Security at Borong
Borong's security programme is designed to protect sensitive procurement data across its full lifecycle on the platform. We apply security controls aligned with industry-recognised frameworks.
Security Controls
Infrastructure Security
Borong's platform is hosted on cloud infrastructure maintained by a major cloud service provider operating globally recognised security certifications. The hosting environment provides physical security, network redundancy, and infrastructure-level threat detection.
Network access to production systems is restricted. Borong applies firewall rules, network segmentation, and intrusion detection controls to limit the attack surface of its production environment.
Data Encryption
All data transmitted between users and the Borong platform is encrypted in transit using TLS 1.2 or higher. Data stored on Borong's platform is encrypted at rest. Encryption keys are managed through a key management system with access logging.
Access Controls
Access to Borong's production systems is restricted to authorised personnel and is governed by a least-privilege access model. Administrative access requires multi-factor authentication. Access rights are reviewed periodically and revoked promptly when an employee leaves or changes role.
Within the Borong platform, client-facing access controls are role-based. Procurement administrators define which users can access which data, place orders, and approve requisitions. These controls are configured by the client organisation and enforced by the platform.
Multi-Tenant Data Isolation
Borong's platform is built on a multi-tenant architecture. Data belonging to one client organisation is logically isolated from data belonging to any other organisation on the platform. This isolation is enforced at the application and database layer. One client cannot access another client's procurement data, spend analytics, or supplier relationships under any circumstances.
Vulnerability Management
Borong conducts regular vulnerability assessments of its platform and infrastructure. Critical and high-severity vulnerabilities are remediated on a defined timeline. The security team monitors for newly disclosed vulnerabilities relevant to the technologies used in the platform.
Incident Response
Borong maintains an incident response plan that defines how security incidents are detected, contained, investigated, and communicated. In the event of a security incident that affects client data, Borong will notify affected clients in accordance with its contractual obligations and applicable legal requirements, including Malaysia's Personal Data Protection Act 2010.
Security Questionnaires and Vendor Assessments
If your organisation requires Borong to complete a third-party security questionnaire, vendor risk assessment, or information security review as part of your procurement process, please contact our team. We aim to respond to security assessment requests within five business days.
Responsible Disclosure
If you have identified a potential security vulnerability in Borong's platform or infrastructure, please report it to us. We will acknowledge your report within two business days and investigate all valid reports. We ask that you do not publicly disclose a vulnerability before Borong has had a reasonable opportunity to investigate and remediate it.