Privacy & Data PoliciesUnggul Axiom Intranet
Privacy manual

Data Containment & Logging Policy

This policy outlines how employee user profiles, activity streams, and file metadata metrics are collected and managed within the corporate intranet portal.

1. Internal Activity Tracking

Every operation executed within the Strategic Hub (such as document uploads, shared link generations, directory creations, or file classification changes) triggers a row insertion in the database `audit_logs` table. Stored properties include user ID references, HTTP request method names, targeted files, and active IP addresses.

2. Log Retention and Archival Window

Compliance logs remain active and queryable by security staff for 30 days. After 30 days, old records are automatically rotated out and transferred to offline security audit storage to limit space overhead and protect privacy records.

3. User Profile Privacy

Authentication relies on WebAuthn biometrics. Biometric fingerprints and face scan vectors are stored locally on user hardware devices. The backend database holds only the public cryptographic key and signature counter to verify sign in assertions, ensuring no private biometric records are sent to company servers.

4. Confidentiality & NDA Scope

All documents labeled under SULIT (Confidential) and RAHSIA (Secret) ratings are bound by corporate Non-Disclosure Agreements (NDAs). Unauthorized duplication, downloading to public host volumes, or classification downgrades will trigger security alerts and direct internal investigations.

WARNING: Employee activity on the intranet is monitored in compliance with corporate safety rules. Mismatched usage or unapproved file exports are subject to review.