Security & Residency

Where Your Data Sits, And Who Can Reach It

Residency, access, and isolation across both lines of service.

Residency

In-Country, Not Nearby

Compute is deployed in Jakarta. Workloads run on hardware in Indonesia, not an offshore regional zone.

Where It Runs

Workloads execute on hardware located in Indonesia. The facility is identified in the service agreement.

What Leaves

Workloads are processed on infrastructure we operate in Indonesia. Any third-party or offshore component is identified during scoping.

At Contract End

Data is returned or destroyed per the agreed method and timeline, subject to retention required by law.

Access

Access By Service Line

Leased compute and built solutions carry different access models.

Leased GPU Compute

You Hold The Keys

We provision the instance and hand over credentials. Once rotated, we hold no standing access to instance contents. Our operations sit at the infrastructure layer.

  • Credentials rotated by you at handover
  • No routine access to instance contents
  • Support at the infrastructure layer
  • Isolation model stated in the agreement
Built Solutions

Bounded Access

Delivery and support require our engineers to handle your material. Build work uses sample or historical data. Production material is loaded by you after handover.

  • Sample or historical data during build
  • Production material loaded by you
  • Support access may include live content
  • NDA in place before any access
Controls

What Governs Access

Confidentiality

An NDA is executed before our engineers access customer material, binding both the company and the individuals involved.

Scope

Access is taken for a stated delivery or support purpose, not as standing permission.

Permissions

Access controls follow the groups and roles you maintain. Users see material their role permits. The model is confirmed during scoping.

Isolation

Dedicated tiers provide a separate environment. Shared tiers use hardware-level partitioning alongside application controls.

Model Training

Customer material is not used to train models shared with other customers. Permitted uses are defined in the agreement.

Contracting Entity

GPU compute is contracted through PT iForte Gilang Pertiwi Utama; AI solutions through PT iForte Artificial Intelligence Solutions. Both operate under common ownership within the Protelindo group and apply the same framework.

This page describes our approach in general terms and does not form part of any contract. Binding terms, service levels, and security obligations are those set out in the executed service agreement.

Compliance

Mapping To Your Obligations

Indonesian personal data protection law, sector rules from bodies such as OJK or Komdigi, and internal policy each place different requirements on data location and access.

Requirements are reviewed during scoping. Where a requirement depends on a control we do not currently hold, this is identified at that stage.

Discuss Your Requirements
Next Step

Start With A Conversation

Share the workload or the business problem. We respond with the approach, the tier, and the timeline.

Book A Consultation