Skip to main content

Public Compliance Resource

Audit Request Templates and Process Overview

How Dootsa handles regulator, election-body, enterprise, and external code audit requests without exposing unnecessary operational detail.

Election body intake template

Submit the following to your Dootsa compliance contact:

  • Requester name, organisation, and verified email
  • Legal basis (statute, contract, or regulatory authority)
  • Jurisdiction (e.g. ZA)
  • Request type: election_body, regulator, code_auditor, or enterprise
  • Purpose and specific review objective
  • Requested artifact types (see evidence pack below)
  • Review time window for log extracts
  • Access tier: Tier 1 evidence bundle (default) or Tier 2 read-only repo (dual approval required)
Stats SA / national statistics intake

Use regulatory body code stats_sa on audit requests. Same intake fields as election-body reviews, plus confirmation that the scope is collection / verification (not electronic voting) and that household doorstep biometrics are out of scope unless separately scheduled.

  • Request artifact: national_stats_governance_summary (SS-01–SS-12)
  • Optional: election_governance_summary when civic/IEC-adjacent
  • Partner APIs: field-worker verify + collection confirmation (DC-…)
  • Public household verify: /verify-fieldworker
External code auditor ROE (summary)

Tier 1 (default)

Access: Signed evidence grant with commit manifest, selected modules, RLS audit output

Approval: Compliance reviewer approval

Tier 2 (exception)

Access: Time-boxed read-only repository access

Approval: Dual approval: legal/compliance + engineering lead

Prohibited: production database access, secrets, forking source material, sharing code with unauthorised third parties. The full process is shared under a signed diligence grant.

Evidence pack contents
  • Governance summary for civic and election-body reviews
  • POPIA and ISO control mapping
  • Tenant isolation evidence
  • Selected source-control and architecture overview
  • SOC 2-aligned control evidence index
  • Redacted operational logs for an agreed time window
  • DPIA summary, key-management policy, and incident-response playbook
  • Independent security-test summary when available

Delivery: time-limited signed grant after legal review, redaction, and integrity packaging.

Regulator communication template

Dootsa acknowledges your audit request under [legal basis]. We will confirm scope within 5 business days and release approved artifacts per agreed SLA. Evidence is delivered through encrypted, time-boxed access grants. Raw respondent-identifying data is withheld unless explicitly approved and legally required.

Escalation: compliance contact on file · Incident findings reported through coordinated disclosure.

Public-safe security disclosure
Role separation, immutable evidence chains, data minimisation, policy-driven redaction, and expiring access grants. Public posture API: /api/public/compliance/posture
What we intentionally do not publish
Private identifiers, secret keys, internal credential paths, privileged infrastructure maps, and any detail that would weaken participant security.

For trust positioning, visit Trust and Compliance · For business context, visit Dootsa for Businesses.