Security & Compliance

Published

syokniaga.com/legal/security · v2.1 · effective 24 Aug 2026

Architecture

Every tenant's data lives in its own MariaDB database — there are no shared tables and no cross-tenant queries. Photos, PDFs, and attachments sit in that same database; used space is measured from it. Platform staff reach tenant data only through audited, time-boxed impersonation sessions that display a persistent banner to the tenant.

Encryption and transport

TLS 1.2+ everywhere; databases and backups are encrypted at rest. Payment gateway keys are envelope-encrypted and never logged, and gateway callbacks are re-queried before anything is marked paid.

Access control

Role-based permissions per tenant; 2FA is mandatory for platform staff and available to every tenant user. Every mutation writes an audit entry, and ledgers (stock movements, price history) are append-only — corrections are reversing entries, never edits.

Availability and backups

Nightly encrypted backups per tenant database with point-in-time recovery; POS is offline-first and syncs with conflict resolution. Maintenance windows are announced in-app. We are a new product on limited infrastructure — we do not advertise unlimited storage or a public uptime SLA.

Compliance alignment

We operate in line with the Personal Data Protection Act 2010 (as amended 2024) and support LHDN MyInvois record-keeping obligations. Enterprise customers can sign our Data Processing Addendum.

Subprocessors

Cloud hosting in Malaysia/Singapore regions; ToyyibPay for payment processing (both our subscription billing and, under each tenant's own keys, their customer collections); transactional email delivery. The current list is maintained in the DPA.

Report a vulnerability

Email security@syokniaga.com — we acknowledge within two business days and do not pursue good-faith security research.