Technically Compliant
Real CTOs. Real Privacy Challenges. Real Engineering Solutions. You've got third-party scripts you can't really identify, your data mapping spreadsheet was last updated in 2019 (and your schema doesn't match it), and someone from Legal just DM'd that "we need to talk about GDPR". Cue eye-roll. Technically Compliant is the podcast where CTOs talk about what privacy compliance really looks like when you're shipping code, managing legacy systems, and trying to convince the CEO (and yourself) that a consent management platform isn't optional. Each episode, I sit down with CTOs who've been in the trenches—the ones who've retrofitted privacy into monoliths held together with duct tape, discovered entire tables of unexpected PII, survived their first DSAR that returned 80,000 records, and lived to tell the tale of explaining to their CEO why they can't "just ignore the risk." No vendors. No legalese. Just real conversations about the messy reality of building privacy into software that's already moving at full speed (or higher). Because let's be honest: you're probably technically compliant. The question is what happens when someone checks.
Technically Compliant
Digital Identity and Informal Markets with Byron Rode from Ignis Labs
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
In this episode, Byron Rode shares his extensive experience in fintech, privacy, and security, focusing on innovative solutions for informal sectors in South Africa. We explore how to balance user experience with robust security and privacy practices in digital identity and loyalty systems.
Key Discussions:
- Digital identity validation without traditional ID
- Privacy challenges in informal sectors
- Security measures in fintech platforms
- Use of QR codes for loyalty programs
- Risk management in data security
About Byron:
Father. Runner. Surfer. Human
Byron is the Co-Founder and CEO of ignis, and founder of the (my)cards app. He's a chapter director of CTO Academy, and serves on the board of Word of Mouth. In the past, Byron was the CTO of Yebo Fresh.
About Ross:
Ross, the "Nerd with Trust Issues", is a technology and privacy specialist with over 20 years of experience navigating the complex intersection of innovation, governance, and cybersecurity. He holds a Master’s degree in Management of Technology and Innovation, a CIPP/E designation in privacy, and certifications in paralegal and ethical hacking.
With a background in Software-as-a-Service and more than a decade dedicated to governance consulting in privacy and security, Ross has helped organizations translate regulatory requirements into actionable strategies. He is a passionate advocate for consumer cybersecurity and privacy rights, known for making even the most complex topics accessible and engaging.
Ross Saunders (00:00)
Hello everyone and welcome to Technically Compliant. Today I am speaking to Byron Rode. He is a father, a runner, a surfer, and a human from my native country of South Africa. So glad to have you on there and and and everyone's gonna have our accents to deal with today.
Byron Rode (00:17)
Yeah, it's a it's a South African South African or South African cast. thanks for having me, Ross. It's been really, really cool to to dive into this. I'm looking forward to it.
Ross Saunders (00:27)
Yeah. Yeah, we've had a couple of conversations before starting this, which I think is going to be really interesting. And we we kind of ended up having what could have been a whole podcast when we were discussing. so Byron is the co-founder and CEO of Ignis Labs, founder of MyCards. He's a chapter director of the CTO Academy. He's on the board for word of mouth, and in the past he was CTO with YeboFresh. did I get
Byron Rode (00:52)
Yeah.
Ross Saunders (00:52)
all that right?
Byron Rode (00:53)
You did indeed.
Ross Saunders (00:54)
Fantastic. And I think from our conversations that we've had, I think we've got a bit of a double bull around privacy and security. talking about the my cards and loyalty side of things, as well as a bit of the YeboFresh side and some cool stuff you were doing there previously when you were there. So so yeah. Folks, welcome to Technically Compliant. We're gonna jump in then. So I think Byron, if let's kind of set the scene here, if you can give a
Me a bit of a a description about kind of YeboFresh, my cards, where you've been, what problems you were ch faced with. let's give some context
Byron Rode (01:30)
Sure.
Ross Saunders (01:30)
for the listeners.
Byron Rode (01:31)
Cool. I mean, we've got a pretty storied history in technology, 20, 25 years in in the industry. you know, it's been a long time actually. I started at Yebofresh. it was my first real CTO gig, I guess, if you will, before that I'd done head of technology and engineering manager or lead, you know, lead architect or some kind of role.
And I took over from a very, very great guy, Mike Jones, who had kind of been the COO slash CTO. and he'd built a really solid foundation. And I came in and I had just come off a bit of contract work in the United States as a CTO, and I was kind of, you know, trying to to find my way in in South Africa, in you know, in the CTO in the CTO space and joined Yebofresh. And that was a
great couple of years of just building our technology in an in a sector that was very different to the rest.
Ross Saunders (02:32)
Mm-hmm.
Byron Rode (02:32)
you know, in traditional sectors you've got people who have a credit card and a and and a nice computer at home and jump on the internet and order from take a lot or Amazon or wherever and they receive their goods and all's fine. But in the informal sector it's very, very different. The bigger townships have this, but the smaller little spaza shops and
you know, the little the little stores that are selling goods don't have those those tools. And the purpose of YeboFresh was to bring that kind of FMCG sales process into into the into the informal sector. And I worked there for for just under three years. I then left and formed a fractional CTO consultancy for a while. So I ran Rodehouse, which was my little consultancy, and I would kind of do fractional work for different companies and and bring about, you know,
architectural changes, etc. And that worked really, really well. And around November 2024, I had seen on Twitter that Stocard was leaving South Africa. And I, you know,
Ross Saunders (03:30)
Mm.
