Data Security
Borong's security programme covers infrastructure protection, encryption, access controls, and incident response.
View Security DetailsEnterprise procurement runs on sensitive commercial data: purchase volumes, supplier relationships, contract terms, financial flows. Borong is built to protect that data at every layer, comply with Malaysian data protection law, and meet the governance requirements of the organisations that rely on us.
Borong's security programme covers infrastructure protection, encryption, access controls, and incident response.
View Security DetailsBorong operates in compliance with Malaysia's Personal Data Protection Act 2010 (Act 709). We process personal data only for defined procurement purposes, apply appropriate security measures, and provide data subjects with access and correction rights under the Act.
View Privacy DetailsBorong maintains a structured compliance programme covering data protection, supplier governance and platform integrity. This page documents the certifications we hold and the standards the programme is built against.
View Compliance DetailsThe Trust Center is for the people who assess Borong as a vendor: IT and security teams running third-party risk assessments, legal and compliance teams reviewing data processing arrangements, and procurement or finance leaders who need assurance that Borong meets their governance requirements.
Enterprise buyers, GLCs and government-linked organisations usually require detailed security and compliance documentation before approving a new vendor, and this collects it in one place. For anything beyond what is published here, security questionnaires, data processing agreements or custom compliance reviews, contact our team directly.
Borong processes procurement data on behalf of its clients. The data processed includes purchase requisitions, purchase orders, supplier information, approval records, and spend analytics. Borong does not use client procurement data for any purpose outside the operation of the platform and the services contracted by the client.
Multi-tenant architecture ensures complete data isolation between organisations. Your spend data, contract terms, and supplier relationships are not accessible to other organisations on the platform, and are not used to inform pricing, recommendations, or analytics provided to any other party.
To report a security vulnerability, request a data processing agreement, or submit a security questionnaire, please contact us.