အကြောင်းအရာသို့ တိုက်ရိုက်သွားရန်
EMPOBase
my
အခမဲ့ စတင်ရန်
Security & privacy

Google Cloud ပေါ်တွင် တည်ဆောက်ထားသည်။ လွယ်ကူစွာ နားလည်နိုင်သော လုံခြုံရေး။

EMPOBase ကို Google Cloud ပေါ်တွင် host လုပ်ထားပါသည်။ ဤစာမျက်နှာတွင် ယနေ့ ကျွန်ုပ်တို့ အသုံးပြုနေသော control များနှင့် policy commitment များ၊ မကြာမီ roadmap နှင့် သင့် data ကို process လုပ်သော vendor များကို ဖော်ပြထားပါသည်။

What we guarantee, what's in progress, and who processes what — all on this page.

app.empobase.com TLS
Every request, verified
  • In place: Connection encrypted
    TLS in transit · HSTS enforced
  • In place: Identity verified
    Signed token checked server-side, every request
  • In place: အဖွဲ့အစည်း scope ကို စစ်ဆေးအတည်ပြုထားသည်
    Query များသည် သင်၏ authenticated organization context ကို အသုံးပြုပါသည်
  • In place: Encrypted at rest
    Google-managed keys on databases and files
  • Operator-blind encryption Roadmap
    Customer-held keys for sensitive records

Illustrative — the checks every authenticated request must clear.

Hosting
Google Cloud
စင်ကာပူ region တွင် host လုပ်ထားပါသည်။ EU သို့မဟုတ် region ပေါ်မူတည်သော data residency သည် roadmap တွင် ပါရှိပါသည်။
Encryption
In transit + at rest
Data ပို့ဆောင်စဉ် TLS ကို အသုံးပြုပါသည်။ သိမ်းဆည်းထားသော data ကို Google-managed encryption ဖြင့် ကာကွယ်ပါသည်။
Isolation
အဖွဲ့အစည်းအလိုက် ကန့်သတ်ထားသော အသုံးပြုခွင့်
Cloud SQL shared database တစ်ခုကို authenticated organization context နှင့် application က စစ်ဆေးအတည်ပြုသော boundary များဖြင့် အသုံးပြုပါသည်။
Standing commitments
  • Data ကို ပြန်လည်မရောင်းချပါ
  • AI model များကို train လုပ်ရန် မသုံးပါ
  • DPA စည်းကမ်းချက်များကို တောင်းဆိုနိုင်သည်
  • Privacy process မှတစ်ဆင့် support လုပ်သော export များ
  • Sub-processor အားလုံးကို အမည်ဖော်ပြထားသည်
How requests flow

သင့် browser မှ database အထိ security layer လေးခုဖြင့် ကာကွယ်ထားသည်။

A high-level view of how every authenticated request travels through EMPOBase. Names the layer (Edge / Identity / Application / Storage), not the products underneath.

Edge

  • TLS · HSTS · strict CSP
  • DDoS and bot filtering

Identity

  • Managed Google identity provider
  • Signed tokens, verified server-side

Application

  • Request များကို organization တစ်ခုအတွင်း ကန့်သတ်ထားသည်
  • API call တိုင်းတွင် စစ်ဆေးပါသည်

Storage

  • Cloud SQL shared database
  • Private file များ · authorization စစ်ဆေးမှု · short-lived signed URL များ

ယနေ့တွင် data-at-rest encryption အတွက် Google-managed key များကို အသုံးပြုပါသည်။ Sensitive record များအတွက် customer-held key ဖြင့် operator-blind encryption သည် roadmap တွင် ပါရှိပါသည်။

ကျွန်ုပ်တို့ ဖော်ပြထားသော control များ

လွယ်ကူစွာ နားလည်နိုင်သော security baseline။

Bank များက ၎င်းတို့၏ network diagram ကို မထုတ်ပြန်သကဲ့သို့ implementation detail များကို private ထားပါသည်။ အောက်ပါအချက်များသည် ယနေ့ ကျွန်ုပ်တို့ public အဖြစ် ဖော်ပြထားသော control များနှင့် policy commitment များဖြစ်ပါသည်။