Byron Rode (03:30)
it was kind of at the the agentic engineering had just kind of come in and it was kind of exciting. So I was like, well, you know what, let me let me see what I can do. And I opened up Xcode and you know we weren't really
at that full agentic experience yet where you could kind of just prompt and let it go. But I, you know, I hand wrote some code, built some stuff, and within a couple of days it built a little prototype app. And I shared it on Twitter and it gained quite a bit of a bit of excitement. So I was like, well, maybe this is worth it. And I built the product and I released it. And it was iOS only and I expected nothing.
And it was about eight months later that it was acquired through a bigger deal and and as a result formed Ignis Labs along with with other directors from the the holding company and started my cards as a as an actual real business. and then segregate now into Yeah.
Ross Saunders (04:21)
That's awesome. I was seeing the LinkedIn post.
Byron Rode (04:25)
And then I segregate, we segregate obviously because that falls within loyalty, we segregate into the full My Loyalty and that's the new product that's come out now, which is
You know, something we've spoken about a little bit and we we can probably have a a lengthy conversation on just on its own.
Ross Saunders (04:39)
Yeah, no lo loyalty is is an interesting space when it comes to privacy, I must say.
Byron Rode (04:44)
Exactly.
Exact especially especially with with the the stamp based or card based loyalty, you know. when you have a little physical
Ross Saunders (04:51)
Yeah, yeah.
Byron Rode (04:52)
card and you lose it you just lose your points. But now when you have to bring that across. So yeah. Privacy
is privacy is an interesting one.
Ross Saunders (04:57)
Yeah, must say I
I still had my stow card app for a while after leaving and and maybe I've got something better now when I go back to SA
Byron Rode (05:08)
Yeah, defin
de definitely. And we've got so much more in store. But yeah, look privacy
Ross Saunders (05:11)
quantas.
Byron Rode (05:12)
privacy is paramount for it's been paramount for me as a personally. I'm I'm a you know, I've been in in a few data breaches, you know, I'm yet have I been prone emails all the time, every time I get added to another
Ross Saunders (05:25)
Mm-hmm.
Byron Rode (05:26)
one, you know, like it's a it's an ongoing thing. But
I have had my identity somewhat stolen in the past, you know, and and I think for me that's always been a big a big proponent
Ross Saunders (05:37)
Mm.
Byron Rode (05:37)
of why I build the way that I build.
Ross Saunders (05:39)
Makes it very personal. I've I've been there, I've had mine stolen and took years to get it back and get a credit rating again and all sorts.
Byron Rode (05:46)
Hundred percent.
Ross Saunders (05:48)
so I want to jump back to what you were saying with YeboFresh and kind of speaking into you know specific challenges that kind of bring you into action in in terms of privacy. And you mentioned you know going to folks without a traditional
space of credit cards and things like that. And and you we had discussed previously around validating those kind of customers. So can you you talk a bit to, you know, what's involved with validating customers without that digital identity attached to them?
Byron Rode (06:20)
Yeah, quite quite a lot. funny enough, like
Ross Saunders (06:23)
Ha ha ha.
Byron Rode (06:24)
you you would think it would be pretty straightforward and and we try to make it as simple as possible. You know, when you transition from something that is non digital and and quite archaic or just no lack of, you know, of any form of of identity, and then try and introduce digital systems into it, it's it's very
very difficult because it's not only the privacy element but there's all the other parts that go along with it. So we had to we had to consider a number of things. the store owner could not speak English as a first language. you know they could be a a an an owner who has limited understanding of a cell phone but is very good at selling you know or doesn't
you know, it doesn't have internet at home or didn't have anything. So we had to kind of, you know, sit down and and figure out how do we build a minimum viable digital identity. maybe there's a new thing in there, but you know, we had to have some form
Ross Saunders (07:26)
Mm-hmm.
Byron Rode (07:26)
of way of knowing who you were and how how
Ross Saunders (07:29)
Mm.
Byron Rode (07:30)
to identify you, insofar as not only was it just those those difficult things, but it was the the case of
You know, oftentimes in the informal sector people will have a cell phone today and then they will get a new number in the next three months. There there are a number of nuances as to why. We won't obviously go into the details here, but you know, number changing was quite quite often a a big
Ross Saunders (07:53)
Hm.
Byron Rode (07:54)
thing. So how do you manage someone's identity when their number changes? and how do you manage that security when inevitably if a number gets recycled and that person, you know, the number
gets a a notification that they want to now all of a sudden go and log in and and how do we prevent that?
Ross Saunders (08:12)
wow. Yeah, so
so that that I I hadn't even thought about that kind of challenge of delivering a message to like a new owner of a device.
Byron Rode (08:20)
Like like the the the
exactly. So, you know, you might have a legacy system that just sends out a WhatsApp or an SMS and the number receives and is like, here's your invoice or whatever. And that could have personally identifying information on it that now then becomes into the realm of somebody else. And that happens. You know, you could throw out something in the trash and somebody finds it on the road. There there's a number of reasons or ways that this can happen. you know, personally identifying information can be found.
But it's how do you re reduce that vector of what they can
Ross Saunders (08:51)
Mm.
Byron Rode (08:51)
do with it once they have found it. And so what we did is we built this model around not only having your personal identifiable information, but what business information could we pertain from that, right? So it could be things like a store name, it could be what was your regular product that you would often buy from us on a weekly basis? you know, how often was your order habit? You know, what was your order basket size?
you know, did you deliver to multiple re you know, areas? What was your preferred delivery date? We would take a lot of those kind of things that are personal nuanced and put it into the system and is a way to I one, identify who you are, but also to ensure that we can start to form an ad a a some form of digital identity within the system
Ross Saunders (09:36)
Yeah, so
Byron Rode (09:37)
that is identifiable by but without a number.
