Built for the people who say no to vendors first.
Security, compliance, and data-residency posture in one place. Written for the procurement, infosec, and compliance reviewers who decide whether a fintech infrastructure vendor can touch production traffic.
Four pillars of our security posture
Boring, on purpose.
Encryption everywhere
TLS 1.2+ in transit. AES-256 at rest. Per-tenant key isolation in our SaaS region; on-prem deployments use the customer's own KMS or HSM.
Deploy where it makes sense
SaaS in Jakarta region for mid-market fintechs. Single-tenant on-premise for regulated banks needing in-country control of every component, including the database.
Identity & access
Single sign-on through Straventa Accounts, our self-hosted OpenID Connect provider — role-based access on every action, step-up MFA on sensitive operations, and audit logs exportable to the customer's SIEM on request.
Monitoring & incident response
Production is observed 24/7 from Jakarta. Documented incident-response runbook with severity-tiered SLAs. Customers are notified of any incident affecting their data within the timelines stated in the DPA.
Aligned where it matters
We do not list standards we do not actually map to. Statuses below are current as of this page's last revision.
OJK SE 21/2023
Our control set maps to OJK guidance on IT risk for financial-sector providers — covering vendor management, data classification, BCP, and audit trails.
BI Regulations
Payment-related products honour Bank Indonesia rules on IDR processing, BI Fast operating windows, and on-soil data residency for transactional data.
PPATK reporting
AML Monitoring is built around PPATK STR/CTR thresholds and reporting formats; the underlying audit trail is preserved for the regulator-mandated retention period.
UU PDP 27/2022
Customer-side data is processed under a Data Processing Addendum that mirrors the obligations of the Indonesian Personal Data Protection Law.
Independent attestation
We are building toward independent attestation and will publish the scope and timeline once it is signed. We would rather show you our controls and let your team assess them than point at a badge we do not hold yet.
Certification programme
Not certified today. The control work that a certification depends on — access control, audit logging, retention, incident response — is in place and documented, and we will say so plainly rather than imply a certificate we do not have.
In Indonesia, by default.
Customer data on our SaaS plane lives in our Jakarta region. Encrypted backups never leave Indonesian sovereign borders. On-premise deployments place every component — including the database and queue brokers — inside the customer's own environment.
Sub-processors
Specific vendor names are shared with customers and prospects under NDA on request.
Need evidence?
Pen-test summaries, control matrices, and DPIA templates are available under NDA. We respond to security questionnaires (CAIQ, SIG-Lite) within 5 working days.
[email protected]Privacy and data-subject requests live on /privacy.
Procurement reviewer in the room? Let us walk you through it.
Bring your rails, controls, and deployment constraints. We will show where the platform fits and where it does not.