Skip to content
Security and compliance

Trust Center

PT Widigital Tri Buana builds software that holds medical records, legal case files, and customer data. This page sets out how we protect them, what already works, and what does not yet. Procurement teams usually find that last part the most useful.

We hold no ISO certificate. What we have is a management system built to follow the ISO/IEC 27001:2022 and ISO/IEC 42001:2023 frameworks, with versioned documents, stored machine evidence, and a numbered list of gaps. We state the difference between aligned and certified up front so that nothing is misread later.

Report a vulnerability

Security programme

Security at WTB is part of how work is done rather than a layer added after a product ships. It takes three forms.

  • In place

    Documents that bind the work

    Twenty-seven information security management documents cover policy, risk assessment, access control, cryptography, incident handling, business continuity, and governance of artificial intelligence agents. Each document is numbered, versioned, and owned.

  • In place

    Machine gates that refuse

    Before code may ship, two scanners run: gitleaks for stray secrets and osv-scanner for third-party library vulnerabilities. The gate returns exit code 1 and the release stops when a secret is found or a vulnerability scores CVSS 7.0 or above. That gate has stopped our own releases, and the records are kept.

  • In place

    Scheduled checks that produce files

    Control checks run on a schedule and write results as dated JSON files, which are then uploaded to our compliance record system. Failing results are uploaded too. We do not keep only the good ones.

Penetration testing is done with WTB's own tooling, not by an outside firm. We say so plainly. The first round against Klinova produced seven findings, all of which were closed on 8 September 2026 and recorded as corrective action TK-2026-003.


Applicable controls and their status

Our Statement of Applicability assesses all 93 Annex A controls of ISO/IEC 27001:2022 individually.

StatusControls
Implemented19
Partially implemented64
Planned7
Not applicable, with recorded reason3
Total93

Sixty-four partial controls is an honest picture of a company our size. No control is marked implemented without a supporting file.

Planned improvements

Our security programme follows a staged hardening plan. Work for the fourth quarter of 2026 is directed at strengthening layered encryption over the most sensitive data, tightening authentication for privileged accounts, and centralising and deepening access monitoring. Each item has a target date and an owner, the Director, and progress is reviewed at the periodic management review.

The full risk register, with scores, compensating controls, and per-item closure targets, is an internal document. It is available to assessors, auditors, and prospective customers on request, under a confidentiality agreement where appropriate. We choose not to publish its detail on a public page, because a description of controls that are not yet complete can be useful to parties who do not have good intentions. If you are evaluating us as a supplier, ask for it and we will share it.

Artificial intelligence governance

For artificial intelligence, the 38 Annex A controls of ISO/IEC 42001:2023 are assessed the same way. That document is still a draft as of 8 September 2026, and four of its controls are not yet complete. They concern data quality and the transparency and monitoring of model behaviour, and all sit within the same hardening plan. The detail is in the internal document we share with assessors on request.


Personal data protection

WTB handles personal data under Indonesia's Personal Data Protection Act. The responsible person is the Director, Witdono; at a company our size that role does sit with one individual, and we say so.

Data subject rights

A request for access to personal data, together with the processing trail, is answered within 3x24 hours. Data is provided in a format readable by electronic systems.

Deletion requests

Some deletion requests cannot be granted, and the reason is not reluctance. Electronic medical records must be retained for at least 25 years from the patient's last visit. That duty applies to every health service facility, including the primary clinics that use Klinova. Deletion requests outside medical records are processed normally.

If a breach occurs

Written notification is sent within 3x24 hours to the affected data subjects and to the supervisory authority, stating what data was exposed, when and how it was exposed, and the handling and recovery steps we have taken.

Still being formalised

The operating procedure for serving data subject requests and controller-to-processor agreements for each supplier are being completed. Both sit on the internal risk register with a closure target and an owner, rather than being treated as done.


Where data is processed

The answer differs by product, so we give it by product.

