🔒 Security & Privacy
ความปลอดภัย + PDPA Compliance
วิธีที่ NirvaDeploy ปกป้องข้อมูลคุณ + รายงาน vulnerability
🚨 พบ Security issue?
อย่า เปิด public GitHub issue — ส่ง email ตรงมาที่:
เราจะตอบกลับใน 48 ชม. · มี bug bounty (ฟอร์ม Phase 5.x)
🛡 Security practices
Encryption at rest + in transit
Database (Postgres): AES-256 encryption at rest. ทุก API call ผ่าน HTTPS/TLS 1.3. Engine credentials เก็บใน encrypted column (KDF จาก NEXTAUTH_SECRET)
Authentication: OAuth-only
ไม่มี password-based login — Line OAuth หรือ Google OAuth เท่านั้น. JWT session 30 วัน. MFA available (Phase 2.x)
Authorization: per-user isolation
Engine credentials per-user — เห็นแค่ projects ของตัวเอง. Audit log ทุก destructive action (delete_service ฯลฯ)
Backups
Database snapshot ทุก 6 ชม. → Cloudflare R2 encrypted. Retention 30 days. RPO 6h / RTO 4h. Customer-side (BYOC): your cloud, your rules
Monitoring + audit
Sentry สำหรับ errors. Datadog (Phase 4+) สำหรับ infra. AuditLog table เก็บ 90 วัน hot + 5 ปี cold (PDPA compliant)
Infrastructure
Phase 1-3: Railway US-East. Phase 4+: Hetzner Singapore + Bangkok (Thai-only data residency available สำหรับ Enterprise). DDoS protection ผ่าน Cloudflare
🇹🇭 PDPA Compliance
พ.ร.บ. คุ้มครองข้อมูลส่วนบุคคล 2562
NirvaDeploy ปฏิบัติตาม PDPA เต็มรูปแบบ — operator คือ Best Investigation Co., Ltd. (Tax ID 0-4055-38000-09-1)
Data Controller: บริษัท เบสท์ อินเวสติเกชั่น จำกัด
DPO Email: [email protected]
สิทธิ์ของคุณ (per PDPA §30-37):
- สิทธิ์ในการเข้าถึงข้อมูล (Right of access)
- สิทธิ์ในการแก้ไข (Right to rectification)
- สิทธิ์ในการลบ (Right to erasure / "Right to be forgotten")
- สิทธิ์ในการขอ portability (Data portability)
- สิทธิ์คัดค้านการประมวลผล (Right to object)
📨 ส่งคำขอ: [email protected] — ตอบกลับภายใน 30 วัน
📊 ข้อมูลที่เราเก็บ
Email + ชื่อ (จาก OAuth provider)
วัตถุประสงค์: Login, communication, billing
เก็บนาน: ตลอดอายุบัญชี + 1 ปีหลังลบ
Stripe customer ID + payment method
วัตถุประสงค์: Subscription billing
เก็บนาน: ตลอดอายุบัญชี + 7 ปี (Thai tax law)
Engine credentials (encrypted)
วัตถุประสงค์: Deploy code ของคุณผ่าน Railway/Dokploy
เก็บนาน: ตลอดอายุบัญชี (revoke ได้ทุกเวลาใน settings)
Audit log (action + IP)
วัตถุประสงค์: Security incident response + compliance
เก็บนาน: 90 วัน hot + 5 ปี cold
ทำใน Free tier: code logs (อ่านได้)
วัตถุประสงค์: Debug ของคุณเอง
เก็บนาน: 7 วันใน Free, 30 วันใน Hobby+, 90 วันใน Business
📋 อ่าน Privacy Policy เต็มที่ /privacy · Terms of Service ที่ /terms
🐛 Responsible Disclosure
ถ้าคุณค้นพบ vulnerability — โปรดส่งให้เราก่อนเปิดเผยสาธารณะ:
- Email [email protected] พร้อม PoC + impact
- เราจะตอบกลับ acknowledge ใน 48 ชม.
- เราแก้ไข + แจ้งกลับเมื่อ patch สำเร็จ (typical 30 days)
- หลังแก้: เราจะ credit คุณใน Hall of Fame (ขอ consent)
Scope: nirvadeploy.com, *.nirvadeploy.com, NirvaDeploy MCP server (GitHub repo), web/ codebase
Out of scope: third-party services เรา depend on (Railway, Stripe, Anthropic API — รายงานให้พวกเขาโดยตรง)
📅 Compliance roadmap
📜 RFC 9116 — security.txt: /.well-known/security.txt