Trust & Security

Security & Data Protection

How Penusila Digital Solutions keeps your data secure and safe — with encryption at every layer.

Security is not a feature we bolt on — it is how we build. Every product we ship, including DAF Connect, KLAW, and KlawConnect, is designed around the same principles: encrypt everything, grant the least access necessary, host on infrastructure we can trust, and write down the rules so everyone follows them. We ensure the best security we practically can at every layer we control.

What we do

Encryption everywhere

Data is encrypted in transit with TLS 1.2+ and at rest with AES-256 (or provider-equivalent) across our products. Nothing travels or sleeps in the clear.

Hardened cloud hosting

We host out-of-house with vetted providers — Amazon Web Services (AWS) for compute and storage, Cloudflare for the edge network, DNS, TLS, and DDoS/WAF protection, and Base44 (our managed application platform, whose backend runs on AWS-based infrastructure) — data centers independently audited under SOC 2 Type II and ISO 27001, with 24/7 physical security, redundant power, and environmental controls.

Strict access control

Multi-factor authentication on every console, least-privilege roles, named-individual admin access, and immediate revocation on role change or departure. Access is logged and reviewed.

Defense in depth

Strict Content-Security-Policy headers, tenant isolation, audit logging, sanitized inputs, and continuous monitoring across DAF Connect, KLAW, and KlawConnect.

Written policies, actually followed

Our security program is documented — Data Management, Physical Security, and Remote Work policies — reviewed annually and enforced across the company.

Incident readiness

Backups are encrypted and tested, incidents are reported within 24 hours internally, and affected customers are notified promptly as required by law.

Out-of-house hosting, on purpose

We deliberately do not run our own server rooms. Production workloads, databases, and backups live with cloud providers whose physical and infrastructure security exceeds what any small company could build alone — Amazon Web Services (AWS) for compute and storage, Cloudflare for the edge network, DNS, TLS, and DDoS/WAF protection, and Base44, our managed application platform (whose backend runs on AWS-based infrastructure) — operating data centers with biometric entry controls, 24/7 security staff, and independent audits (SOC 2 Type II, ISO 27001).

Under the shared-responsibility model, the provider secures the buildings and hardware; we secure everything that is ours — identity and access management, encryption and key management, secure configuration, logging, and monitoring. We review both sides regularly.

Our policies

Our security program is governed by written policies, reviewed at least annually:

  • Data Management Policy — rules for handling data through its entire lifecycle: collection, classification, storage, access, sharing, retention, backup, and secure deletion.
  • Physical Security Policy — protecting people, workspaces, equipment, and physical records.
  • Remote Work Policy — security requirements for working outside the office: company equipment, VPN and MFA use, secure Wi-Fi, and protecting company data at home.

The full text of each policy is published at the links above.

Reporting a security concern

Found a vulnerability or have a security question? We want to hear about it. Contact us at hello@penusiladigitalsolutions.org and we will respond promptly. Please do not publicly disclose an issue before we have had a chance to address it.