Security & Compliance
Publishedsyokniaga.com/legal/security · v2.1 · effective 24 Aug 2026
Architecture
Every tenant's data lives in its own MariaDB database — there are no shared tables and no cross-tenant queries. Photos, PDFs, and attachments sit in that same database; used space is measured from it. Platform staff reach tenant data only through audited, time-boxed impersonation sessions that display a persistent banner to the tenant.
Encryption and transport
TLS 1.2+ everywhere; databases and backups are encrypted at rest. Payment gateway keys are envelope-encrypted and never logged, and gateway callbacks are re-queried before anything is marked paid.
Access control
Role-based permissions per tenant; 2FA is mandatory for platform staff and available to every tenant user. Every mutation writes an audit entry, and ledgers (stock movements, price history) are append-only — corrections are reversing entries, never edits.
Availability and backups
Nightly encrypted backups per tenant database with point-in-time recovery; POS is offline-first and syncs with conflict resolution. Maintenance windows are announced in-app. We are a new product on limited infrastructure — we do not advertise unlimited storage or a public uptime SLA.
Compliance alignment
We operate in line with the Personal Data Protection Act 2010 (as amended 2024) and support LHDN MyInvois record-keeping obligations. Enterprise customers can sign our Data Processing Addendum.
Subprocessors
Cloud hosting in Malaysia/Singapore regions; ToyyibPay for payment processing (both our subscription billing and, under each tenant's own keys, their customer collections); transactional email delivery. The current list is maintained in the DPA.
Report a vulnerability
Email security@syokniaga.com — we acknowledge within two business days and do not pursue good-faith security research.