Encryption
SSL certificate and configuration.
Your website collects personal data through forms, cookies and trackers, and it is the first thing attackers probe. We check both sides together: the basic security settings and the privacy practices visitors and regulators see.
A non-intrusive external check of your website's security configuration and privacy practices, with a prioritised fix list for your developer.
Websites leak data through insecure forms, outdated plugins and misconfigured settings, and collect data through cookies and trackers that visitors never agreed to. Both expose you under the PDPA. This check covers the basics without the cost of a penetration test.
SSL certificate and configuration.
Browser protections configured.
Content management system and plugin versions.
What personal data forms collect and how it is sent.
What is set and whether consent is obtained.
Whether the notice matches the site's actual behaviour.
One check, two risks.
No testing that could disrupt the site.
Clear instructions.
Consent and notice evidence.
Fixed fee.
External checks.
Forms, cookies and notices.
Prioritised report.
Your developer applies them.
Confirming results.
Configuration and software.
What the site sets.
Is consent valid?
Notice versus reality.
For your developer.
We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.
Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.
Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.
Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.
Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.
No. It is a non-intrusive check of configuration and privacy practices.
We provide fixes for your developer. We can coordinate with them.
Where cookies and trackers collect personal data, PDPA notice and consent principles apply. We assess your site.
Usually a few days.
Yes, priced per site.
Send us your website addresses. We will quote per site.