CH-ISE Secure — security & POPIA audits

Your AI-built website works. But who else can reach your data?

Sites built fast with Lovable, Bolt, v0, Cursor or no-code tools ship with exposed keys, open databases and missing POPIA notices. CH-ISE Secure finds the gaps before someone else does.

Plain-English report. Delivered in days. Free re-audit after you fix things.

The blind spot

You built your site fast with AI. It works. But nobody checked who else can reach your data.

AI builders and no-code tools are brilliant at shipping something that looks finished. What they don't do is lock the doors. If you're an SMB owner or an agency handing client sites over, the live, customer-facing parts often go out the door without anyone confirming the database is private, the keys are hidden, or your data handling is even legal. It looks done. That's exactly the problem.

What's at stake

Under POPIA, this can land on you, personally.

A leaked customer database isn't just a bad day — it's a legal exposure that follows the people running the business. South Africa's Information Regulator has real teeth, and it has already used them.

Up to 10 years

imprisonment

For the most serious POPIA contraventions, the penalty can include imprisonment of up to 10 years.

Up to R10 million

in fines

POPIA allows administrative fines of up to R10 million — and a director can be held personally liable.

R5 million

already imposed

The Information Regulator has already fined an organisation R5 million. This is not hypothetical.

The fix

The CH-ISE Secure audit.

A focused review of your live site and its backend — combining automated scans with hands-on expert checks. We tell you exactly what's wrong, in plain English, and what to do about it. Delivered in days, not weeks.

Exposed secrets

API keys, passwords and tokens left visible in your site’s code or config.

Database access & RLS

Whether your database (e.g. Supabase) stops strangers reading other users’ data.

Authentication

How logins, sessions and access controls are set up — and where they leak.

Privacy policy & POPIA notice

Whether your data handling is disclosed and compliant with POPIA.

Security configuration

Headers, permissions and platform settings that quietly leave you exposed.

Free re-audit after you fix

A free secondary re-audit once you’ve actioned the report — so you can prove you acted.

Start with a free 60-second check.

Answer eight plain-language questions and get an instant traffic-light read on where you stand. It's an indicator, not a full audit — but it's a fast, honest place to start.

VibeCheck

A free 60-second security & POPIA self-check from CH-ISE Secure

Question 1 of 80% complete
Was your website built with an AI tool (Lovable, Bolt, v0, Cursor, Replit) or a no-code builder?
Choose your level

Three ways to get covered.

From a quick automated scan to deep compliance readiness. Indicative starting prices — final scope is confirmed on your call.

Essential Scan

An automated scan of your live site for the most common, high-risk gaps.

from R4,500

  • Automated exposed-secret scan
  • Basic database access check
  • Privacy policy & POPIA notice check
  • Plain-English summary report
Start with the free check
Most popular

Pro Audit

Automated scans plus hands-on expert review of your site and backend.

from R15,000

  • Everything in Essential Scan
  • Manual review of database access & RLS
  • Authentication & access-control review
  • Security configuration review
  • Prioritised, plain-English findings report
  • Free re-audit after you fix things
Book a Pro Audit

Compliance+

For teams that need to demonstrate maturity to customers and partners.

from R35,000

  • Everything in Pro Audit
  • ISO 27001 / SOC 2 readiness assessment
  • Deeper penetration test via our specialist cybersecurity partners
  • Remediation roadmap & guidance
Talk to us about Compliance+

Straight talk, because trust matters.

Automated scans + expert review

We pair automated tooling with a hands-on review by a person. The two together catch far more than either alone.

Not a runtime penetration test

The core audit is an assessment, not a live attack on your systems. Deeper penetration testing is escalated via our specialist cybersecurity partners.

Reduces — does not eliminate — risk

No audit can promise perfect safety. Ours meaningfully reduces your legal and security risk; it does not eliminate it.

We practise what we preach

CH-ISE is itself POPIA-registered with an appointed Information Officer. We hold our own house to the same standard.

Get covered

Find the gaps before
someone else does.

Run the free 60-second check now, or book a full CH-ISE Secure audit and get a plain-English report in days.