MUST Technology Trust Center
MUST Technology Pte Ltd

How we protect the payroll, HR and accounting data you trust us with

MUST runs your back office: payslips, CPF, invoices, employee records. This page sets out where that data lives, the controls around it, and where we stand on formal certification. We only list what is in place today.

SingaporeHosting and backups in Google Cloud asia-southeast1
Twice dailyEncrypted, integrity-checked backups
Per customerA separate database for every customer
TLS 1.2+Encryption for all traffic in transit

Compliance

Where we are with each framework. A framework is marked "Certified" only once the certificate or report has been issued.

PDPA (Singapore)

In effect

We handle personal data under the Personal Data Protection Act 2012. Our privacy policy is public.

  • Pending
  • Appointment of a named Data Protection Officer

CSA Cyber Essentials

In progress

Self-assessment against the Cyber Security Agency of Singapore's Cyber Essentials mark is under way.

  • Pending before submission
  • MFA enforced on all administrator accounts
  • Staff security briefing
  • Incident response tabletop exercise
  • Endpoint protection confirmed on all staff devices

ISO/IEC 27001:2022

In progress

We are building our information security management system: scope, risk register, Statement of Applicability, policies and procedures.

  • Pending
  • Management review and formal approval of policies
  • Three months of ISMS operation with records
  • Stage 1 certification audit (target: early 2027)

IMDA InvoiceNow Solution Provider (IRSP)

Pending

Not yet accredited. Technical testing on the InvoiceNow network is complete and the application to IMDA is being finalised.

  • Pending
  • Submit application to IMDA
  • IMDA assessment and live demonstration

SOC 2

Planned

On our roadmap after ISO/IEC 27001: Type I first, then Type II.

PDPC Data Protection Trustmark

Planned

Planned once our data protection programme and DPO are in place.

MUST software is built for the InvoiceNow (Peppol) network and IRAS requirements. An item marked "Pending" is not yet in place. It moves to "Certified" or "In effect" only once it has been granted.

Security controls

Controls running in production today.

Infrastructure

  • Hosted on Google Cloud in Singapore (asia-southeast1)
  • HTTPS (port 443) is the only public entry point
  • No public SSH. Admin access goes through Google Identity-Aware Proxy
  • Organisation policies block long-lived service-account keys and default networks

Data protection

  • TLS 1.2 or higher for all traffic. Older protocols are refused
  • Data encrypted at rest on Google Cloud storage
  • Each customer's data sits in its own database
  • Passwords stored as salted PBKDF2-SHA256 hashes

Access control

  • Single sign-on for customer users
  • Password rules of 12+ characters, with reuse history
  • Accounts lock after repeated failed sign-ins, and idle sessions expire
  • Multi-factor authentication (authenticator app or security key) available
  • Two-factor authentication required for every account on our source-code platform

Backup & recovery

  • Full backups of every customer database and file store, twice a day
  • Each backup is integrity-checked; failed or missed runs raise an alert
  • Backups kept in versioned storage in Singapore, plus daily disk snapshots
  • Restore procedures are tested with real restore drills

Monitoring & logging

  • Cloud audit logs for admin activity and data access
  • Logs retained for five years
  • Uptime checked for every customer every five minutes
  • Alerts on resource, availability and backup failures

Secure development

  • Every release image scanned for vulnerabilities; fixable critical issues block the build
  • A software bill of materials (SBOM) recorded for every release
  • Third-party components pinned to exact, reviewed versions
  • Changes reach production only through version-controlled GitOps; build servers hold no production credentials

Pending work

Security and compliance work that is scheduled but not yet complete. We keep this list current so you know exactly what is and is not in place.

Last reviewed: 26 September 2026

ItemAreaStatus
MFA enforced for all administrator accounts
Available to every user today; becoming mandatory for admins
Access controlPending
Independent penetration testApplication securityPending
Immutable (locked) retention on audit logsMonitoringPending
Mandatory review on protected code branchesSecure developmentPending
Staff security briefing and incident tabletop exercisePeoplePending
Named Data Protection OfficerPrivacyPending
Approval of information security policies
13 policies drafted, awaiting management review
GovernancePending
CSA Cyber Essentials submissionCertificationIn progress
IMDA InvoiceNow Solution Provider applicationAccreditationPending
Singpass sign-in for MUST HRMS in productionIdentityPending

Sub-processors

Third parties that process customer data on our behalf when you use MUST software.

ProviderPurposeData locationStatus
Google CloudApplication hosting, databases, backups and logsSingaporeActive
CloudflareDNS, and routing of email sent to our customer-support addressesGlobal networkActive
TickstarPeppol access point for InvoiceNow. E-invoices leave our gateway in Singapore and are exchanged over the Peppol network through TickstarIreland (EU)Pending
GovTech (Singpass)Employee sign-in to MUST HRMS with SingpassSingaporePending

Our website (must.com.sg)

ProviderPurpose
CloudflareContent delivery and cookieless web analytics
DigitalOceanWebsite hosting
Google AdsConversion measurement for enquiries
FormSubmitFallback delivery for contact forms

"Pending" providers are contracted or in testing but do not yet process customer data. We update this list before a new sub-processor starts handling customer data. Customers under contract can ask to be notified of changes.

Documents

Public policies are linked directly. Other documents are shared with customers and prospects on request.

FAQ

Questions customers often ask during vendor review.

Where is my data stored?

In Singapore. The application, its databases and all backups run in Google Cloud's asia-southeast1 region.

Is my data kept separate from other customers?

Yes. Each customer has a dedicated database. Customers with custom modules also get their own application deployment.

Who owns the data, and can I export it?

You own your data. You can export your records to Excel or CSV at any time. When you leave, we can hand over a full export on request.

Is MUST certified?

Not yet. We are working towards CSA Cyber Essentials and ISO/IEC 27001:2022, and will publish each certificate here once it is issued. The "Pending work" section shows what remains. Until then we can take you through our controls in a security review.

Do you use AI on my data?

No customer data is sent to third-party AI services today. If that changes, the provider will be added to the sub-processor list first.

What happens if there is a data breach?

We follow the notification duties in the PDPA. That means notifying affected customers without undue delay and, where required, notifying the Personal Data Protection Commission within three calendar days of assessing that a breach is notifiable.

Will MUST ever ask for my passwords?

Grant applications are always submitted by you: we never ask for your Corppass or Singpass credentials. Our team will never ask for your password by email, WhatsApp or phone.

Updates

Changes to our security programme and this page.

Welcome to the MUST Trust Center

This page is the single reference for how MUST protects customer data. Unfinished work is listed openly under "Pending work". We will post here when a certification is issued, a sub-processor changes, or a pending item is completed.

Found a security issue?

Email security@must.com.sg with the details. We read every report and will not take action against good-faith research. Machine-readable contact: security.txt.

Email security team