Security & Compliance at Binari
Published by:Binari Legal & CompliancePublished at:July 18, 2020Last Updated:January 17, 2023Read time:12 min readBinari's approach to information security, secure development, data protection, and compliance, to support enterprise vendor evaluation.
Overview
Binari applies security and compliance practices across the lifecycle of the digital platforms and services we build, from planning through ongoing operations. This page gives a high-level overview of our approach, intended to support procurement, information security, compliance, and legal teams during vendor evaluation. It is not a technical security architecture document, a penetration test report, or a complete security control matrix.
Security & Compliance Callouts
Secure Development
Security considerations are built in from the planning and architecture stage, not bolted on after a system is finished.
Access Control
Access to systems, source code, and production environments is limited according to job responsibility and project need.
Data Protection
Personal data and sensitive information are handled in line with our Privacy Policy and DPA, with safeguards scaled to the level of risk.
Continuous Monitoring
We may monitor systems we’re responsible for to catch availability issues, errors, and unusual activity.
Incident Response
We follow a structured approach to identifying, investigating, and handling suspected security incidents.
Vendor Governance
Third-party providers supporting our services are evaluated on service fit, security, and reliability.
Security by Design
Security considerations are factored in from planning, architecture, development, testing, and deployment through to operations and ongoing maintenance. Depending on the project, this can include secure configuration, least privilege, separation of responsibilities, input validation, dependency management, secure deployment, and continued upkeep. The exact architecture and controls applied aren’t identical across every project, since they’re tailored to the needs and risk of each one.
Secure Software Development
Our approach to secure development can include coding standards, peer or technical review, input validation, authentication and authorization controls, dependency management, proper error handling, secure API implementation, testing, patching, and separating development environments from production. This generally aligns with widely recognized principles such as OWASP, though Binari does not hold a formal OWASP certification.
Access Control
Access to systems, infrastructure, source code, production environments, client systems, and sensitive information is limited according to job responsibility and the requirements of the relevant project. This can involve role-based access, least privilege, restricting access to authorized personnel, authentication controls, revoking access once it’s no longer needed, and periodic access review. Multi-factor authentication may be used where supported and appropriate for the system involved.
Infrastructure and Hosting Security
Infrastructure controls depend on the hosting environment, client architecture, cloud provider, and project requirements. Potential safeguards include network protection, secure configuration, environment isolation, encryption, access restrictions, managed infrastructure, patching, and monitoring. Some client systems may run on infrastructure the client has selected or controls directly; in those cases, that infrastructure sits outside Binari’s direct responsibility.
Encryption and Data Protection
Appropriate protection may be applied to data in transit, stored data, credentials, and sensitive information, depending on technical feasibility and risk. For a fuller account of our personal data protection obligations, please refer to Binari’s Privacy Policy and DPA.
Monitoring and Logging
Depending on the service and infrastructure involved, we may use monitoring and logging to identify availability issues, errors, abnormal behavior, performance problems, and security events. The scope of monitoring depends on the individual project.
Vulnerability and Patch Management
We work to reduce security risk through practices such as dependency updates, software patching, vulnerability review, remediation, secure configuration, and monitoring of relevant security issues. Remediation priority can depend on severity, the affected environment, exploitability, service impact, and the contractual scope in place.
Security Testing
Depending on project scope, security-related testing can include code review, automated checks, dependency scanning, vulnerability testing, penetration testing, and configuration review. Formal penetration testing may be performed internally, conducted by an independent third party, or requested separately by a client, depending on project requirements. Not every website or application we build undergoes independent penetration testing.
Backup and Recovery
On projects where Binari is responsible for system operations, backup and recovery practices may be implemented according to system criticality, the hosting environment, the service agreement, and operational requirements. This can include scheduled backups, restoration procedures, backup retention, and recovery planning. Project-specific recovery commitments, including schedules, retention, RTO, and RPO, should be defined through the relevant contractual agreement.
Business Continuity
Binari considers service continuity and recovery for relevant managed services and systems. Depending on the scope of the service, this can include redundancy, recovery procedures, backup strategy, incident escalation, and the capabilities of the infrastructure provider involved.
