Notes
What we keep learning in the reviews
Short pieces from engagements and from the questions teams ask before they book. These are not legal advice.
What we actually open when we audit a fintech app
Not a pentest, not a policy review. A record of how we spend the first week inside a wallet or payments product.
PDPA duties that show up inside a payment app
Consent banners are easy to screenshot. Retention of IC images and the path to withdraw consent are harder — and that is where we spend time.
Onboarding gaps we keep seeing in e-wallet apps
Expired IC retries, silent vendor timeouts, and rejection screens that strand people with no next step.
How we sample transaction logs without drowning in them
A week of logs is too much to read and too little to ignore. Here is the sampling method we use in Kuching engagements.
Preparing your team for an audit week in Kuching or remote
Access, a messy ticket, and one owner who can say yes. That is most of the preparation.