Security Policy

Last updated: 2 July 2026 · Framworq Digital

Security is foundational to how we build and operate AI automation. This policy outlines the administrative, technical, and organisational safeguards Framworq uses to protect the confidentiality, integrity, and availability of the data entrusted to us.

Overview

Framworq Digital implements layered administrative, technical, and physical safeguards across its systems. We review our infrastructure and practices regularly to stay aligned with recognised security standards and to respond to evolving threats.

Data Protection Principles

Our approach is guided by a small set of principles:

  • collect only the data needed for a legitimate purpose;
  • grant access on a least-privilege basis;
  • treat client information as confidential by default;
  • retain data only as long as necessary; and
  • continuously monitor and improve our controls.

Access Control

Access to systems and data is restricted to authorised personnel, governed by role-based permissions, and protected with multi-factor authentication where supported. Access logs are monitored to detect and respond to unusual or unauthorised activity.

Encryption and Data Storage

Sensitive information transmitted between our systems and external services is encrypted using SSL/TLS. Stored data is protected using the encryption capabilities provided by our hosting and platform partners, and backups are performed regularly to support recovery.

Network and Infrastructure Security

Our infrastructure is protected by firewalls, monitoring, and regular software updates. We carry out periodic vulnerability reviews and assess third-party integrations before they are introduced into production environments.

Application Security

We follow secure development practices, including code review, secure storage of credentials and secrets, separation of development, testing, and production environments, and operational logging to support monitoring and diagnostics.

Third-Party Services and Integrations

We integrate with reputable third-party platforms such as cloud providers, AI model providers, and business applications. While we choose partners carefully, we are not responsible for vulnerabilities or breaches occurring within third-party systems that are outside our operational control.

Client Responsibilities

Security is a shared responsibility. Clients are asked to:

  • keep credentials and access tokens confidential;
  • rotate keys and tokens periodically;
  • report suspected unauthorised activity promptly; and
  • avoid sharing confidential data through unencrypted channels.

Incident Response

In the event of a security incident, our process is to investigate promptly, isolate affected systems, notify impacted clients where appropriate, and carry out root-cause analysis with corrective action to prevent recurrence.

Data Retention and Disposal

Data is retained only for as long as it is needed. When no longer required, it is securely deleted, anonymised, or archived, and access for inactive accounts is revoked.

Compliance and Standards

We align our practices with applicable regulations and industry best practices, including Malaysia’s PDPA and, where relevant, the GDPR and CCPA. We expect the vendors we work with to maintain comparable standards.

Employee Awareness and Training

Team members receive security guidance during onboarding and on an ongoing basis, covering data handling, phishing awareness, secure system use, and incident reporting.

Continuous Improvement

We treat security as an ongoing programme rather than a one-time exercise. Regular reviews and assessments help us adapt our controls as threats and requirements change.

Reporting a Concern

If you have a security question or would like to report a suspected vulnerability, please contact us at hello@framworq.com. We appreciate responsible disclosure and will respond promptly.

Have a question about this policy? Get in touch or email us at hello@framworq.com.