Security & PDPA
- Sign-in is a simulated persona selector — no credentials are entered, stored or verified.
- PDPA posture, retention schedule and data-subject request register are published as prototype policy, not as a live compliance service.
- MFA, device and session security are documented policy positions only; nothing is enforced by this prototype.
- KYC document sets are described for each stakeholder type; no identity document is ever collected or verified here.
The full posture, data-subject register and retention schedule live on the security screen inside the app.