Ross Saunders (09:39)
Yeah. Wow. Okay. So this this gives me a few things to to think of in here. So you that it's interesting coming from South Africa and knowing as well, because for those listening, one of the interesting nuances around South African privacy law is that the law applies to jurisdictional persons as well. So what that means, in essence is that any business or corporate entity has
personal information and you need to treat it as such. So I think it's it's great that you are addressing that kind of thing well and treating that as personal information. I find a lot of companies, especially in the dev space, and I I think partly to blame for this is the way we classify data in security, where things are confidential,
Byron Rode (10:23)
Mm.
Ross Saunders (10:24)
sensitive, public, or internal, and we assume that's
Byron Rode (10:26)
Exactly.
Ross Saunders (10:27)
that's what it is. And and PII is just personal and it's just a name. Where that's really not the case in the way things actually work.
In that anything that you're inferring and bringing in from a different aspect is all ties into this profile, and the profile itself becomes the PII.
Byron Rode (10:44)
Exactly.
Ross Saunders (10:45)
I feel like I'm half just getting my thoughts organized as to where
Byron Rode (10:48)
Ha ha ha.
Ross Saunders (10:48)
to go. with what you were saying there, and and and you know, those numbers change, but also limiting the PII that gets exposed, and then you also
hit on something like a data subject request as to, you know, how do you identify someone? Let's talk about the limiting of the data and each surface that you had there. So you mentioned a lot of stuff there between the stores, the sales habits and the profiling and that kind of thing, plus the WhatsApps and the challenges that that someone's number might change. How did you limit what is seen on the front end, what's seen on the back end? How did you kind of protect those aspects of it first?
Byron Rode (11:28)
phased approaches very similar to a gated approach that you would do with some form of security, right? You you you have a gate and you have a key and you open the gate, but that doesn't necessarily get you in far enough. You can sort of see in the background. So
Ross Saunders (11:42)
Mm.
Byron Rode (11:43)
it was a similar kind of approach to how we would do things, right? If you would send in a WhatsApp with your number and we identified your number as being a number that was on the system. And and obviously when WhatsApp when you send us a message,
That isn't obviously just a text message. It's an API payload in the background that contains a lot of information that is tied to WhatsApp. So WhatsApp can identify you even if you change your number by them having a unique identifier. So we could use that unique identifier as a means of does this unique identifier exist? We would hash it. We would never store the the same unique identifier. So we would sort and hash.
And then compare and does the hash match. Okay, great. We now have found that this person is potentially who they say they are in the system
Ross Saunders (12:33)
Hmm.
Byron Rode (12:34)
and then dynamically would f feed in information into the system. Very similar to I guess if you were to apply for a form of financial contract in South Africa, and that you type in your ID number and then they'll be like, Do you own this property? And do you own
Ross Saunders (12:49)
Mm.
Byron Rode (12:50)
this car? And
So very similar approach to going, hey, what was your last order? For example, what was the order number of
Ross Saunders (12:57)
Yeah.
Byron Rode (12:57)
your last order? Great. Now I found a a an invoice in the dustbin and I rattle off the invoice. So the immediate assumption is I'm going to ask you questions about that invoice and we wouldn't. We would completely throw it out and then we go, okay, great. Now you ordered from us on the third of December. What did you order? it's it's a it's it's hard to do that.
Because it's a blocker from a you from a usability perspective. As a
Ross Saunders (13:21)
Hm.
Byron Rode (13:22)
user experience, it's quite crap. You know, you have to be like, well, I'm I'm now slowing you down when I all you want to do is pay money to us, and that's what we really want. But it was important to ensure and that speaks again, i if if you think of this vector, you can think of multiple attack surfaces just on that, right? You could do a sim swap, for example, and get the person's number. So now I can WhatsApp the line.
And now the number is identifiable, but the user identifier might be different. But if you then start to pick up all these questions, okay, what was your law? And then all of a sudden now, you know, you've kind of thrown the trail off. And so we
Ross Saunders (14:00)
Yeah.
Byron Rode (14:01)
did it in a in a it's it was very much an approach of how you do, I guess, even physical security. Make you climb over every sharp piece of metal and barbed wire, etc. And if you can make it all the way to the end.
then you're very likely the person that we're letting you in.
Ross Saunders (14:16)
Yeah.
Byron Rode (14:17)
and if not, you're very good at being the person that you were to get in. In which case, you know, how do we how do you navigate that? So we we had to consider that. yeah, quite quite
Ross Saunders (14:25)
Yeah. I
Byron Rode (14:27)
a lot of of of back and forth.
Ross Saunders (14:28)
Yeah, and I think that speaks to like a very responsible approach in terms of risk management. And you have that those different inputs into this where you've got like the what is the degree of certainty that this is the person, how much is that affecting the user experience at the end of the day?
Byron Rode (14:45)
Yeah.
Ross Saunders (14:45)
And you strike a balance. I think and this is something I've seen with companies that are perhaps starting out or or sort of
Sometimes new founders or or folks that are venturing into a product for the first time tend to go for the nth degree of s security and full certainty and all of that at the expense of user experience, or they do the flip side
Byron Rode (15:06)
Of user experience.
