It also criminalizes data messages that incite violence or damage to property, which bears on what agencies watch for online.
RICA (Regulation of Interception of Communications and Provision of Communication-Related Information Act, 2002)
Prohibits interception of communications without a direction from a designated judge and requires SIM cards to be registered to their users. It draws the line between monitoring open sources and intercepting private communications, a boundary every collection plan in South Africa has to respect.
Deployment & data residency

Your data stays where it must

  • On-premises in your own facilities, including air-gapped networks with no outside connection.
  • Hosting in South African data centers or a government cloud, so personal information stays in the country.
  • Hybrid deployments that keep sensitive records on-premises and synchronize only selected data to the cloud.
  • Tenant isolation for every agency or institution, hard-walled Banking and Insurance workspaces, and a PII token vault that tokenizes sensitive identifiers and logs every detokenization.
Coverage

Countries and languages

Languages

  • English
  • Afrikaans
  • isiZulu
  • isiXhosa
  • Sesotho
  • Setswana
In the field

Scenarios in this region

FAQ

Regional questions

Get started

Take the next step

Talk to the team serving South Africa. We will work within your data-residency and regulatory requirements from the first conversation.

Trust & security