Skip to content

Security and data

PartDoesBuilt on
CDD Core consoleOfficers’ screensWeb app over HTTPS
KYC CoreApplicants’ screensSeparate web app over HTTPS
DatabaseAll data, business functions, sign-offs, row-level security, delete guards, audit logsPostgreSQL (Supabase)
AuthenticationE-mail and password; session tokensSupabase Auth
File storageApplicant documents and images, sign-off documents, statement filesSupabase Storage
ConnectorsAccount opening, sign-in, dispatch to and from trading and statement systemsEdge functions
SchedulerLadder, screening sweeps, messages, monitoring, session expirypg_cron inside the database
Key storeKeys for connectors and outside systemsSupabase Vault

Neither app keeps business data on the user’s device. Every read and write goes to the database with the signed-in user’s token, under row-level security. The database region, service plan and backups are recorded for each institution’s installation.

Several institutions can share one platform. Each is a tenant, and row-level security on every business table keeps each tenant’s rows invisible to others. Writes go through database functions that check the role before anything is recorded.

  • Every sign-in, sign-out and refused sign-in is logged with time and IP address. The browser cannot write these records.
  • One active session per user. A new sign-in closes the old session.
  • Idle sign-out is set by the institution, between 5 and 60 minutes. The database refuses values outside that range.
  • Tokens refresh hourly. Expired sessions are closed by a job every five minutes.
  • Every action, sign-off, import run and contact with an outside system is recorded.
  • Each record carries a retain-until date. Records under retention cannot be deleted or edited; the database refuses.
  • Filings are kept for five years from submission, with documents, receipts and approvals.
  • Applicant documents are captured only where needed. For example, the back of the Thai ID card is never photographed or kept.

Detailed security material (the architecture, the access matrix by role and the installation annex) is shared with institutions directly. It is not published on this site.