Ross Saunders (15:09)
where, you know, we're not gonna we're we're gonna make the assumption that this is the person because we don't wanna hinder them. So it
Byron Rode (15:17)
Exactly, in
which case you then open up a a a and and finding that balance is hard. Right? A guy
Ross Saunders (15:23)
Yeah, yeah.
Byron Rode (15:24)
like a rep come in, take an order, punch it in on their phone, great, you get a delivery the next week. Now it's like, Hey, we want we want to make you order for yourself. Where and and
It was a very ambitious goal at EboFresh was to bring technology into the informal sector. But also, you know, w we wanted to encourage that kind of buying behaviour because it really is, when
Ross Saunders (15:57)
Mm.
Byron Rode (15:58)
you do realize it, it it really is a good thing. But the secure yeah, I I think I think the security side around just making sure and we had to also protect not only the customers' data, but their own customer data, right? You know, we were starting to get people that were
Going to then come and start to deliver products. So we would deliver products to you in the store for somebody else, which meant that the order was placed by the store owner on behalf of somebody else. So now you have a fragmented personal identifiable information because
Ross Saunders (16:27)
Hm.
Byron Rode (16:28)
now you've got that other bit of information that isn't necessarily going to do anything, but it does give you a name, potentially an email address and/or a cell phone number. And
That's mostly what people want anyway in these cases for those dirty marketing lists that they want to send out. But then there's obviously,
Ross Saunders (16:43)
Ha ha ha.
Byron Rode (16:44)
can I go and try and hack your bank account? Can I try and hack your, you know, can I do a sim swap on your name? Those kind of things. So we didn't only think of our security. We
Ross Saunders (16:56)
Mm.
Byron Rode (16:56)
had to think of the security of the store owner and their security of their customers because it's a full circle. So it was quite a yeah, it was a it was a very interesting thing to try and and protect against.
Ross Saunders (17:07)
Yeah. And you know, I think and something that's coming to mind now and and we you've mentioned it in a couple of spaces and and and the limiting the exposure of that data.
With the amount that's available to you and the cool stuff that you can do with the data, how did you go about limiting what you took to being what is actually valid for the use case as opposed to kind of going
all ahead and collecting
Byron Rode (17:28)
All in. Yeah.
Ross Saunders (17:30)
as much as we can because we can get cool statistics and and do cool stuff.
Byron Rode (17:33)
Yes.
And and that so very tricky because two businesses the the two business models there kind of conflict with each other, right? There is the legal requirement of how much information we had to hold in order to facilitate you as a customer and to facilitate your delivery. So that would be a location, it could be a what three words, it could be a GPS point of you know, like we we had to have those those bits of data and how we tried to do them was to put that data
On a separate object or model. So instead of attaching the data to the user, we attach the data to the order. Because it was very simple if we needed to divorce the set the user from the order, and all of a sudden you've lost quite a fair amount of information. but in the same breath, an order and invoice and those things had to have certain requirements. We were required
and and one of the reasons that this was such a big thing is is that we were not a credit provider, but we provided product as a
Ross Saunders (18:31)
Hm.
Byron Rode (18:31)
means of credit to vetted you know, store owners that had gone through a process. But now there was now also a financial element to it because now all of a sudden there could be a credit balance that I could use to order from. you know, so we would look at the bare minimum name, surname.
And sometimes not even a surname, just sometimes your first name, store name even. We didn't even need your personal details if you weren't willing to do it. there is a lot of political reasoning behind the whole thing within the informal sector. That's a an another conversation
Ross Saunders (19:05)
Yeah.
Byron Rode (19:05)
for it for its own day, but we had to manage those things as well. so we tried to take as very little as possible. Mobile number.
And we even had a way to work mobile numbers as email addresses. We built a whole service around that so that we could still deliver email to a mobile number. we would never surface personal information in SMSs or WhatsApps, for example. That would only be the basics. If there was any personal information that was required or any way that we would then take somebody, verify them via an OTP.
and then only take them to an offline form that they could then fill in and do some stuff and that was secure.
Ross Saunders (19:44)
okay.
Byron Rode (19:45)
we tried never to have more than your store, your name, how can we contact you? Because we have to deliver to you and we need to phone you or we need to email you. And internally within the company, obviously then there were a lot of protections and measures that we would put into place then to protect that information internally. So
Ross Saunders (20:04)
Mm.
Byron Rode (20:05)
publicly, very little.
You know, name, surname, like I said, store name your orders. Internally, there was a lot more data. A lot of times sales reps
Ross Saunders (20:13)
Yeah.
Byron Rode (20:13)
would get on the phone, have a phone call, place an order on their behalf, etcetera. And the internal security was the extra like the the biggest because as you know, that is the bigger vector for attack
Ross Saunders (20:26)
Mm.
Byron Rode (20:26)
is to find somebody in the business that is that is easy to give
Ross Saunders (20:30)
Yeah.
Byron Rode (20:30)
you the information. So scoping that was was big.
Ross Saunders (20:33)
So so two things coming from this part as well. And I think one just I want to tie it back, just because it's something I see in the field a lot here, is and and I think it's good for the listeners, is that limiting of data, and it it's it's good what you were saying about how you match someone previously and and and and using the information you have. What happens a lot with companies is they will
Someone will put in a data subject request or they'll want to do some function that needs requires validation. And the first jump is to ask for a government-issued ID, which is collecting more information than you need and you possibly
Byron Rode (21:14)
Exactly.
