Security is built into
every layer of Laksana
From encrypted cloud infrastructure to role-based access control, we designed Laksana so facility managers, building owners, and vendors can trust us with the data that keeps operations running safely.
How we keep your data safe
The foundational pillars of the Laksana security architecture.
Cloud Infrastructure
Laksana is hosted on Amazon Web Services (AWS) in Singapore, with strict multi-tenant data isolation organization by organization, and daily automated backups ensuring your building's data is protected.
Encrypted at Rest & Transit
Data moving between your device and Laksana is encrypted the same way online banking is. All databases, backups, and file storage are encrypted at rest with AES-256 so your data remains unreadable.
Technical detail: TLS 1.3 in transit with HSTS enforced; AES-256 server-side encryption.
Evidence Integrity
Photos and inspection evidence are securely watermarked with timestamps, coordinates, and user metadata for irrefutable operational auditing. EXIF metadata is preserved for forensic verification when needed.
Role-Based Access Control
Granular permissions with over 65+ distinct capabilities restrict every role — from technicians and security guards, to property managers and platform admins — to only the data they are authorized to act on.
Comprehensive Audit Trail
Every record modification, status change, configuration update, and access event is meticulously logged with actor identity and timestamps, so any incident can be traced back flawlessly.
Data Retention & Compliance
Laksana aligns with Malaysia's PDPA and is designed with GDPR data protection principles in mind. Automated retention policies prune obsolete data, and complete evidence archives can be exported securely.
Bookings — payments, refunds & applicant data
How facility booking payments, refunds and applicant records are handled.
We never touch card data
Card, bank and e-wallet details are handled entirely by the payment gateway — the merchant of record for every transaction, not Laksana.
Your own account on Advanced and Enterprise
Bring your own payment gateway and collections settle directly into your organisation's own account — we never hold tenant funds.
Refunds
Most Malaysian FPX gateways don't support automatic refunds. A refund is filed by the system and approved by your finance team, settling within 7 working days. Deposits follow the same rule.
IC number, printed on your approval letter
An identity card number is collected because it is required on the surat kelulusan (approval letter) your organisation issues — not for any other purpose.
Retention & automatic purge
Applicant records are retained for 24 months by default, configurable per organisation. After that, IC number, address and email are permanently removed. Name, phone and the booking reference are kept, because the financial record must remain attributable. Any export containing an IC number is restricted to the finance role and logged for audit.
Sub-processors
CHIP, Airwallex, Billplz or Stripe for payment processing (depending on the gateway your organisation configures), Meta-approved WhatsApp Business templates for notifications, and AWS Singapore (ap-southeast-1) for file storage — the same region as the rest of the platform.
Shared Responsibility Model
Security is a partnership. While we secure the platform, you play a key role by managing user access, safeguarding API tokens, and configuring appropriate permission levels for your team members.
For security inquiries or vulnerability reports, contact us at security@laksana.ai.