Data Security Policy
Data Security & Information Security Policy, applicable to the Hunter Repo platform and all digital infrastructure operated by Hunter Analytix Sdn. Bhd.
Policy Statement
Hunter Analytix Sdn. Bhd. is committed to implementing and maintaining a comprehensive Information Security Management System (ISMS) aligned with internationally recognised standards and regulatory requirements.
This includes compliance with:
- ISO/IEC 27001:2022
- Bank Negara Malaysia Risk Management in Technology (RMiT) Guidelines
- Malaysia Personal Data Protection Act (PDPA)
We operate under a bank-grade, zero-trust security architecture to ensure that all data assets are protected with the same level of rigour expected of regulated financial institutions.
Objectives
- Protect the confidentiality, integrity, and availability of data
- Establish a structured Information Security Management System (ISMS)
- Ensure compliance with applicable laws, regulations, and standards
- Safeguard trust among users, financial institutions, partners, and regulators
- Enable secure and scalable operations across Malaysia and international markets
Scope of ISMS
- All employees, contractors, agents, and representatives
- All systems, platforms, and infrastructure supporting Hunter Repo
- All data processed, stored, or transmitted
- All third-party vendors, integrations, and service providers
Governance & ISMS Structure
- An Information Security Committee (ISC)
- Designated security leadership (including CISO-equivalent role)
- Defined reporting lines to senior management
- Access Control Policy
- Cryptography Policy
- Incident Response Policy
- Vendor Risk Management Policy
- Business Continuity and Disaster Recovery Policy
- Data Classification and Handling Policy
- Identification of risks to information assets
- Risk assessment and impact analysis
- Risk treatment and mitigation planning
- Maintenance of a risk register
- Continuous monitoring and periodic review
Data Classification & Handling
- Restricted, personal, financial, and enforcement data
- Confidential, operational and analytical data
- Internal Use, non-public internal data
- Public, information approved for public disclosure
Restricted data is protected with the highest level of security, including encryption, strict access controls, and full audit logging.
Access Control
- Role-Based Access Control (RBAC)
- Least privilege principle
- Multi-Factor Authentication (MFA)
- Privileged Access Management (PAM)
- Periodic access review and recertification
Cryptography & Data Protection
- Data at rest encrypted using AES-256
- Data in transit protected using TLS 1.2 or higher
- Encryption keys securely managed with restricted access
- Data masking, tokenization, and anonymization where applicable
Technology & Infrastructure Security
- · Firewall protection and segmentation
- · Intrusion Detection and Prevention (IDS/IPS)
- · Zero Trust architecture
- · Secure configuration and hardening
- · Continuous patch management
- · Endpoint protection solutions
- · Enterprise-grade secure cloud
- · Dev / staging / production segregation
- · Secure identity and access management
Application Security
- Secure Software Development Lifecycle (SSDLC)
- Code reviews and security testing
- Protection against OWASP Top 10
- API security with authentication, authorisation, and rate limiting
Logging, Monitoring & Threat Detection
- Centralised logging of all system and user activities
- Real-time monitoring of security events
- AI-driven anomaly detection
- Tamper-resistant audit logs
Incident Response
- Detection and identification
- Containment and mitigation
- Investigation and root cause analysis
- System recovery and restoration
- Post-incident review and improvement
Business Continuity & Disaster Recovery
- Regular encrypted data backups
- Defined recovery objectives (RTO and RPO)
- Redundant systems and failover capabilities
- Periodic disaster recovery testing
Third-Party & Vendor Security
- Security due diligence before onboarding
- Execution of Data Processing Agreements (DPA)
- Continuous monitoring of vendor compliance
Mobile & Field Agent Security
- Secure mobile device authentication
- Device-level encryption
- Remote wipe capability
- Anti-tampering and anti-reverse engineering protections
- Full tracking and audit logging of field activities
Legal & Compliance
- Malaysia Personal Data Protection Act (PDPA)
- Bank Negara Malaysia RMiT Guidelines
- ISO/IEC 27001 standards
- Applicable international data protection regulations
Continuous Improvement
- Plan, Do, Check, Act (PDCA) methodology
- Ongoing threat assessment
- Regular updates to policies and controls
Contact
Security & Compliance Office, Hunter Analytix Sdn. Bhd.
Email: security@hunterrepo.com