Ross Saunders (21:14)
have. And you really don't want to be collecting additional pieces of information to validate someone whose information you already have. And I think it was really good that that you have these data points and that's how you would validate people. So I just wanted to kind
Byron Rode (21:26)
Yeah, we never
Ross Saunders (21:27)
of
Byron Rode (21:27)
yeah, we never used identification. The only time we ever took identification was if you were taking credit. And that was just because f legally we had to. and we had
Ross Saunders (21:33)
Yeah, yeah. Yeah.
Byron Rode (21:37)
to store it somewhere and we had to make sure so you know, internally I I was not only the CTO, but I was the CIO at Yeverfresh. So I was the I was the mandated person that
had to sign
Ross Saunders (21:47)
Ha ha ha.
Byron Rode (21:48)
off all the governance and privacy. So as you can imagine, that's always quite a risky little bit of thing to know. So
I vetted and scrutinized everything and everybody to ensure that we what was the minimum viable data set that was necessary in order to operate the business? And then thereafter, if we needed to gather other information, it was behavioral rather than
Ross Saunders (22:10)
Yeah.
Byron Rode (22:11)
than personal.
Ross Saunders (22:12)
Yeah. Yeah. And d jumping back to what you were saying on the securing side now as well. you mentioned security and and you mentioned to me previously around pen testing and things like that. How did you tie all of that in and how d how did that work in the platform, the security side?
Byron Rode (22:29)
Good question. so the pen testing was an exciting one. it was a six week pen testing process, quite long, lengthy, detailed. it involved multiple p people. You know, we we had to vet this, you know, to ensure that there was no way to get into the system. And we'd actually made it so secure that they couldn't test in the first in the first week.
It was actually quite locked down. Like we were like, Cool, go ahead, figure out what you can do. And they're like, We we don't even know where the URLs are properly. You know, like we gave them access to systems as well to kind of go, Okay, great, you're a customer, you're a an end user, you're a store owner, you know, and we gave them different scoped roles and then said, have at it. You know, go and and and do whatever you can. you know, and and pre precursory to that, we'd obviously had a few discussions around what was necessary.
in order to sign off the pen test, right? Because the the security here is paramount because one, you could still use the data if you got it wrong. But two, you could make financial purchases on a person's
Ross Saunders (23:35)
Mm.
Byron Rode (23:36)
account without verification. So we had to fit we had to we had to secure that down. It's a hindrance in some ways or form. Hey you want to make this order place the order you say place the order
Okay, great, we're gonna send you an OTP. Then you get the OTP, you've got to come back. It's like a bit the but security wise and the pen testing for us, in order to in order for me to say I as the CTO was okay to sign this off, the pen test was my non-negotiable.
Ross Saunders (24:03)
Yeah.
Byron Rode (24:04)
I was okay if it didn't look a hundred percent okay. I was okay if we sent thirty SMSs instead of one because you can walk back that. You can say, Hey, like it was a tech issue. You can't walk back, hey, this is a data breach. And a data breach
Ross Saunders (24:16)
Yeah.
Byron Rode (24:16)
A data breach follows you wherever you go. You know, like if I was the CTO at the thing and there was a data breach, then everywhere I go from there I was the CTO that had the data breach at YeboFresh. You know, so like it was
Ross Saunders (24:27)
Ha ha ha.
Byron Rode (24:28)
always paramount to me to make sure that it was secure. So we did OWASP obviously as a as a bare minimum. you know, th those were kind of the things we we went and we we gave basically multiple attack vectors. Here is an invoice. Here you go.
You've got an invoice that's got personally identifiable information. It wasn't real, personally identified. It was from our staging environment. Obviously, we never gave real customer data out during those things. And all of this testing was done in the staging environment. And what we did was when we initially set that up, we took all of the data and fully anonymized it. So it would have been, you know, Joe Soap instead of Byron Road or whatever it was down the line. Numbers were in
And then internally we went and we used a local company and we bought, I think it was a hundred SMS, like a hundred SIM card, digital SIM cards and numbers. And we signed those up with different accounts. And then that was the c so go ahead, try, you find your way, WhatsApp the line, inject code, try, you know, cross scripting, try try SQL injection, try anything that you can. Here are the APIs. We'll give you the APIs. You're gonna surface a token.
I can guarantee you the token that you would have got out of a semi-authenticated WhatsApp would have given you the same information had you been in WhatsApp, had you hit our API. So it was scoped all the way down. Tokens, secure tokens were issued for the relevance that they were. We verified it with OTP. We yeah, I think in some cases I think I might have over engineered some of the security.
Ross Saunders (25:56)
Ha ha ha.
Byron Rode (25:58)
And perhaps maybe we did. but yet you know, if I look back at that, it's one system that I know was never, ever, ever
Ross Saunders (26:06)
Hm.
Byron Rode (26:06)
even there were times that we locked our own selves out. So that shows you know where those things. So yeah, I I made I
Ross Saunders (26:11)
Nice. Nice.
Byron Rode (26:13)
made I made sure that for me, we were opening up a platform to I I think at that time it was about thirty th different stores.
into multiple two big areas, Joe Burg and K T Town. and customers, you know, it was tens of thousands of customers and it's imp well sorry, 25 I said 25 stores, 25 townships within Joe Burg in South Africa. So there were hundreds of of stores in some areas. We had to make sure that the air this the the the data was safe.
But also considering the political c climate, considering the informal settlement, confer all of that had to be considered because not only were you risking people's data, but you were risking their very livelihoods if that data went out. So for me, security
Ross Saunders (27:02)
Hmm.
