Security at Borong
Borong's security programme is designed to protect sensitive procurement data across its full lifecycle on the platform. We apply security controls aligned with industry-recognised frameworks.
Security Controls
Infrastructure Security
Borong is hosted on cloud infrastructure maintained by a major cloud service provider operating globally recognised security certifications, providing physical security, network redundancy and infrastructure-level threat detection.
Network access to production systems is restricted. Borong applies firewall rules, network segmentation, and intrusion detection controls to limit the attack surface of its production environment.
Data Encryption
All data transmitted between users and the Borong platform is encrypted in transit using TLS 1.2 or higher. Data stored on Borong's platform is encrypted at rest. Encryption keys are managed through a key management system with access logging.
Access Controls
Access to production systems is restricted to authorised personnel under a least-privilege model. Administrative access requires multi-factor authentication, and access rights are reviewed periodically and revoked promptly when an employee leaves or changes role.
Client-facing access controls are role-based. Procurement administrators define who can reach which data, place orders and approve requisitions. The client organisation configures these controls and the platform enforces them.
Multi-Tenant Data Isolation
Borong is built on a multi-tenant architecture. Each client organisation's data is logically isolated from every other organisation's, enforced at the application and database layer. One client cannot access another client's procurement data, spend analytics, or supplier relationships under any circumstances.
Vulnerability Management
Borong runs regular vulnerability assessments of its platform and infrastructure, remediating critical and high-severity findings on a defined timeline. The security team monitors newly disclosed vulnerabilities relevant to the technologies the platform uses.
Incident Response
Borong maintains an incident response plan that defines how security incidents are detected, contained, investigated, and communicated. In the event of a security incident that affects client data, Borong will notify affected clients in accordance with its contractual obligations and applicable legal requirements, including Malaysia's Personal Data Protection Act 2010.
Responsible Disclosure
If you have identified a potential security vulnerability in Borong's platform or infrastructure, please report it to us. We will acknowledge your report within two business days and investigate all valid reports. We ask that you do not publicly disclose a vulnerability before Borong has had a reasonable opportunity to investigate and remediate it.
Security Questionnaires and Vendor Assessments
If your organisation requires Borong to complete a third-party security questionnaire, vendor risk assessment, or information security review as part of your procurement process, please contact our team. We aim to respond to security assessment requests within five business days.