Data Security

The safeguards we apply to protect the confidentiality, integrity, and availability of your data.

Security Layers

  • TLS encryption for all application traffic.
  • At-rest encryption for databases and file storage.
  • Inter-company data isolation at the database level (row-level security) — automatically tested on every release.
  • Files accessed via short-lived signed links; no public access.
  • Audit logs for sensitive actions: access, status changes, exports, and deletion.

Data Residency

Portal data is stored in the Jakarta, Indonesia region. Assessment processing by the PRIME engine runs on partner infrastructure with exchange limited to pseudonymous references.

Retention and Deletion

Data is retained per program retention policy and organiser contracts. Deletion is permanent (hard delete, including files) and recorded in auditable purge logs.

Incident Handling

Security incidents are handled through internal incident-response procedures. Affected parties are notified in accordance with applicable provisions.

Vulnerability Reporting

Vulnerability findings may be responsibly reported to primayasaeduka@gmail.com.