Data Security
The safeguards we apply to protect the confidentiality, integrity, and availability of your data.
Security Layers
- TLS encryption for all application traffic.
- At-rest encryption for databases and file storage.
- Inter-company data isolation at the database level (row-level security) — automatically tested on every release.
- Files accessed via short-lived signed links; no public access.
- Audit logs for sensitive actions: access, status changes, exports, and deletion.
Data Residency
Portal data is stored in the Jakarta, Indonesia region. Assessment processing by the PRIME engine runs on partner infrastructure with exchange limited to pseudonymous references.
Retention and Deletion
Data is retained per program retention policy and organiser contracts. Deletion is permanent (hard delete, including files) and recorded in auditable purge logs.
Incident Handling
Security incidents are handled through internal incident-response procedures. Affected parties are notified in accordance with applicable provisions.
Vulnerability Reporting
Vulnerability findings may be responsibly reported to primayasaeduka@gmail.com.
