Security-Aware Infrastructure & Governance
We engineer systems with strict defense-in-depth principles: zero-trust network boundaries, least privilege role design, automated input validation, and transparent vulnerability management.

Core Technical Security Controls
Our engineering architecture enforces active defensive controls across every layer of the technology stack.
Data Protection & Encryption
TLS 1.3 for data in transit; AES-256 for data at rest. Strict key separation between customer tenants and operational databases.
Identity & Access Boundaries
Role-based access control (RBAC), multi-factor authentication (MFA), SAML 2.0 / OIDC federated SSO, and short-lived access tokens.
Application & API Hardening
Server-side schema validation (Zod), header injection protection, automated honeypots, rate limiting, and strict CSP headers.
Environment Isolation
Strict separation between production, staging, and sandbox environments. Zero customer production data in non-production environments.
Observability & Logging
Centralized audit logging of administrative actions, anomaly detection, and real-time security telemetry without logging sensitive message payloads.
Secure SDLC & Code Scanning
Automated dependency scanning, static code analysis, peer review gates, and deterministic build pipelines.
Vulnerability Disclosure Guidelines
We welcome security researchers and community members who responsibly report security vulnerabilities in IndoTium systems.
How to Submit a Report
Send vulnerability reports to info@indotium.comor use our central contact form selecting the "Vulnerability Report" category. Include:
- Description of the vulnerability and impacted URL/endpoint
- Step-by-step proof of concept (PoC) or reproduction script
- Impact assessment without accessing or modifying third-party user data
Prohibited Research Activities
- Denial of Service (DoS / DDoS) attacks or spamming forms
- Accessing, altering, or destroying user data or tenant records
- Social engineering or phishing of IndoTium directors, staff, or customers
- Public disclosure of any unverified vulnerability prior to coordinated fix
Our Response & Acknowledgements
We acknowledge receipt of security reports promptly upon internal verification. We investigate valid reports and work to remediate security issues in order of severity.
