Security and data
Architecture
Section titled “Architecture”| Part | Does | Built on |
|---|---|---|
| CDD Core console | Officers’ screens | Web app over HTTPS |
| KYC Core | Applicants’ screens | Separate web app over HTTPS |
| Database | All data, business functions, sign-offs, row-level security, delete guards, audit logs | PostgreSQL (Supabase) |
| Authentication | E-mail and password; session tokens | Supabase Auth |
| File storage | Applicant documents and images, sign-off documents, statement files | Supabase Storage |
| Connectors | Account opening, sign-in, dispatch to and from trading and statement systems | Edge functions |
| Scheduler | Ladder, screening sweeps, messages, monitoring, session expiry | pg_cron inside the database |
| Key store | Keys for connectors and outside systems | Supabase Vault |
Neither app keeps business data on the user’s device. Every read and write goes to the database with the signed-in user’s token, under row-level security. The database region, service plan and backups are recorded for each institution’s installation.
Separation between institutions
Section titled “Separation between institutions”Several institutions can share one platform. Each is a tenant, and row-level security on every business table keeps each tenant’s rows invisible to others. Writes go through database functions that check the role before anything is recorded.
Sign-in and sessions
Section titled “Sign-in and sessions”- Every sign-in, sign-out and refused sign-in is logged with time and IP address. The browser cannot write these records.
- One active session per user. A new sign-in closes the old session.
- Idle sign-out is set by the institution, between 5 and 60 minutes. The database refuses values outside that range.
- Tokens refresh hourly. Expired sessions are closed by a job every five minutes.
Records and retention
Section titled “Records and retention”- Every action, sign-off, import run and contact with an outside system is recorded.
- Each record carries a retain-until date. Records under retention cannot be deleted or edited; the database refuses.
- Filings are kept for five years from submission, with documents, receipts and approvals.
- Applicant documents are captured only where needed. For example, the back of the Thai ID card is never photographed or kept.
For your security review
Section titled “For your security review”Detailed security material (the architecture, the access matrix by role and the installation annex) is shared with institutions directly. It is not published on this site.