Byron Rode (27:04)
was paramount.
Ross Saunders (27:05)
Yeah, the context matters. The context always matters.
Byron Rode (27:06)
Exactly. Exactly.
Ross Saunders (27:09)
going from that and and the stuff you learnt there, I want to flip a bit to the QR and the loyalty
Byron Rode (27:16)
To the lawyer.
Ross Saunders (27:17)
side and and kind of what you learned from that and and what you've brought in now. So we were talking about QR codes. Perhaps give us a bit of a background of kind of how that works, and we'll go into a couple of questions there before we wrap up.
Byron Rode (27:28)
Cool. yeah, so like if you d in order to understand where I went and how we architected this whole thing, you have to understand the context, right? So if you will walk into a coffee shop or a store that offers you a stamp card, right? You you get a physical card, it's either stamped or written or signed or whatever it is, and you carry this little card around with you in your pocket, but you come, you order your coffee, you hand your card, they stamp your card, you walk away.
Very simple transaction. There is absolutely no mental thought around it, and there is no security because you don't need to. If you lose your card, you lose your coffee. Whoops. moving that into the digital space comes with its very similar kind of processes that we had in the informal sector. In this case,
Ross Saunders (28:16)
Yeah.
Byron Rode (28:17)
it's a little bit different. Now, a QR code that is stored on the device, it could be static.
And if it's static, it could contain information, right? So I scan that and I get that information. Anyone can scan that with any camera anywhere in the world and they will be able to pick that up. So there is one publicly scannable QR code, and that is the only one that takes you to the landing page to join the loyalty program for said store. That is it. Everything else is dynamic beyond that point. and again.
there is certain information that we require. So when you have a physical card and a stamp, you know, like you don't need your name because I'm gonna come in with my card. But there there there is no vetting, there's no verification. I bring in a full card, you give me a free coffee, I walk out the door. I could have beat somebody up out the road for that. It doesn't matter, you know, like
Ross Saunders (29:06)
Issue the holder with
Byron Rode (29:08)
Exactly. That's all it is. Issue the holder. Whereas with the QR code, there's a little bit more. So we need to take some identifiable information and we we again bare minimum. So the choice is your first name. That is all we need. We don't need more than that. The store doesn't actually need more than that. Most people are willing to give more than that, but you know, and a mobile number or an email address. And
the way that it is done is done in such a way. So if you remember the beginning of how I spoke about this is that when you walk into a store, it's a very s quick and simple transaction. Hand a card, get a stamp, get it back. It had to be exactly the same. You're gonna walk into a busy Starbucks or a coffee shop anywhere and you've got five hundred people standing behind you and then you've got to fill in six form scanner QR code, copy your
Ross Saunders (29:52)
Ha ha ha.
Byron Rode (29:53)
ID, take a photo, do this. The people have walked out the door behind and you've not really got any loyalty. You've got disloyalty. So like
I had to ensure contextually that we made the process as simple as possible. So it is exactly the same. You walk up to the c counter, instead of handing a card, you s take a photo of the or you s you scan the QR code with your camera. And it's going to ask you for your first name and your mobile or your email address. And we're going to store that encrypted on the device. And the only time we will then send it through to the thing is once we need to now issue your stamp. and we create a small, again, digital profile of that person.
I am very big on not knowing email addresses and wanting
Ross Saunders (30:33)
Ha ha ha.
Byron Rode (30:33)
to know those people. So data is encrypted at rest.
Ross Saunders (30:37)
Okay.
Byron Rode (30:38)
it is encrypted at transf during you know transfer of data, so over any of those protocols and it is d decrypted when it is needed to be decrypted and it is decrypted by the system. I don't know what that what the decryption code is. I purposely built it in such a way.
There is a storage of it. We obviously have to keep some level of storage here because if something goes
Ross Saunders (30:59)
Mm-hmm. Yeah.
Byron Rode (31:01)
wrong and we have to change that that that key. We need to ensure that we have a weight. Exactly. Yeah. So we don't
Ross Saunders (31:06)
Yeah. Cryptographic deletion. Yay.
Byron Rode (31:10)
want to have a similar instance of what happened to me with data loss where I wasn't able to decrypt. So quite an interesting story, a little bit of a segue, but Apple have
Very good privacy and security on their devices. and when you form a what they call a group container, which is allows you to store container data within your sandboxed environment in your phone, there is an undocumented thing that if you don't specify a specific URL or a key or whatever it was that they mentioned, your data becomes inaccessible when you transfer from the old account to the new account. So we went.
Hey, we're transferring the app from this account to this one. And they were like, green ticks, all the green ticks, transferred it across, launched the next version of the app, and everybody's data was gone. And it was, I I think that those couple of weeks was the worst thing, like, because it was a trust issue. Now all of a sudden, people and I'm like, your data isn't gone. What happened is
Ross Saunders (32:06)
Ha ha.
Byron Rode (32:07)
Apple moved the house and said you can't have the keys. The keys have to remain here. So
I never wanted something like that to happen, so I've put in little bits of pr protection and measures in the place, but I don't want to know your data. I don't want
Ross Saunders (32:19)
Mm.
Byron Rode (32:19)
to know it. The only person that can look at your data is the store owner. And that he can log in and he has to log in. And when he logs in with his username and his password, it goes and generates an API key that is used for that session. We generate JWT
Ross Saunders (32:33)
Hmm.
