TRUST
Security
MediaClip is used by communications, marketing and executive teams in Botswana who care about the confidentiality of the coverage we monitor for them. This page summarises the controls we operate. A more detailed enterprise security briefing is available on request under NDA.
Network and application security
- All web and API traffic is served over HTTPS with TLS 1.2 or higher.
- The public website enforces standard security headers including X-Content-Type-Options, X-Frame-Options, Referrer-Policy and a restrictive Permissions-Policy.
- The demo-request endpoint is protected by rate limiting and a bot honeypot.
- Admin endpoints require a bearer key with constant-time comparison and are CORS-restricted to mediaclip.net origins.
Data storage
- Client data is stored in a managed PostgreSQL database with TLS-encrypted connections.
- Backups are managed by the database provider on a rolling schedule.
- Application services run on isolated cloud environments with least-privilege configuration.
Access control
- Access to production systems is limited to authorised MediaClip personnel on a need-to-know basis.
- Administrative credentials are stored in a secrets manager, never in source control.
- All administrative actions on client data are logged.
Monitoring and incident response
- Application and infrastructure metrics are continuously monitored.
- Anomalies and failures trigger alerts to the on-call engineer.
- Client-facing incidents are triaged against a severity matrix (P1 through P4) with response-time targets set out in the client's service agreement.
- In the event of a personal-data breach, MediaClip notifies affected clients and — where required — the Botswana Data Protection Commissioner within 72 hours of becoming aware of the breach, in line with Botswana's Data Protection Act 2024 (Act 18 of 2024). Where a full assessment is not possible in 72 hours, an initial notification is issued and updated as the investigation progresses.
- Post-incident, affected clients receive a written incident report describing the nature of the breach, the personal data involved, the mitigation measures taken and the steps to prevent recurrence.
Third-party sub-processors
MediaClip uses a small number of established cloud sub-processors for hosting, database, transactional email and monitoring. A current list is provided to enterprise clients under NDA and updated when it changes materially. Each sub-processor is selected for its published security controls and DPA compliance.
Client responsibilities
- Protect account credentials and share them only with staff who need access.
- Notify us promptly at dumela@mediaclip.net if you suspect account compromise.
- Comply with your own organisation's information-security policies when using MediaClip dashboards and reports.
Responsible disclosure: if you believe you have found a security issue in a MediaClip system, please email dumela@mediaclip.net with details. We investigate every report and will not pursue action against good-faith researchers.
Contact
MediaClip
Gaborone, Botswana
dumela@mediaclip.net
