Security & Compliance

Your people's data,
protected by design.

PayBun is built on Microsoft Azure with layered defenses, encryption everywhere and isolated customer data — engineered to keep you secure, available and compliant with Malaysia's PDPA.

2×
Azure availability zones
24/7
Threat monitoring
1yr
Backup retention
99.9%
High-availability design
Infrastructure

Built on Microsoft Azure.

PayBun runs on a secure, high-availability Azure architecture split across two availability zones, with traffic tiered through an Application Gateway, hardened application servers and a private data tier. Administrative access is brokered only through Azure Bastion.

  • Multi-tier network: gateway, application, data and directory subnets
  • Azure Load Balancer with a Web Application Firewall at the edge
  • Optional Active Directory (ADFS) single sign-on
  • Privileged access via Azure Bastion / jump host only
Azure regions
Availability Zone 1 Active
Availability Zone 2 Active
Web Application Firewall On
Azure Defender Monitoring
Network tiers
Application Gateway Public
Application subnet Private
Data tier subnet Private
Defense in depth

Six layers between an attacker
and your data.

Encrypted entry through the firewall

All user traffic reaches PayBun over HTTPS, terminating at a Web Application Firewall — the only public door to the platform.

OWASP protection at the WAF

The firewall shields hardened, non-internet-facing application servers from OWASP threats — SQL injection, cross-site scripting and intrusion attempts — and alerts administrators on suspicious activity.

Authentication separated from data

The authentication database holds no customer data — it only locates your dedicated instance, kept separate from the application tier.

Encrypted connection brokering

Connection properties to your data are encrypted and can be decrypted only by the application server — never exposed to the client or stored in plain text.

Least-privilege data access

Each role uses a distinct, restricted account. Support and project staff get individual, audited accounts, reachable only through Azure Bastion or a jump host.

Continuous monitoring with Azure Defender

Azure Defender scans for suspicious activity around the clock and produces monthly analysis of consumption, faults, performance and error logs.

Data protection

Encrypted everywhere,
isolated by customer.

Encryption in transit

HTTPS for all traffic, with encrypted connection strings throughout — connection properties can be decrypted only by the application server.

Isolated customer data

Your data lives in its own dedicated instance and database — kept entirely separate from authentication and from other customers.

No data in the auth tier

The authentication database stores no personal or payroll data — only the keys needed to route a request to your encrypted instance.

Optional IP filtering

Whitelist your trusted networks: internal users on safe IPs get full access while external sessions are limited to a restricted set of functions.

Full audit trail

Individual, named accounts for every administrator and support action mean each access to your data is attributable and reviewable.

Always-on detection

Azure Defender continuously inspects activity and reports anomalies, so threats are surfaced early rather than discovered late.

Privacy & PDPA

Aligned with Malaysia's
Personal Data Protection Act.

PayBun's architecture and processes are built to support the seven principles of the PDPA 2010 for the personal data you entrust to us.

Security Principle

Layered defenses, encryption and least-privilege access protect personal data against loss, misuse and unauthorized access.

Retention Principle

Defined backup and retention schedules — data is kept only as long as needed, then handled per your retention policy.

Data Integrity Principle

Isolated databases, point-in-time restore and audit trails keep records accurate, complete and recoverable.

Access Principle

Role-based, self-service access lets data subjects and administrators view and correct the data they're entitled to.

Notice & Choice

Clear handling of what data is collected and how it's used, supporting your obligations to employees and applicants.

Disclosure & General

Personal data is processed only for agreed HR and payroll purposes — never disclosed beyond what you authorize.

Certification

Independently certified to
ISO/IEC 27001:2022.

PayBun Sdn Bhd's Information Security Management System is certified by InterCert to ISO/IEC 27001:2022 — covering the infrastructure, applications and systems that deliver our services, and how we hold and manage customer and business data.

ISO/IEC
27001:2022

Information Security Management System

Certified by InterCert. Scope covers HR, Engineering & Product Management, Customer Support, Sales & Marketing and Finance.

Certification bodyInterCert
Registration no.IC-IS-2409030
Initial certification05 Sep 2024
Surveillance valid to04 Sep 2026
Recertification04 Sep 2027
StandardISO/IEC 27001:2022

PayBun also runs entirely on Microsoft Azure, whose data centres carry their own independent global security certifications.

Business continuity

Built to stay up,
built to recover.

Every tier is redundant and continuously backed up. If a component or a whole zone fails, PayBun keeps running — and your data can be restored to any point in the recent past.

  • Firewall and application servers run a minimum of two instances behind a load balancer
  • Daily server snapshots kept for 7 days, plus a snapshot before every patch or update
  • Database across two availability zones with 35-day point-in-time restore
  • Monthly backups kept 12 months; annual backups kept 1 year; geo-redundancy available
Recovery posture
Point-in-time restore 35 days
Monthly retention 12 months
Annual retention 1 year
Pre-patch snapshot Automatic
Redundancy
App servers 2+ instances
Firewall 2+ instances
Database zones 2 zones
Questions about security?

We'll walk your team through it.

Request our security overview or arrange a session with an HR solution expert and our technical team.