Byron Rode (32:34)
tokens that are social session based for the time being. And then we use that token to decrypt the data.
by pulling the hash. So it's like a it's a a bit of a a a three part system. It needs the hash, it needs the user
Ross Saunders (32:46)
Hm.
Byron Rode (32:46)
to log in and have a token, and then we can go and say, okay, and decrypt the data. The other one, which I've mentioned to you, is the same as what most people do. We give you a support pin when you phone and we can type in a pin and that pin will allow us to decrypt some of your information to be able to see it.
Ross Saunders (33:02)
You you say what most people do. It's probably what most people should do. I don't know if I see it as frequently.
Byron Rode (33:05)
W exactly. I when I say what most people do, it's what most
big companies that I've worked with when they know that PII is massively important. Everybody else doesn't really care. So
Ross Saunders (33:14)
Yeah.
Byron Rode (33:15)
to that point. So with the loyalty stuff, it's quite tricky. So we made sure that our friendly Hardy does. I don't know if you can pick them up on the I don't
Ross Saunders (33:25)
I l love that sound.
Byron Rode (33:29)
know if you can pick it up. sorry, I'm not I'm thinking of the Hardy Dob. So w with the QR code
Needs to be quick and efficient, but it has to be secure. So any one of those QR codes that you scan, you're just gonna get garbled letters. Each account, each store owner has its own encryption for its own QR codes. So I can take your encryption key or your encrypted QR code, come in and set up a business and decrypt what I think is mine, and you're still gonna get garbled. We've done three stage encryption.
So it's an encrypted encryption encrypted. again, I don't know if again if it's too much information, but the thing is
Ross Saunders (34:04)
Mm-hmm.
Byron Rode (34:04)
is that you know, like I'm now saying to somebody, and we're not only just doing loyalty, we're doing loyalty f not just for for coffee shops, but we're doing it for places where you could go and spend ten thousand and get a thousand rand back in points, for example,
Ross Saunders (34:18)
Hm.
Byron Rode (34:18)
as a loyalty. We could issue you a gift of a thousand rands worth of loyalty points.
That has a financial bit of data to it. And if I said, Hey Ross, you know, I found your QR code and I've gone and spent two grand at take a lot because I found your code, you're gonna be pissed. nobody's gonna trust the system and I've lost money.
Ross Saunders (34:35)
You You're speaking to someone
who was a bit of a points hacker and I I used to rack up points in loyalty and and use them a lot.
Byron Rode (34:43)
Yeah, exact and the thing is this exact and
so that's exactly the thing. So I'm trying to prevent that, but I'm also trying to do it in such a way so we will when you sign up, we will send you an email, welcome you to the platform, and we'll let you go and you can scan and issue your stamps as many times as you want to. but we're gonna hit a limit and the store owner determines what that limit is, and at that point, you now have to verify your email address.
So your next time you log your QR code and it pops up, we're gonna go, hey, you need to type in, you know, your email address. It has to match the one that is decrypted or encrypted on the device. And then we do an API call in the background and then send them an OTP. And then we have to now verify. So then you can only now start to issue. And if your email address is not verified, if I know yours, Ras like and I go and I type and I join
And I go, well, maybe you have a loyalty card and I type your email address. I might be able to see one or two of your points if we have had that interaction with the with the API. But when it comes time to rewarding those points, when it comes time to making sure that you can actually do it, you're not going to be able to do that because now all of a sudden
Ross Saunders (35:52)
Hmm.
Byron Rode (35:53)
I'm not no longer Ross. I'm Byron pretending to be Ross. How do I confirm that? I can't verify that OTP via email.
you know, I can't do those things. So we've we've done a very similar approach to what we did with the mobile number and business, but identifying you now based on your thing. If you scan a my loyalty card, a QR code at one store and you go to another store, they are completely separate. Even though you
Ross Saunders (36:17)
Mm.
Byron Rode (36:18)
have one user identity in the system, because we have to be able to identify that one core service, I can't pick up from one to the other who you are.
The other store will never know who I am. you know, and and even though there is PII information attached to both stores, all three of us would have to be sitting in the same room with somebody with a gun to all of our heads and saying each one of you have to log in and do something in order. At least that's that's
Ross Saunders (36:44)
Ha ha ha.
Byron Rode (36:47)
my that's that's how I've tested it so far. We run we run
Ross Saunders (36:50)
Yeah.
Byron Rode (36:51)
we run continuous pen testing. The beauty of agentic engineering now is you can.
Ross Saunders (36:56)
Yeah,
yeah.
Byron Rode (36:56)
You
know, you can spend a couple of hundred dollars. I don't think it's the be all and end all. We should still obviously be going to a third party. So we verify our stuff externally as well. when when this whole thing happened and the acquisition, you know, all came about, everything had to be vetted.
Ross Saunders (37:12)
Mm.
Byron Rode (37:13)
as part of the D D to you know, and you know, so I've gone under quite a bit of scrutiny and so far have come out unscathed.
Ross Saunders (37:21)
that's great.
Byron Rode (37:21)
But I don't
let that I don't let that I don't I I don't let that become something I'm like, I'm pretty good at this because the moment you drop your guard, that's the moment that somebody goes, Okay, there we go, I found my entry points.
Ross Saunders (37:27)
Yeah. Yeah.
And it's interesting you you speak about due diligence and things like that and like MA processes and and and acquisitions and so on. I'm seeing more and more the kind of PI privacy stuff. I remember y what, five to eight years ago doing checks for for acquisitions and it was just security. There there wasn't much beyond security.
