Trust Center
PT Widigital Tri Buana builds software that holds medical records, legal case files, and customer data. This page sets out how we protect them, what already works, and what does not yet. Procurement teams usually find that last part the most useful.
We hold no ISO certificate. What we have is a management system built to follow the ISO/IEC 27001:2022 and ISO/IEC 42001:2023 frameworks, with versioned documents, stored machine evidence, and a numbered list of gaps. We state the difference between aligned and certified up front so that nothing is misread later.
Security programme
Security at WTB is part of how work is done rather than a layer added after a product ships. It takes three forms.
- In place
Documents that bind the work
Twenty-seven information security management documents cover policy, risk assessment, access control, cryptography, incident handling, business continuity, and governance of artificial intelligence agents. Each document is numbered, versioned, and owned.
- In place
Machine gates that refuse
Before code may ship, two scanners run: gitleaks for stray secrets and osv-scanner for third-party library vulnerabilities. The gate returns exit code 1 and the release stops when a secret is found or a vulnerability scores CVSS 7.0 or above. That gate has stopped our own releases, and the records are kept.
- In place
Scheduled checks that produce files
Control checks run on a schedule and write results as dated JSON files, which are then uploaded to our compliance record system. Failing results are uploaded too. We do not keep only the good ones.
Penetration testing is done with WTB's own tooling, not by an outside firm. We say so plainly. The first round against Klinova produced seven findings, all of which were closed on 8 September 2026 and recorded as corrective action TK-2026-003.
Applicable controls and their status
Our Statement of Applicability assesses all 93 Annex A controls of ISO/IEC 27001:2022 individually.
| Status | Controls |
|---|---|
| Implemented | 19 |
| Partially implemented | 64 |
| Planned | 7 |
| Not applicable, with recorded reason | 3 |
| Total | 93 |
Sixty-four partial controls is an honest picture of a company our size. No control is marked implemented without a supporting file.
Planned improvements
Our security programme follows a staged hardening plan. Work for the fourth quarter of 2026 is directed at strengthening layered encryption over the most sensitive data, tightening authentication for privileged accounts, and centralising and deepening access monitoring. Each item has a target date and an owner, the Director, and progress is reviewed at the periodic management review.
The full risk register, with scores, compensating controls, and per-item closure targets, is an internal document. It is available to assessors, auditors, and prospective customers on request, under a confidentiality agreement where appropriate. We choose not to publish its detail on a public page, because a description of controls that are not yet complete can be useful to parties who do not have good intentions. If you are evaluating us as a supplier, ask for it and we will share it.
Artificial intelligence governance
For artificial intelligence, the 38 Annex A controls of ISO/IEC 42001:2023 are assessed the same way. That document is still a draft as of 8 September 2026, and four of its controls are not yet complete. They concern data quality and the transparency and monitoring of model behaviour, and all sit within the same hardening plan. The detail is in the internal document we share with assessors on request.
Personal data protection
WTB handles personal data under Indonesia's Personal Data Protection Act. The responsible person is the Director, Witdono; at a company our size that role does sit with one individual, and we say so.
Data subject rights
A request for access to personal data, together with the processing trail, is answered within 3x24 hours. Data is provided in a format readable by electronic systems.
Deletion requests
Some deletion requests cannot be granted, and the reason is not reluctance. Electronic medical records must be retained for at least 25 years from the patient's last visit. That duty applies to every health service facility, including the primary clinics that use Klinova. Deletion requests outside medical records are processed normally.
If a breach occurs
Written notification is sent within 3x24 hours to the affected data subjects and to the supervisory authority, stating what data was exposed, when and how it was exposed, and the handling and recovery steps we have taken.
Still being formalised
The operating procedure for serving data subject requests and controller-to-processor agreements for each supplier are being completed. Both sit on the internal risk register with a closure target and an owner, rather than being treated as done.
