Skip to Content
Governance

Governance-first, by design

02X is a governance-first venture builder. Every business we build is designed so that accountability, not just software, sits at its core.

Why governance comes first

We build in regulated, compliance-heavy industries, where getting it wrong carries real legal and financial consequences. Automation alone is not enough in those settings. A register, a reminder or a generated document is only useful if someone accountable stands behind it. So we design every venture around clear ownership and human review, and we treat the technology as the engine, not the decision-maker.

How our ventures are governed

Each 02X venture runs under defined operational leadership with founder oversight. Software handles the tracking, the reminders and the paperwork; qualified people own the judgement and the sign-off. Material decisions are reviewed by a person, and nothing that affects a client's compliance position is left to run unsupervised. This is the same model our flagship venture, GRC Shop, uses across every app.

Discipline in what we build

Governance also shapes which ventures we start. We look for a clear statutory obligation, a heavy and repetitive manual workload, and a genuine need for accountable oversight alongside good software. We do not chase problems where automation would only create a false sense of safety. That keeps the portfolio focused on areas where our model genuinely reduces risk for the businesses we serve.

Accountable leadership

02X is founder-led by Philip de Witt, a chartered management accountant (ACMA, CGMA) and MBA with close to two decades in financial governance, risk and operational leadership. That background sets the standard for how our ventures are run: careful, evidence-based, and answerable for outcomes.

What we hold ourselves to

A venture that sells compliance has to be able to answer the same questions it asks of a client. 02X (Pty) Ltd is a registered South African private company, registration number 2025/768856/07, incorporated in 2025. It maintains its own statutory filings with the Companies and Intellectual Property Commission, including annual returns, the compliance checklist and beneficial ownership, and it publishes a PAIA manual as section 51 of the Promotion of Access to Information Act requires of every private body.

The same accountability applies to the professional layer. Where a compliance judgement is made for a client, a named qualified person owns it. Where an obligation sits outside our competence, we say so and point to the professional who should carry it, rather than absorbing it quietly into a service description.

How we handle a rule that changes

Regulatory change is the failure mode for compliance software, not an edge case. Three South African occupational health and safety regulation sets were amended in 2025 and 2026, one long standing set is repealed in September 2026, and the compensation framework changed materially in early 2026. A product that encoded the 2023 position and was never revisited is now wrong in several places.

Our answer is structural rather than heroic. Statutory rules are held as sourced data with the gazette reference attached, not scattered through application code. Amendments are tracked against the Government Gazette and applied to the rule set, and content that cites an instrument due to be repealed carries a review date. Where we cannot verify a figure against a primary source, we do not publish it as settled.

What accountability looks like when something goes wrong

Our ventures surface obligations, evidence and gaps. The client decides on remediation and remains the party the regulator holds responsible, because that is how the statutes are written and no service agreement changes it. What we are accountable for is that the obligation was identified correctly, raised in time, and evidenced properly, and that is the standard we expect to be measured against.

Client data is treated on a purpose basis, with retention set by why the record exists rather than by a single blanket period, and with categories that are separately protected where the law requires it. We do not sell client data, and we do not use it for any purpose outside delivering the service.

Handling data responsibly

Our ventures work with sensitive compliance records, so we treat data protection as part of governance, not an afterthought. Ventures are built to keep client records organised, access-controlled and handled in line with South African law, including POPIA.