Learn how we protect, manage, and secure your company data with transparency and industry-standard practices.
The current production service is hosted in Railway's Singapore region. No Malaysian-only residency commitment is claimed until a verified hosting and backup policy is approved.
HTTPS is required for the production application origin. Provider encryption, key management and rotation commitments will be published only after they are verified contractually.
Every query is scoped by workspace at the data layer. Cross-workspace identifiers return not-found rather than forbidden, so existence is never disclosed.
A production backup schedule and restore rehearsal have not yet been evidenced. Paid launch readiness remains blocked until both are configured and tested.
Financial mutations write actor and durable-record audit evidence. Database-level immutability and the final retention policy are still pending approval.
Server-side workspace membership and role checks protect administrative routes. MFA, recovery and support-access procedures are not represented as complete until independently verified.
| PROVIDER | PURPOSE | REGION |
|---|---|---|
| Railway | Hosting, database | SG |
| Payment provider | Configured provider checkout | Pending |
| Transactional email | Invoices, alerts | Pending |
| Error monitoring | Diagnostics, no financial data | Pending |
| Bank feed provider | Not enabled | — |
Incident notification timing and escalation policy are pending legal and operational approval. Contact support for a current issue.
Use the contact form to report a vulnerability until the security mailbox and response policy are operational.
Contact UrusHQ