Where data is processed
The answer differs by product, so we give it by product.
| Product | Main data | Processing location |
|---|---|---|
| Klinova | Clinic medical records and patient data | Virtual machine in Jakarta, Indonesia |
| Studio by WTB | User accounts and content | Cloudflare Asia Pacific region; sessions at the edge; some files on Google Drive, United States |
| Pengacara-ku | Accounts, conversations, case files | Cloudflare Asia Pacific region; case files on Google Drive, United States; transactional email via providers in Europe and the United States |
| Internal automation and personal data redaction service | Internal operational data | Virtual machine in Jakarta, Indonesia |
Klinova's health data is deliberately held in Indonesia because it counts as specific personal data. For the other products, processing abroad is a recorded decision rather than an oversight, and we list it so prospective customers can weigh it from the start.
Backups are encrypted with age X25519 before upload, so the storage provider cannot read them. The private key is kept off production machines.
Registrations and memberships
Electronic System Operator
Eight WTB electronic systems are registered with the Ministry of Communication and Digital Affairs, each with its own registration number.
| System | Domain | TD-PSE number |
|---|---|---|
| Klinova | klinova.id | 029496.01/DJAI.PSE/09/2026 |
| Studio by WTB | studiowtb.id | 029496.02/DJAI.PSE/09/2026 |
| Pengacara-ku | pengacaraku.co.id | 029496.03/DJAI.PSE/09/2026 |
| Widigital Tri Buana | widigitaltribuana.co.id | 029496.04/DJAI.PSE/09/2026 |
| Widigital Tri Buana Corporate Site | widigitaltribuana.com | 029496.05/DJAI.PSE/09/2026 |
| TangkasAI | tangkasai.id | 029496.06/DJAI.PSE/09/2026 |
| TriBuana Cloud | tribuanacloud.com | 029496.07/DJAI.PSE/09/2026 |
| Ternalogi Kepatuhan | ternalogi.id | 029496.08/DJAI.PSE/09/2026 |
These numbers can be checked against the public Komdigi registry.
SATUSEHAT
WTB has been registered as an Electronic Medical Record System Provider on the Ministry of Health's SATUSEHAT platform since July 2026.
Klinova's integration runs end to end in the sandbox environment for five core FHIR resources: encounter, condition, vital sign observation, medication request, and composition. Production access has not yet been granted; registration of the medical record system for production is still in progress. We put it this way so that no prospective customer assumes production integration is already live.
NVIDIA Inception
Suppliers and sub-processors
| Supplier | Role | Data touched |
|---|---|---|
| Cloudflare | Edge network, compute, database, object storage, DNS, web application firewall | Product user data, encrypted backups |
| Jakarta virtual machine provider | Klinova production | Medical records and patient data |
| Tencent Cloud, Jakarta region | Automation and supporting services | Internal operational data |
| Google Cloud and Google Workspace | Automation virtual machine, company email, file storage | Internal data, some product files |
| AI model providers | Product features requiring language processing | Feature-dependent; health data is not passed through raw |
| Transactional email providers | Product notifications | Names and email addresses |
| WhatsApp Business platform | User notifications | Phone numbers and notification content |
| Xendit | Payments | Transaction data |
Patient data is not sent raw to model providers. That rule is enforced through environment separation and masked test data, and strengthening how it is verified forms part of the fourth-quarter 2026 improvement plan.
Reporting a vulnerability
If you find a security weakness in our services, write to security@widigitaltribuana.com.
Include the steps to reproduce it, the impact you expect, and a reply address. Where possible, add a screenshot or the relevant HTTP request.
What we commit to:
| Stage | Target |
|---|---|
| First reply acknowledging the report | 3 business days |
| Initial severity assessment and remediation plan | 10 business days |
| Fix for critical vulnerabilities | 14 days from confirmation |
| Fix for high vulnerabilities | 30 days from confirmation |
We run no paid bounty programme. Researchers who report in good faith will not face legal action from us, and we will credit them in the fix notes if they wish. We ask that you do not access other users' data, do not degrade service availability, and give us time to fix an issue before disclosing it.
Contact
Questions about security, data protection, or anything on this page can go to security@widigitaltribuana.com. Procurement and supplier due diligence enquiries are handled at the same address.
This page is reviewed at least annually, and sooner when systems or applicable regulations change materially.
Last reviewed: 10 September 2026.