Multilingual translations are provided for international partners' convenience and reference. In case of any discrepancy or conflict in legal interpretation, the original Vietnamese version shall prevail under Vietnamese law.
1. ISO/IEC 27001 Information Security Framework
CreditBird establishes and maintains an Information Security Management System (ISMS) strictly aligned with ISO/IEC 27001 standards and the Cybersecurity Law of Vietnam.
The entire delivery lifecycle—from talent vetting, requirement intake, infrastructure configuration, to source code handover—enforces three core security pillars:
Information is restricted solely to authorized personnel.
ERP accounting books and code repositories are tamper-evident.
Mission-critical services guaranteed under SLA contractual terms.
2. Source Code Security & DevSecOps Pipeline
For custom software engineering and bespoke ERP implementations, CreditBird enforces a strict Secure Software Development Lifecycle (SSDLC):
- Isolated Code Repository Architecture: Each client project is allocated an isolated repository with branch protection rules, requiring at least 2 Senior Tech Lead approvals prior to merge.
- Automated Security Scanning: Integrated Static Application Security Testing (SAST) detecting OWASP Top 10 vulnerabilities and Software Composition Analysis (SCA) to preempt open-source zero-day vulnerabilities.
- Secret Leak Prevention: Automated pre-commit hooks and CI pipelines blocking accidental check-ins of API keys, credentials, or secret tokens.
- 100% Clean Code Handover: Source code delivery accompanied by verification reports ensuring zero high/critical vulnerabilities.
3. ERP Data Security & Disaster Recovery (DRP)
Enterprise ERP records (sales transactions, inventory ledger, VAS accounting, and HR payroll) constitute mission-critical corporate assets. Protection protocols include:
- Automated Daily Backups: Scheduled non-peak snapshots supporting Point-In-Time Recovery (PITR) to minimize data loss risk.
- 3-2-1 Enterprise Backup Strategy: At least 3 copies across 2 independent media formats, with 1 off-site immutable archive hosted in a secondary Tier III data center.
- End-to-End Encryption: All database backups are strongly encrypted using AES-256 before upload to secure sovereign cloud storage.
- Immutable Audit Trail: Every ledger voucher amendment, inventory transaction, and access permission change is recorded in write-once audit logs.
4. Security Standards for Onsite/Remote IT Staffing
To guarantee absolute protection of client intellectual property and commercial secrets during IT outsourcing contracts:
- Individual Non-Disclosure Agreements (Individual NDA): 100% of deployed software engineers execute legally binding personal confidentiality covenants prior to project onboarding.
- Standardized Secure Workstations: Engineers operate exclusively on client-provisioned terminals or CreditBird corporate hardware equipped with BitLocker/FileVault full-disk encryption and MDM controls.
- Zero Local Unauthorized Storage: Engineers are strictly forbidden from copying client repositories or customer databases to personal hardware or unapproved USB media.
5. Smart Commercial Diffusers & HVAC Security
Commercial scent diffusers featuring WiFi connectivity and mobile app orchestration are engineered with hardened IoT protocols:
- Encrypted TLS/MQTT communication channels backed by mutual server authentication.
- Network isolation segregating diffusers onto dedicated IoT VLANs away from internal enterprise networks.
- Digitally signed firmware updates from CreditBird to prevent unauthorized firmware tampering or hijacking.
6. Security Vulnerability Reporting & Incident Handling
CreditBird welcomes responsible vulnerability disclosures from security researchers and the global developer community. To report potential security issues, please contact: