Resources
Index of Bursa security, privacy, and legal documents.
Documents you can open without an NDA. No audit report exists yet.
Security program
Architecture, vendors, and program scope.
Control matrix
Technical, organizational, and admin-access controls.
Regulatory compliance
UU PDP, POJK, PCI, GDPR-ready, PSE.
Vulnerability reporting
Responsible disclosure to security@.
Security FAQ
SOC 2, bug bounty, and claims we refuse.
Legal & privacy
Request a security pack
For vendor due diligence, security questionnaires, or a DPA. We do not have a SOC 2 / ISO report to share.