Welcome to BestDealz International Track your order Help Center Become a supplier
  1. Home
  2. Trust Center

BestDealz Trust Center

Live system status, compliance certifications, security practices and transparent incident history — everything you need to trust BestDealz with your data, your orders and your business.

All systems operational · 99.96% uptime (last 90 days)
99.96%
Platform uptime · 90 days
0
Data breaches · ever
< 2 hrs
Incident response SLA
5
Incidents · last 12 mo

90-day uptime

Each bar = one day. Hover for details.

Operational Degraded Outage

Storefront & checkout

90 days ago Today

Service status

All systems checked every 60 seconds from 3 SA edge nodes.

Last refresh: 21:56 SAST

Storefront (bestdealz.co.za)

Ok
Uptime 99.97% · Latency 180 ms

Checkout & payments

Ok
Uptime 99.99% · Latency 210 ms

Supplier portal

Ok
Uptime 99.95% · Latency 240 ms

RFQ + quotation API

Ok
Uptime 99.92% · Latency 320 ms

Search + product API

Ok
Uptime 99.96% · Latency 95 ms

Email & SMS notifications

Ok
Uptime 99.91% · Latency OK

Image CDN (S3)

Ok
Uptime 99.99% · Latency 40 ms

Trade Assurance escrow

Ok
Uptime 99.98% · Latency OK

Compliance & security

Audited annually by third parties. All certificates available on request to enterprise customers.

POPIA compliant

Certified · 2026

Full POPIA compliance under SA Protection of Personal Information Act. Data residency in SA (AWS Cape Town). Information Officer registered with the SA Information Regulator.

PCI-DSS Level 1

Self-attested via PSP

Card payments tokenised by PayFast / Yoco / Stripe. BestDealz never sees or stores full card numbers. Quarterly ASV scans.

ISO 27001 aligned

Targeting cert mid-2026

Information security management system in place. Annual penetration testing by independent SA firm. Working towards full ISO 27001 cert.

CPA compliant

Year-round

Consumer Protection Act compliant — clear pricing, 14-day returns where applicable, transparent dispute resolution. CPA-aligned terms & conditions.

CIPC & SARS registered

Verified

BestDealz International (Pty) Ltd — CIPC company registration current. SARS VAT registered. SARS import / customs registration code active.

SARS Customs Code

Active importer

Registered SARS importer + clearing agent partnership. All Class B Direct Import shipments cleared by BestDealz or our nominated SARS-licensed broker.

ITAC + ECTA aware

Year-round

Pre-shipment anti-dumping screening via ITAC list. Electronic Communications & Transactions Act compliant — opt-in marketing only.

NRCS / SAHPRA aware

Per-category

Where products require Letter of Authority (NRCS) or device registration (SAHPRA), BestDealz pre-vets supplier documentation as part of Class B onboarding.

Security practices

Our defence-in-depth approach across infrastructure, application and people.

Infrastructure

  • AWS Cape Town region (SA data residency)
  • VPC isolation + private subnets
  • WAF + CloudFront DDoS shielding
  • Daily encrypted backups (35-day retention)
  • Multi-AZ database failover
  • TLS 1.3 only · HSTS preloaded

Application security

  • CSRF tokens on every form
  • Parameterised SQL queries only
  • Argon2id password hashing
  • Session rotation on privilege change
  • Rate limiting on auth + sensitive endpoints
  • Content Security Policy (CSP) headers

Access control

  • Role-based access (buyer/supplier/admin)
  • 2FA mandatory for all admin accounts
  • SSO via Google Workspace for staff
  • Quarterly access review
  • Audit log on all admin actions
  • Zero-trust internal networking

Testing & assurance

  • Annual penetration test (SA firm)
  • Quarterly vulnerability scans
  • Continuous Dependabot + npm audit
  • Code review on every PR
  • Security incident playbook (24/7 oncall)
  • Bug bounty programme (private)

Incident history

Last 12 months of incidents that affected customers. We don't hide them.

Subscribe to status →
12 Apr 2026
Search latency briefly degraded (resolved 14:32 SAST) Elasticsearch node failover triggered re-indexing. Search query latency spiked to ~800ms for 22 minutes before automatic recovery. Root cause: AWS routine maintenance.
resolved
03 Mar 2026
Payment provider intermittent timeouts (PayFast) PayFast experienced an upstream outage with one of their card acquirers. ~3% of card transactions failed during a 38-minute window. Affected customers were automatically re-attempted; no chargebacks resulted.
resolved
21 Feb 2026
Image CDN slow in Europe AWS S3 Cape Town region experienced increased latency to European edge POPs. SA traffic unaffected. Resolved within 1 hour.
minor
08 Jan 2026
Supplier portal login degraded Session sticky-routing issue caused some suppliers to be logged out repeatedly. Affected ~40 users. Hotfix deployed and post-mortem published internally.
resolved
14 Dec 2025
Newsletter delivery delays AWS SES rate-limit hit during the Black Friday subscriber surge. Newsletters delivered with a 2-hour delay. SES quota permanently raised post-incident.
resolved

Your data rights

Under POPIA you have the right to access, correct, delete and object. Here's how.

📥 Export

Download every record we hold on you, as JSON or CSV.

Export my data →

✏️ Correct

Update inaccurate information from your dashboard, anytime.

Open dashboard →

🗑️ Delete

Request account closure and erasure (subject to legal retention).

Request deletion →

🛑 Object

Opt out of marketing or non-essential processing.

Submit objection →
Information Officer · [email protected] · SA Information Regulator: inforegulator.org.za

Found a security issue?

We run a private bug bounty programme. Email [email protected] with PGP encryption (key on request). We acknowledge within 24 hours and pay verified critical findings within 14 days. We commit to never legally pursuing good-faith researchers.

Trust, then verify

Need a SOC 2 letter, our pen-test attestation or compliance documentation for your procurement team? We hand these out free to verified business customers.

Forgot password?
No account? Create one free