TH ThaiHotelMinder
Home / Security

Security overview

A summary of the technical and organisational security measures we operate. For the full technical baseline, see the Security Whitepaper.

Thailand-resident storage

Primary storage in AIS Cloud Bangkok DC; off-site backup in True IDC Chiang Mai. No Thai-origin Personal Data leaves Thailand without explicit consent.

Encryption

AES-256 at rest. TLS 1.3 in transit. Zero cross-tenant sharing of encryption keys.

ISO 27001-aligned controls

Access controls, change management, incident response and business continuity aligned with ISO 27001:2022.

Passwordless identity

Every workspace user logs in with a passwordless email link. No shared passwords, no password-reuse attacks.

PDPA breach notification

72-hour notification to PDPC and 24-hour notification to affected Subscribers, per PDPA s.37(4).

Quarterly pen-testing

Independent Bangkok cybersecurity firm runs a quarterly grey-box penetration test. Executive summary shared with paying Subscribers on request.

Bug bounty

Up to ฿90,000 per confirmed critical vulnerability. Report to security@thaihotelminder.org.

Audit trail

Centralised audit log of every workspace action retained for 5 years. Export available to Subscribers on request.