Whereas you look at them now, that it's very much coming into the privacy space, PII, the risk involved there, and and it it's good to see and it's something to be ahead of.
Byron Rode (38:00)
Yeah. I I work I w I
a hundred percent and I work so you know, I I'm I'm still ultimately a tech person and I've been doing this for so many years. I I work and I consult to different places. So I consult to banks, you know, I I've done consulting to banking. Their PII is, you know, you can't even request somebody's first name without having to go through sixty pages of information and sign
Ross Saunders (38:25)
Yeah.
Byron Rode (38:27)
off.
But I think in in twenty twenty six where we are now, and with the if you look at the number of vector supply chain attacks that have happened and how much PII has been stolen just from those things, if privacy isn't number one on your list when you're building a product from day dot, then you shouldn't build a product now if you've got personal
Ross Saunders (38:46)
Yeah.
Byron Rode (38:46)
information. I'm sorry, like I i I would rather spend six months on on privacy.
And spend one month on UI and user experience and and kind of build it up as we go, but know that it might not look great. And it might be a little bit clunky because I'm asking you to do three or four things to identify yourself. But I'm doing that so that when your data inevitably gets stolen in a data breach by a corporate that hasn't got enough protection in place, and they now have enough vector information to go, great, I can piece together Ross. So let me go find where I can find Ross on the internet.
My goal is to make sure that our products never allow that to happen.
Ross Saunders (39:23)
Hm.
Byron Rode (39:24)
and and you know, we are launching bigger things with my cards in the future. we're working with the Department of Home Affairs through a third party to do identity verification through those systems that are government approved. When we get to that level, the security goes
Two max, you know, like now we're now because now
Ross Saunders (39:44)
Yeah.
Byron Rode (39:47)
we are holding a government issued identity card and the information that pertains to that. You know, so for me that is a big thing. And I've been working on that for two years. For two years, I've been building this process and testing and battle testing, because once you put an ID on a telephone and that phone can get stolen, and somebody could potentially know your PIN code.
That frightens me beyond anything else.
Ross Saunders (40:10)
Yeah. Well it
it's interesting. One of the cases that I I read about recently, it was in Namibia and happened to a friend of mine. she was mugged, stole her phone, but before leaving, they held her up at knife point and demanded her pins and her access to the
Byron Rode (40:28)
Yeah.
Ross Saunders (40:28)
phone and to turn off the facial identity before they left. So it's it's really
Byron Rode (40:32)
been seeing a lot of that like
Ross Saunders (40:34)
crazy.
Byron Rode (40:34)
I've seen a lot of in even in the Uber space with this happening and I mean that this is why that privacy is so important to me. Like you know you get an Uber driver gets it and somebody jumps in the car and then all of a sudden they hold them up at gunpoint and the same thing. Face ID, unlock your phone. Great. Turn off all of these things while you're here with a gun to your head. Of course you're gonna switch all those things off. Then what happens?
Ross Saunders (40:55)
Yeah. And then it's your digital
life. Yeah. crazy.
Byron Rode (40:59)
Exactly. Look, digital identity
and digital privacy. I've thought about this for many, many years. I would love where we could have a a a digital identity service layer that was really robust. My problem is not the security of the data. We have very smart people on this planet that can build secure things.
problem is the humans that are always and it's the human in the loop that is always the issue. Corruption and those things is what make so I get scared when we you know, I I would love to have a way that we could digitally identify you without you having to tell me who you were. You know, we all have a fingerprint of sorts and that fingerprint is based on my usage, my internet behaviors, the things that I do, where I go, what I do, who I speak to, what I see.
But having one government organization or one organization that holds on and owns that data is is very, very petrifying. But I think we're getting to
Ross Saunders (41:53)
Yeah.
Byron Rode (41:55)
the point now. I think
Politics aside, I think we're getting to the point where we're having a single we we're we're a we're a world of people now. There are no more borders anymore with cryptocurrency, financial borders are gone, you know, with all of these things. So a digital identity now, doesn't matter if it's government ID, it does it it's very important that you protect that. And it's very important as me as a custodian of your data, that I protect your data.
and the moment that that changes, I will leave this industry because then
Ross Saunders (42:25)
Ha ha ha.
Byron Rode (42:26)
then I'm no longer then I'm no longer fit for purpose.
Ross Saunders (42:29)
Yeah. Byron, thank you so much for this. This has been enlightening.
Byron Rode (42:31)
Processing right.
Ross Saunders (42:32)
I think there's been so many excellent points in here. And I think towards the end there, there were some quotes of the day that I'm gonna be cutting out and putting that on on on LinkedIn. send me your invoice.
Byron Rode (42:39)
Amazing. Amazing. Yeah, yeah.
Ross Saunders (42:44)
But this has been fantastic. Thank you so much for joining us. Thank you to the listeners for being there
Byron Rode (42:47)
No, Ross, it has been great.
Ross Saunders (42:49)
as well.
Byron Rode (42:49)
And I'm looking forward to going into more detail when we when we scale the security up to max and we have to
Ross Saunders (42:55)
Yeah.
Byron Rode (42:56)
we have to discuss this in more detail.
Ross Saunders (42:57)
We'll have episode two and we'll dive into loyalty because that that is a whole other world. So Byron, again, thanks so much. And you too, and thank you to our listeners. Till next time.
Byron Rode (43:00)
Amazing. I'm looking forward to. Ross, thank you so much. Have a great day. Cheers. Cheers.
Cheers guys, bye.