အဖွဲ့အစည်းအလိုက် ကန့်သတ်ထားသော အသုံးပြုခွင့်

  • Record များသည် Cloud SQL database တစ်ခုကို shared အသုံးပြုပြီး organization ID ပါရှိပါသည်။ Authenticated context နှင့် organization-qualified query များက boundary ကို စစ်ဆေးအတည်ပြုပါသည်။
  • File များသည် private ဖြစ်ပါသည်။ EMPOBase သည် short-lived signed download URL ထုတ်ပေးမီ authorization ကို စစ်ဆေးပါသည်။
  • Support လုပ်ထားသော API path တိုင်းသည် login တစ်ကြိမ်တည်းတွင်သာ မဟုတ်ဘဲ authenticated organization context နှင့် လိုအပ်သော capability များကို စစ်ဆေးပါသည်။

Encryption

  • HTTPS/TLS သည် browser နှင့် service ကြား traffic ကို ကာကွယ်ပြီး HSTS ကို enforce လုပ်ထားပါသည်။ Application သည် Google ၏ authorized encrypted Cloud SQL connector မှတစ်ဆင့် ချိတ်ဆက်ပါသည်။
  • Data-at-rest အတွက် database နှင့် file storage နှစ်မျိုးလုံးတွင် Google-managed encryption key များကို အသုံးပြုပါသည်။
  • Customer-managed encryption key (BYOK) သည် Enterprise အတွက် roadmap တွင် ရှိသော်လည်း ယခု မရရှိသေးပါ။

Identity & sessions

  • Sign-in goes through a managed Google identity provider — your credentials never touch our database
  • Identity tokens are cryptographically signed and verified server-side on every request
  • Session cookies are HttpOnly + Secure + SameSite. JavaScript can't read them; cross-site requests can't replay them
  • Authorised-domain allowlist on the identity provider — phishing pages can't proxy your login

Resilience

  • Cloud SQL သည် point-in-time recovery အတွက် automated backup ဆယ့်လေးခုနှင့် transaction log ခုနစ်ရက်ကို သိမ်းဆည်းထားပါသည်။
  • Production credential များကို secret တစ်ခုချင်းစီအလိုက် IAM access ကန့်သတ်ထားသော Google Secret Manager တွင် သိမ်းဆည်းပါသည်။ Secret access ကို Cloud Audit Logs တွင် မှတ်တမ်းတင်ပါသည်။
  • Container-level immutable deploy ကို အသုံးပြုပါသည်။ Server ထဲသို့ SSH ဝင်၍ patch လုပ်ခြင်းမရှိဘဲ release တိုင်းသည် build အသစ်ဖြင့် အဟောင်းကို အစားထိုးပါသည်။
  • စာမျက်နှာတိုင်းတွင် Strict Content-Security-Policy၊ X-Frame-Options နှင့် X-Content-Type-Options ကို အသုံးပြုပါသည်။
Privacy

Your data, your rules. Not training fodder.

ကျွန်ုပ်တို့သည် portal ကို လည်ပတ်စေပါသည်။ Customer များက ပေးပို့သော data ကို သူတို့က ထိန်းချုပ်ပြီး service ကို ပေးအပ်ရန်နှင့် ကာကွယ်ရန်အတွက်သာ ကျွန်ုပ်တို့က process လုပ်ပါသည်။

