Intelligence, fraud detection and cyber defense for South Africa
Dark Pools has offices in Cape Town and Johannesburg and runs security operations from both cities. Gov AI monitors social media in English, Afrikaans, isiZulu, isiXhosa, Sesotho and Setswana, FinCrimes detects fraud and money laundering for institutions that report under the FIC Act, and our SOC provides 24/7 monitoring and incident response. Every deployment can keep data inside South Africa.
What we do in South Africa
- Social media monitoring in local languagesGov AI tracks threats, narratives and sentiment across nine platforms, including WhatsApp and Telegram, in English, Afrikaans, isiZulu, isiXhosa, Sesotho, Setswana and other languages. Automated alerts flag threats and emerging situations as posts come in.
- Fraud detection and AML for FIC Act reportingFinCrimes scores transactions against named typologies such as structuring, mule rings and SIM-swap takeover, then carries each alert through an audited case to a filing-ready report your compliance officer submits to the FIC.
- Insurance claims fraudStaged-accident rings, ghost policies and provider collusion look clean one claim at a time. Entity resolution links the vehicles, providers and parties that recur across claims, so SIU teams see the whole ring before payout.
- SOC as a service from South AfricaOur Cape Town and Johannesburg operations centers provide 24/7 monitoring, triage and incident response, co-managed with your team or fully managed, with SIEM engineering and threat hunting mapped to MITRE ATT&CK.
The rules your program answers to
A plain summary for orientation, not legal advice. Your own counsel and compliance function decide how each applies.
- POPIA (Protection of Personal Information Act, 2013)
- Sets the conditions for lawful processing of personal information, enforced by the Information Regulator, with extra limits on special personal information such as criminal behavior and biometrics, and on transfers outside South Africa. It governs what a monitoring or fraud platform may collect, how long records are kept and where they are hosted.
- FIC Act (Financial Intelligence Centre Act, 2001)
- Requires accountable institutions, including banks and long-term insurers, to verify customers, keep records, run a risk management and compliance program, and report suspicious and unusual transactions to the Financial Intelligence Centre. Reports are submitted through the Centre’s goAML system.
- Cybercrimes Act (2020)
- Defines offenses such as unlawful access, interception of data and cyber fraud, sets out how evidence is searched for and preserved, and places reporting duties on electronic communications service providers and financial institutions. It also criminalizes data messages that incite violence or damage to property, which bears on what agencies watch for online.
- RICA (Regulation of Interception of Communications and Provision of Communication-Related Information Act, 2002)
- Prohibits interception of communications without a direction from a designated judge and requires SIM cards to be registered to their users. It draws the line between monitoring open sources and intercepting private communications, a boundary every collection plan in South Africa has to respect.
Your data stays where it must
- On-premises in your own facilities, including air-gapped networks with no outside connection.
- Hosting in South African data centers or a government cloud, so personal information stays in the country.
- Hybrid deployments that keep sensitive records on-premises and synchronize only selected data to the cloud.
- Tenant isolation for every agency or institution, hard-walled Banking and Insurance workspaces, and a PII token vault that tokenizes sensitive identifiers and logs every detokenization.
Countries and languages
Languages
- English
- Afrikaans
- isiZulu
- isiXhosa
- Sesotho
- Setswana
Scenarios in this region
Regional questions
Dark Pools has offices in Cape Town and Johannesburg. Security operations run from both cities, and our Mbabane office in Eswatini supports clients across the wider region.
Yes. The platform can run on-premises in your own facilities, in South African data centers, in a government cloud or as a hybrid. You choose where data resides when the deployment is planned, and each tenant is isolated from every other.
FinCrimes builds filing-ready reports from case evidence, including the transactions, parties and reasons behind each alert. Submission through goAML stays with your compliance officer, who reviews each report before it is filed.
Monitoring covers English, Afrikaans, isiZulu, isiXhosa, Sesotho and Setswana, along with other African languages used across the region. Narratives that circulate only in a local language are still picked up and translated for analysts.
Role-based access, multi-factor authentication, encryption, a PII token vault with retention policies and a tamper-evident audit trail give you the technical controls to apply POPIA’s security safeguards and retention limits. Accountability for lawful processing stays with your organization, and our vCISO advisory team can help with POPIA readiness.
Take the next step
Talk to the team serving South Africa. We will work within your data-residency and regulatory requirements from the first conversation.