MST: 0315397327 CREDITBIRD TECHNOLOGY CO., LTD • Custom Software, Kelvot ERP & Lemy Finest Scent
_INFORMATION SECURITY STANDARDS/ OWASP Top 10 & DevSecOps Standards

Information Security & Cyber Defense Standards

Technical policies, DevSecOps pipelines, and data encryption standards governing all software, ERP, and IoT deployments by CREDITBIRD TECHNOLOGY CO., LTD (Tax ID: 0315397327).

Hotline: +84 932 640 968
Note on Legal Language Versions

Multilingual translations are provided for international partners' convenience and reference. In case of any discrepancy or conflict in legal interpretation, the original Vietnamese version shall prevail under Vietnamese law.

_SECTION 01/

1. ISO/IEC 27001 Information Security Framework

CreditBird establishes and maintains an Information Security Management System (ISMS) strictly aligned with ISO/IEC 27001 standards and the Cybersecurity Law of Vietnam.

The entire delivery lifecycle—from talent vetting, requirement intake, infrastructure configuration, to source code handover—enforces three core security pillars:

CONFIDENTIALITY Access Control

Information is restricted solely to authorized personnel.

INTEGRITY Tamper Proof

ERP accounting books and code repositories are tamper-evident.

AVAILABILITY 99.9% Uptime

Mission-critical services guaranteed under SLA contractual terms.

_SECTION 02/

2. Source Code Security & DevSecOps Pipeline

For custom software engineering and bespoke ERP implementations, CreditBird enforces a strict Secure Software Development Lifecycle (SSDLC):

  • Isolated Code Repository Architecture: Each client project is allocated an isolated repository with branch protection rules, requiring at least 2 Senior Tech Lead approvals prior to merge.
  • Automated Security Scanning: Integrated Static Application Security Testing (SAST) detecting OWASP Top 10 vulnerabilities and Software Composition Analysis (SCA) to preempt open-source zero-day vulnerabilities.
  • Secret Leak Prevention: Automated pre-commit hooks and CI pipelines blocking accidental check-ins of API keys, credentials, or secret tokens.
  • 100% Clean Code Handover: Source code delivery accompanied by verification reports ensuring zero high/critical vulnerabilities.
_SECTION 03/

3. ERP Data Security & Disaster Recovery (DRP)

Enterprise ERP records (sales transactions, inventory ledger, VAS accounting, and HR payroll) constitute mission-critical corporate assets. Protection protocols include:

  • Automated Daily Backups: Scheduled non-peak snapshots supporting Point-In-Time Recovery (PITR) to minimize data loss risk.
  • 3-2-1 Enterprise Backup Strategy: At least 3 copies across 2 independent media formats, with 1 off-site immutable archive hosted in a secondary Tier III data center.
  • End-to-End Encryption: All database backups are strongly encrypted using AES-256 before upload to secure sovereign cloud storage.
  • Immutable Audit Trail: Every ledger voucher amendment, inventory transaction, and access permission change is recorded in write-once audit logs.
_SECTION 04/

4. Security Standards for Onsite/Remote IT Staffing

To guarantee absolute protection of client intellectual property and commercial secrets during IT outsourcing contracts:

  • Individual Non-Disclosure Agreements (Individual NDA): 100% of deployed software engineers execute legally binding personal confidentiality covenants prior to project onboarding.
  • Standardized Secure Workstations: Engineers operate exclusively on client-provisioned terminals or CreditBird corporate hardware equipped with BitLocker/FileVault full-disk encryption and MDM controls.
  • Zero Local Unauthorized Storage: Engineers are strictly forbidden from copying client repositories or customer databases to personal hardware or unapproved USB media.
_SECTION 05/

5. Smart Commercial Diffusers & HVAC Security

Commercial scent diffusers featuring WiFi connectivity and mobile app orchestration are engineered with hardened IoT protocols:

  • Encrypted TLS/MQTT communication channels backed by mutual server authentication.
  • Network isolation segregating diffusers onto dedicated IoT VLANs away from internal enterprise networks.
  • Digitally signed firmware updates from CreditBird to prevent unauthorized firmware tampering or hijacking.
_SECTION 06/

6. Security Vulnerability Reporting & Incident Handling

CreditBird welcomes responsible vulnerability disclosures from security researchers and the global developer community. To report potential security issues, please contact:

Information Security Team: CÔNG TY TNHH CÔNG NGHỆ CREDITBIRD (CreditBird Technology Co., Ltd.)
Tax ID: 0315397327
Emergency Hotline: +84 932 640 968
Security Inquiries: contact@creditbirdtech.com
Initial Response SLA: Within 24 business hours
vienzhfrhiesjakolothmsdeitptnlidar