How we secure the infrastructure we run for you, where your data sits, and how to report a vulnerability.
Last updated 27 August 2026
We design and operate our services with Malaysia's Personal Data Protection Act 2010 in mind, and we can host and keep your data within Malaysia where data residency matters to you. For customers in regulated sectors, that usually matters more than where the servers are cheapest, so we treat the region as something you choose rather than something we assign.
If you believe you have found a security issue in our website or in a service we operate, email support@dojoapp.ai with the subject line “Security”. Please include enough detail for us to reproduce it, and give us a reasonable window to fix it before disclosing publicly.
We will acknowledge your report within 3 business days and keep you updated while we work on it. We ask that you do not access, modify or delete data belonging to anyone else while investigating, and do not run tests that degrade the service for other customers.
If we become aware of a breach affecting your data, we will notify affected customers without undue delay with what we know, what we are doing about it, and what we recommend you do. Where the law requires us to notify a regulator, we will.
We do not currently hold ISO 27001 or SOC 2 certification. If your procurement process requires a certified provider, tell us early at support@dojoapp.ai.
This document is published in English. Where it is translated, the English version governs.
SUPER SIMPLE TECHNOLOGY SDN. BHD. (202401009740 / 1555590-M) · B323 Merchant Square, Jalan Tropicana Selatan 1, Tropicana, 47410 Petaling Jaya, Selangor, Malaysia · support@dojoapp.ai