Security Policy for Duitlah
This policy describes our current security practices and commitments. It is referenced from our Privacy Policy and our Terms of Service.
Effective Date: July 23, 2026
1. This Marketing Website Today
This website does not collect personal data through any form, does not store financial information, and has no user accounts. Traffic to the site is served over TLS. The only data captured here is web analytics — see our Privacy Policy for details.
2. platform.duitlahapp.com
The Duitlah app is intended to run on the same underlying infrastructure as our OnePlanner platform: Supabase (managed PostgreSQL) for data storage, Supabase Auth for authentication, TLS in transit, and role-based, database-level Row Level Security (RLS) policies scoping who can read or write a given record. Administrative access to production systems is limited to authorized personnel on a need-to-know basis.
Where AI-assisted features are used, data submitted to them is transmitted over encrypted connections to our AI subprocessors, who act on our instructions. See our Subprocessors page.
3. Personal Data Breach Response
In line with the PDPA, including the mandatory data breach notification requirement introduced by the PDPA (Amendment) Act 2024, if we become aware of a personal data breach that is likely to result in significant harm to affected individuals, we will assess and contain the incident as soon as practicable, notify the Personal Data Protection Commissioner within the timeframe required by law, and notify affected individuals directly where required.
4. Responsible Disclosure
If you believe you've found a security vulnerability in our systems, please report it to [email protected]. Please do not publicly disclose the issue until we've had a reasonable opportunity to investigate and remediate it. We will not pursue legal action against good-faith security research conducted consistent with this policy.
5. Independent Assurance
We build on infrastructure and service providers that maintain their own independent security certifications, and we select subprocessors partly on that basis — see our Subprocessors page. Documentation of a specific subprocessor's certifications can be requested at [email protected].
6. Changes to This Policy
We will update the "Effective Date" above when this policy changes materially.
7. Contact
Security contact: [email protected]