Incident Response
Our general approach to a suspected security incident includes identification, investigation, containment, mitigation, recovery, documentation, and communication. Where client data or systems are affected, communication about the incident follows applicable law, the relevant service agreement, the DPA, and the specific requirements of that incident.
Personal Data Protection
Security controls relating to personal data are part of Binari’s broader privacy and data protection approach. For the full picture, please refer to our Privacy Policy and Data Processing Agreement (DPA).
Confidentiality
Access to confidential information, such as client information, project materials, credentials, system information, and business data, is limited to authorized personnel and handled in accordance with contractual requirements, confidentiality obligations, and project-level controls.
Client Environments and Shared Responsibility
Security responsibility can be shared between Binari, the client, hosting providers, cloud providers, and other third-party technology vendors, depending on the project’s architecture and contract scope. For example, a client may retain responsibility for identity management, internal user access, endpoint security, infrastructure configuration, data classification, and their own corporate policies, where those areas stay under the client’s control. Security responsibilities should be clearly defined during project planning or contracting.
Third-Party and Vendor Management
Binari may rely on external providers for infrastructure, hosting, email, monitoring, analytics, security, development tools, and other technology services. These providers are evaluated based on factors such as service suitability, security, privacy, reliability, contractual terms, and operational risk.
Subprocessors and Data Processing
Where an external provider processes client-controlled personal data on Binari’s behalf, the relevant arrangements may be addressed under the applicable DPA. For subprocessor detail, please refer to our Data Processing Agreement.
AI Security and Responsible Use
AI-enabled systems can introduce additional risks, including confidential data leakage, prompt injection, insecure integrations, inaccurate outputs, unauthorized access, and insecure AI-generated code. Appropriate controls are selected based on the use case and the level of risk involved. For our broader AI governance principles, please refer to our Responsible AI Policy.
SEO and AI Search Platform Dependency
Search engines, AI platforms, analytics tools, external APIs, and other third-party platforms may operate outside Binari’s direct control. Security and availability commitments relating to these third-party platforms are subject to each provider’s own systems and terms.
Our Approach to Compliance
Binari seeks to align our operations and client delivery with applicable Indonesian law, contractual requirements, client-specific compliance needs, and recognized industry practices where appropriate. Compliance requirements can vary by client, industry, system, data type, jurisdiction, and project scope.
Regulated Industries
Projects for regulated sectors, such as banking and financial services, healthcare, government, telecommunications, or insurance, may require additional controls. This can include extra security controls, specific data handling, documentation, testing, audit support, or deployment restrictions. These needs are evaluated on a project-by-project basis. Binari itself does not hold sector-specific regulatory licenses, unless separately stated.
Security and Compliance Documentation
Qualified prospective or existing clients can request additional information during procurement, security review, compliance assessment, vendor due diligence, or contracting. Materials that may be made available, where appropriate, can include security questionnaires, architecture information, data flow information, the DPA, subprocessor information, security control summaries, or project-specific technical documentation.
Responsible Disclosure
If you believe you’ve found a security vulnerability in a Binari system, we welcome the report. Please describe the suspected issue clearly, avoid accessing data unnecessarily, avoid disrupting our services, and allow reasonable time for us to investigate.
PT Binary Cipta Solusindo (Binari)
Email: [email protected]
Certification and Assurance Status
Specific certifications, independent audits, penetration test reports, or compliance attestations should only be considered applicable where Binari has explicitly confirmed them for the relevant service or project. References to industry frameworks such as ISO/IEC 27001 or the NIST Cybersecurity Framework on this page are industry practice references, not claims of formal certification or compliance with those frameworks.
Continuous Improvement
Binari may update its security practices, technical controls, internal procedures, and supplier arrangements as technologies evolve, threats change, regulations develop, client requirements shift, and industry practices mature.
Contact
For security questions, compliance inquiries, enterprise due diligence, or vendor security assessments, please contact:
PT Binary Cipta Solusindo (Binari)
Security & Compliance
Email: [email protected]
Security, legal, or procurement teams can contact us for additional information relevant to vendor assessment or project due diligence.


