Skip to main content
Straventa
Security & Trust

Built for the people who say no to vendors first.

Security, compliance, and data-residency posture in one place. Written for the procurement, infosec, and compliance reviewers who decide whether a fintech infrastructure vendor can touch production traffic.

Four pillars of our security posture

Boring, on purpose.

Encryption everywhere

TLS 1.2+ in transit. AES-256 at rest. Per-tenant key isolation in our SaaS region; on-prem deployments use the customer's own KMS or HSM.

Deploy where it makes sense

SaaS in Jakarta region for mid-market fintechs. Single-tenant on-premise for regulated banks needing in-country control of every component, including the database.

Identity & access

Single sign-on through Straventa Accounts, our self-hosted OpenID Connect provider — role-based access on every action, step-up MFA on sensitive operations, and audit logs exportable to the customer's SIEM on request.

Monitoring & incident response

Production is observed 24/7 from Jakarta. Documented incident-response runbook with severity-tiered SLAs. Customers are notified of any incident affecting their data within the timelines stated in the DPA.

Compliance mapping

Aligned where it matters

We do not list standards we do not actually map to. Statuses below are current as of this page's last revision.

OJK SE 21/2023

Our control set maps to OJK guidance on IT risk for financial-sector providers — covering vendor management, data classification, BCP, and audit trails.

BI Regulations

Payment-related products honour Bank Indonesia rules on IDR processing, BI Fast operating windows, and on-soil data residency for transactional data.

PPATK reporting

AML Monitoring is built around PPATK STR/CTR thresholds and reporting formats; the underlying audit trail is preserved for the regulator-mandated retention period.

UU PDP 27/2022

Customer-side data is processed under a Data Processing Addendum that mirrors the obligations of the Indonesian Personal Data Protection Law.

Independent attestation

We are building toward independent attestation and will publish the scope and timeline once it is signed. We would rather show you our controls and let your team assess them than point at a badge we do not hold yet.

Certification programme

Not certified today. The control work that a certification depends on — access control, audit logging, retention, incident response — is in place and documented, and we will say so plainly rather than imply a certificate we do not have.

Data residency

In Indonesia, by default.

Customer data on our SaaS plane lives in our Jakarta region. Encrypted backups never leave Indonesian sovereign borders. On-premise deployments place every component — including the database and queue brokers — inside the customer's own environment.

Primary region: Jakarta, Indonesia

Sub-processors

Cloud (SaaS region)
Compute + storage, Indonesia region
Jakarta, Indonesia
Email delivery
Transactional and pre-sale email
Asia-Pacific
Analytics
Aggregated, anonymised website analytics
EU region
Scheduling
Demo-booking calendar
Asia-Pacific

Specific vendor names are shared with customers and prospects under NDA on request.

Need evidence?

Pen-test summaries, control matrices, and DPIA templates are available under NDA. We respond to security questionnaires (CAIQ, SIG-Lite) within 5 working days.

[email protected]

Privacy and data-subject requests live on /privacy.

Procurement reviewer in the room? Let us walk you through it.

Bring your rails, controls, and deployment constraints. We will show where the platform fits and where it does not.