Trust Center

Security, Privacy, and Compliance Built Into the Platform

Enterprise procurement involves sensitive commercial data - purchase volumes, supplier relationships, contract terms, and financial flows. Borong is built to protect that data at every layer of the platform, comply with Malaysian data protection law, and meet the governance requirements of the organisations that rely on us.

Three Pillars

Data Security

Borong's security programme covers infrastructure protection, encryption, access controls, and incident response.

View Security Details

Data Privacy & PDPA

Borong operates in compliance with Malaysia's Personal Data Protection Act 2010 (Act 709). We process personal data only for defined procurement purposes, apply appropriate security measures, and provide data subjects with access and correction rights under the Act.

View Privacy Details

Compliance & Certifications

Borong maintains a structured compliance programme covering data protection, supplier governance, and platform integrity. This page documents the certifications we hold and the standards our programme is built against.

View Compliance Details

Who This Page Is For

The Trust Center is designed for the people inside your organisation who need to assess Borong as a vendor: IT and security teams conducting third-party risk assessments, legal and compliance teams reviewing data processing arrangements, and procurement or finance leaders who need assurance that Borong meets their organisation's governance requirements.

Enterprise buyers, GLCs, and government-linked organisations often require detailed security and compliance documentation before approving a new platform vendor. This Trust Center provides that documentation in one place. For requests that go beyond what is published here - security questionnaires, data processing agreements, or custom compliance reviews - please contact our team directly.

Data Handling Principles

Borong processes procurement data on behalf of its clients. The data processed includes purchase requisitions, purchase orders, supplier information, approval records, and spend analytics. Borong does not use client procurement data for any purpose outside the operation of the platform and the services contracted by the client.

Multi-tenant architecture ensures complete data isolation between organisations. Your spend data, contract terms, and supplier relationships are not accessible to other organisations on the platform, and are not used to inform pricing, recommendations, or analytics provided to any other party.

  • Data is encrypted in transit using TLS 1.2 or higher
  • Data is encrypted at rest using AES-256 encryption
  • Role-based access controls restrict data access to authorised users within your organisation
  • Audit logs provide a complete, immutable record of all platform activity

Security Contact

To report a security vulnerability, request a data processing agreement, or submit a security questionnaire, please contact us.