Trust
Security at IntBooks
Last updated:
Our security posture
- Encryption. TLS 1.2+ in transit, AES-256 at rest. HSTS preload on intbooks.my.
- Authentication. Clerk-managed identity with MFA available on all plans, mandatory on Enterprise.
- Authorisation. Per-organisation row-level security in Postgres; every query is filtered by
organization_id. Production access by named engineers under MFA + audit log only. - Backups. Continuous WAL streaming + daily snapshots retained 30 days; cross-region copy.
- Network. Cloudflare WAF + DDoS, rate-limited gateway, IP allowlisting available on Enterprise.
- Supply chain. SBOM tracked per release; Dependabot + secret scanning on every PR.
- Penetration testing. Annual third-party penetration test plus quarterly internal red-team exercises.
- SOC 2 / ISO 27001. Type II audit underway; report available under NDA from hello@intbooks.my.
Responsible-disclosure programme
We thank security researchers who help us keep IntBooks safe. If you believe you have found a vulnerability, email security@intbooks.my with:
- A clear description of the vulnerability and its impact.
- A reliable reproduction (steps, payloads, screenshots, or video).
- Your name and a way to contact you for follow-up.
- Optionally, a PGP-signed mail (key on request).
We will acknowledge receipt within 2 business days and provide a triage decision within 10 business days. Do not publicly disclose the issue until we have shipped a fix or 90 days have passed, whichever comes first.
In scope
https://intbooks.my(marketing site)https://app.intbooks.my(the IntBooks ERP application)https://api.intbooks.my(API gateway)
Out of scope
- Third-party services we depend on (Stripe, Clerk, Cloudflare). Report those directly to the vendor.
- Reports against best-practice header omissions without demonstrated impact.
- Self-service rate-limit bypass on free-tier features.
- Automated scanner output without manual validation.
- Social-engineering attacks against our staff.
Bounty & rewards
We do not yet operate a paid bounty programme. Eligible reporters of previously-unknown, in-scope vulnerabilities receive public credit (with consent) and IntBooks swag. Critical vulnerabilities ranked CVSS 9.0+ are eligible for a goodwill RM 1,500 reward at our discretion until a formal programme launches.
Acknowledgments
We are grateful to the researchers who have responsibly disclosed issues. Names are listed here with consent.
- The hall of fame is empty for now β be the first.
Status & incidents
Live system status, post-mortems, and historical uptime are published on our incident page (linked from the in-app footer during outages). Subscribe via your account preferences to receive incident notifications.