ProductMain dataProcessing location
KlinovaClinic medical records and patient dataVirtual machine in Jakarta, Indonesia
Studio by WTBUser accounts and contentCloudflare Asia Pacific region; sessions at the edge; some files on Google Drive, United States
Pengacara-kuAccounts, conversations, case filesCloudflare Asia Pacific region; case files on Google Drive, United States; transactional email via providers in Europe and the United States
Internal automation and personal data redaction serviceInternal operational dataVirtual machine in Jakarta, Indonesia

Klinova's health data is deliberately held in Indonesia because it counts as specific personal data. For the other products, processing abroad is a recorded decision rather than an oversight, and we list it so prospective customers can weigh it from the start.

Backups are encrypted with age X25519 before upload, so the storage provider cannot read them. The private key is kept off production machines.


Registrations and memberships

Electronic System Operator

Eight WTB electronic systems are registered with the Ministry of Communication and Digital Affairs, each with its own registration number.

SystemDomainTD-PSE number
Klinovaklinova.id029496.01/DJAI.PSE/09/2026
Studio by WTBstudiowtb.id029496.02/DJAI.PSE/09/2026
Pengacara-kupengacaraku.co.id029496.03/DJAI.PSE/09/2026
Widigital Tri Buanawidigitaltribuana.co.id029496.04/DJAI.PSE/09/2026
Widigital Tri Buana Corporate Sitewidigitaltribuana.com029496.05/DJAI.PSE/09/2026
TangkasAItangkasai.id029496.06/DJAI.PSE/09/2026
TriBuana Cloudtribuanacloud.com029496.07/DJAI.PSE/09/2026
Ternalogi Kepatuhanternalogi.id029496.08/DJAI.PSE/09/2026

These numbers can be checked against the public Komdigi registry.

SATUSEHAT

WTB has been registered as an Electronic Medical Record System Provider on the Ministry of Health's SATUSEHAT platform since July 2026.

Klinova's integration runs end to end in the sandbox environment for five core FHIR resources: encounter, condition, vital sign observation, medication request, and composition. Production access has not yet been granted; registration of the medical record system for production is still in progress. We put it this way so that no prospective customer assumes production integration is already live.

NVIDIA Inception

NVIDIA Inception Program member badge

PT Widigital Tri Buana is a member of NVIDIA Inception, accepted on 7 September 2026.


Suppliers and sub-processors

SupplierRoleData touched
CloudflareEdge network, compute, database, object storage, DNS, web application firewallProduct user data, encrypted backups
Jakarta virtual machine providerKlinova productionMedical records and patient data
Tencent Cloud, Jakarta regionAutomation and supporting servicesInternal operational data
Google Cloud and Google WorkspaceAutomation virtual machine, company email, file storageInternal data, some product files
AI model providersProduct features requiring language processingFeature-dependent; health data is not passed through raw
Transactional email providersProduct notificationsNames and email addresses
WhatsApp Business platformUser notificationsPhone numbers and notification content
XenditPaymentsTransaction data

Patient data is not sent raw to model providers. That rule is enforced through environment separation and masked test data, and strengthening how it is verified forms part of the fourth-quarter 2026 improvement plan.


Reporting a vulnerability

If you find a security weakness in our services, write to security@widigitaltribuana.com.

Include the steps to reproduce it, the impact you expect, and a reply address. Where possible, add a screenshot or the relevant HTTP request.

What we commit to:

StageTarget
First reply acknowledging the report3 business days
Initial severity assessment and remediation plan10 business days
Fix for critical vulnerabilities14 days from confirmation
Fix for high vulnerabilities30 days from confirmation

We run no paid bounty programme. Researchers who report in good faith will not face legal action from us, and we will credit them in the fix notes if they wish. We ask that you do not access other users' data, do not degrade service availability, and give us time to fix an issue before disclosing it.

Report a vulnerability


Contact

Questions about security, data protection, or anything on this page can go to security@widigitaltribuana.com. Procurement and supplier due diligence enquiries are handled at the same address.

This page is reviewed at least annually, and sooner when systems or applicable regulations change materially.

Last reviewed: 10 September 2026.