Security & PDPA

  • Sign-in is a simulated persona selector — no credentials are entered, stored or verified.
  • PDPA posture, retention schedule and data-subject request register are published as prototype policy, not as a live compliance service.
  • MFA, device and session security are documented policy positions only; nothing is enforced by this prototype.
  • KYC document sets are described for each stakeholder type; no identity document is ever collected or verified here.

The full posture, data-subject register and retention schedule live on the security screen inside the app.