Last updated: March 2026
Security Policy
At webSIGHT Solutions, we are committed to protecting your data and ensuring that all transactions conducted through our website are secure. This policy outlines the measures we take to safeguard your information.
1. Payment Security
All online payments are processed through Curlec, a licensed payment service provider regulated in Malaysia. Curlec's infrastructure is PCI-DSS compliant, meaning it meets the highest international standards for handling payment card data.
- webSIGHT Solutions does not store, process, or have access to your card numbers, bank login credentials, or e-wallet PINs at any time.
- All payment data is encrypted in transit using industry-standard TLS (Transport Layer Security) encryption.
- Payment sessions are conducted on Curlec's secure platform — you are redirected to their hosted payment page for all transactions.
- We only receive confirmation of payment status (success or failure), transaction reference numbers, and basic billing details (name, email) from Curlec.
2. Website Security
Our website at websightsolutions.com.my is protected by the following measures:
- HTTPS encryption— All traffic to and from our website is encrypted using SSL/TLS certificates. Look for the padlock icon in your browser's address bar to verify.
- Cloudflare protection — Our website is served through Cloudflare, which provides DDoS protection, web application firewall (WAF), and bot mitigation.
- Regular updates — We keep our website software, frameworks, and dependencies up to date to protect against known vulnerabilities.
3. Data Protection
We follow data minimisation principles — we only collect the information necessary to provide our services and respond to enquiries. Specific measures include:
- Limited data collection — We collect only your name, contact information, and project details. We do not collect unnecessary personal data.
- Access control — Access to client data is restricted to authorised team members who need it to deliver the service.
- No third-party data sharing — We do not sell, rent, or share your personal information with third parties for marketing purposes.
- Secure communications — Sensitive project materials and credentials are shared via secure channels, never through unencrypted email.
4. Client Website Security
For websites we build and deliver to clients, we follow industry best practices:
- HTTPS enabled by default on all deployed websites.
- Secure coding practices to protect against common vulnerabilities (XSS, CSRF, SQL injection, and other OWASP Top 10 risks).
- Secure authentication implementation where login functionality is required.
- All third-party dependencies are vetted and kept up to date during the project warranty period.
5. Incident Response
In the unlikely event of a security incident affecting your data:
- We will notify affected parties within 72 hours of becoming aware of the incident.
- We will provide a clear description of what happened, what data was affected, and what steps we are taking to resolve the issue and prevent recurrence.
- We will cooperate with relevant authorities as required by Malaysian law.
6. Your Responsibilities
To help us keep your data secure, we recommend that you:
- Keep your website login credentials confidential and do not share them with unauthorised persons.
- Use strong, unique passwords for any accounts we set up for you.
- Notify us immediately if you suspect any unauthorised access to your website or accounts.
- Verify that payment links you receive are from our official email address before making any payments.
7. Related Policies
For more information on how we handle your data and payments, please see:
- Privacy Policy — How we collect, use, and protect your personal information.
- Payment Policy — Accepted payment methods, billing terms, and payment processing details.
8. Contact Us
If you have security concerns or wish to report a vulnerability, please contact us immediately:
Email: [email protected]
WhatsApp: +60 16-771 2560
← Back to Home