
Press Release: For Immediate Release
Yogyakarta, March 17, 2018
While most startups are still focused on business expansion and marketing, PrivyID is instead focused on improving its data security systems. PrivyID is serious about maintaining the security and confidentiality of its users’ data. This is evidenced by the ISO/IEC 27001:2013 certification awarded to this digital signature startup in late January 2018.
In Indonesia, only large companies such as banks, telecommunications operators (XL Axiata), government agencies (OnlinePajak from the Directorate General of Taxes), and foreign companies (Google for Business from Google) have successfully obtained this certification. PrivyID is the first startup in Indonesia to pass the ISO 27001:2013 audit.
The ISO 27001:2013 certificate is an information security standard launched in September 2013 by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). These two organizations established a standard for information security management systems, commonly referred to as ISMS (Information Security Management System).
Companies that obtain ISO/IEC 27001:2013 certification have been tested and proven successful in implementing ISMS standards to safeguard their corporate data. Of course, only companies that pass rigorous testing by an independent team can obtain ISO/IEC 27001:2013 certification.
There are three essential requirements a company must meet before it can obtain ISO/IEC 27001 certification. First, the company must be able to systematically monitor information security risks. Second, it must be able to design and implement security controls. Third, the company must have management processes that ensure information security controls operate continuously in line with the company’s needs and developments.
“In total, there are 14 annexes divided into 140 control points established by ISO and IEC. PrivyID must understand all the established points and then identify which control points are required but have not yet been implemented by us,” said Marshall Pribadi, CEO & Founder of PrivyID.
According to Marshall, now that Privy has successfully obtained ISO/IEC 27001 certification, companies doing business with Privy need not worry about the security of their data. “Privy’s security standards are now recognized by international organizations as being on par with those of the Directorate General of Taxes—and even companies of Google’s caliber,” added Marshall.
The audit process itself lasted twenty weeks and was divided into four stages, including internal audits and an external audit conducted by TÜV Rheinland Indonesia, an internationally accredited private auditor specializing in technical inspection, testing, and certification services.
Ajisatria Suleiman, Executive Director of the Indonesian Fintech Association, confirmed that the ISO 27001 audit process is not easy. “Over the past few months, the Financial Services Authority has indeed been pushing for fintech companies in the lending sector to obtain ISO 27001 certification as soon as possible, but in practice it’s difficult because it requires significant overhauls to business processes and corporate structures,” according to Aji. Privy serves as an example of how Indonesian startups are actually capable of meeting international security standards.
About PrivyID
PT. Privy Identitas Digital (PrivyID) is the first company in Indonesia to provide digital signature services. PrivyID was founded in 2016 by Marshall Pribadi, a former attorney and graduate of the University of Indonesia. To date, PrivyID’s digital signature services have been adopted by 20 major companies, including Telkom Indonesia, Bank Mandiri, BNI, and several financing companies such as Kreditplus, Bussan Auto Finance, and Koinworks.
PrivyID has also secured funding from Mandiri Capital Indonesia and Mitra Digital Innovation, a Telkom subsidiary specializing in venture capital.