Data ownership
သင်ပေးပို့သော data သည် သင့်ပိုင်ဆိုင်မှုဖြစ်ပါသည်။ Service ကို ပေးအပ်ရန်နှင့် ကာကွယ်ရန်အတွက် process လုပ်ပြီး privacy process မှတစ်ဆင့် export request များကို support လုပ်ပါသည်။
AI training နှင့် ပြန်လည်ရောင်းချမှု မရှိပါ
Customer data ကို ရောင်းချခြင်း သို့မဟုတ် license ပေးခြင်း မပြုပါ။ Customer content ကို EMPO သို့မဟုတ် third-party model များ train လုပ်ရန် မသုံးပါ။ လိုအပ်သော processor များကို အောက်တွင် အမည်ဖော်ပြထားပြီး သက်ဆိုင်သော DPA စည်းကမ်းချက်များကို တောင်းဆိုနိုင်ပါသည်။
Right to delete
Support လုပ်ထားသော workflow များတွင် record အလိုက် delete လုပ်နိုင်ပါသည်။ Verified account-deletion request များသည် privacy process နှင့် သက်ဆိုင်သော retention duty များအတိုင်း ဆောင်ရွက်ပါသည်။
Right to export
Support လုပ်ထားသော export များကို product အတွင်းနှင့် privacy process မှတစ်ဆင့် ရယူနိုင်ပါသည်။ Format နှင့် scope သည် data နှင့် plan ပေါ်မူတည်ပါသည်။
DPA on file
Support လုပ်ထားသော processing နှင့် transfer arrangement များအတွက် သက်ဆိုင်သော Data Processing Agreement စည်းကမ်းချက်များကို တောင်းဆိုနိုင်ပါသည်။
Beneficiary data
Beneficiary အမည်၊ ဓာတ်ပုံ၊ GPS coordinate သို့မဟုတ် identity document များကို သိမ်းဆည်းပါက sensitive data အဖြစ် သတ်မှတ်ပြီး သင့် programme အတွက် လိုအပ်သော access၊ retention နှင့် redaction control များကို အတည်ပြုပါ။
Sub-processors

Who else touches your data, and why.

Customer data ကို ကိုင်တွယ်သော လိုအပ်သည့် processor များကို အမည်ဖော်ပြပြီး ထို processor များ ပြောင်းလဲသည့်အခါ ဤစာရင်းကို update လုပ်ပါသည်။

Who else touches your data, and why.
Vendor Purpose Data type Location
Google Cloud Hosting, database, file storage, DNS, secrets All customer data စင်ကာပူ region
Google identity provider Sign-in (Google + email) Email, display name, sign-in timestamps Global
Hostinger Domain registrar Domain ownership records only EU (Lithuania)
Resend Transactional email (receipts, auth, notifications) Email address, message content USA
Stripe Subscription billing (planned — not yet active) Billing contact, email, payment instrument USA · EU available

Sub-processor list is updated as integrations change. Stripe is planned but not yet active.

The honest part

What's on the roadmap, dated.

We're a young product. Pretending to hold certifications we don't would not survive your first intake call. Here is the real state.

Today

Foundational controls

  • Google Cloud-native baseline
  • Application က အတည်ပြုသည့် organization access control များ
  • Encryption in transit + at rest
  • DPA template on request
  • Sub-processor list (above)
In progress

2026 H2

  • MFA စတင်အသုံးပြုရန် ပြင်ဆင်နေသည် — စာရင်းသွင်းခြင်း၊ ပြန်လည်ရယူခြင်းနှင့် ပြန်လည်သတ်မှတ်ခြင်းတို့ကို စစ်ဆေးရန် ကျန်ရှိနေသည်။
  • Customer-facing audit log export
  • GDPR data export + delete endpoints
  • EU data residency
  • Vendor security questionnaire kit
Roadmap

2027

  • SOC 2 Type I
  • Customer-managed encryption keys (BYOK)
  • ISO 27001 audit kickoff
  • Public status page
Talk to us

Send your security questionnaire — we'll answer it.

INGO procurement teams: send your CAIQ, your VSA, your home-grown vendor security checklist. We respond within 5 business days under NDA and walk through any gap.

Responsible disclosure: found a vulnerability? Email security@empobase.com. We acknowledge within 48 hours and credit researchers in the changelog.