nirva|deploy

🔒 Security & Privacy

ความปลอดภัย + PDPA Compliance

วิธีที่ NirvaDeploy ปกป้องข้อมูลคุณ + รายงาน vulnerability

🚨 พบ Security issue?

อย่า เปิด public GitHub issue — ส่ง email ตรงมาที่:

[email protected]

เราจะตอบกลับใน 48 ชม. · มี bug bounty (ฟอร์ม Phase 5.x)

🛡 Security practices

🔐

Encryption at rest + in transit

Database (Postgres): AES-256 encryption at rest. ทุก API call ผ่าน HTTPS/TLS 1.3. Engine credentials เก็บใน encrypted column (KDF จาก NEXTAUTH_SECRET)

🚪

Authentication: OAuth-only

ไม่มี password-based login — Line OAuth หรือ Google OAuth เท่านั้น. JWT session 30 วัน. MFA available (Phase 2.x)

🎯

Authorization: per-user isolation

Engine credentials per-user — เห็นแค่ projects ของตัวเอง. Audit log ทุก destructive action (delete_service ฯลฯ)

🔄

Backups

Database snapshot ทุก 6 ชม. → Cloudflare R2 encrypted. Retention 30 days. RPO 6h / RTO 4h. Customer-side (BYOC): your cloud, your rules

📊

Monitoring + audit

Sentry สำหรับ errors. Datadog (Phase 4+) สำหรับ infra. AuditLog table เก็บ 90 วัน hot + 5 ปี cold (PDPA compliant)

🌐

Infrastructure

Phase 1-3: Railway US-East. Phase 4+: Hetzner Singapore + Bangkok (Thai-only data residency available สำหรับ Enterprise). DDoS protection ผ่าน Cloudflare

🇹🇭 PDPA Compliance

พ.ร.บ. คุ้มครองข้อมูลส่วนบุคคล 2562

NirvaDeploy ปฏิบัติตาม PDPA เต็มรูปแบบ — operator คือ Best Investigation Co., Ltd. (Tax ID 0-4055-38000-09-1)

Data Controller: บริษัท เบสท์ อินเวสติเกชั่น จำกัด

DPO Email: [email protected]

สิทธิ์ของคุณ (per PDPA §30-37):

  • สิทธิ์ในการเข้าถึงข้อมูล (Right of access)
  • สิทธิ์ในการแก้ไข (Right to rectification)
  • สิทธิ์ในการลบ (Right to erasure / "Right to be forgotten")
  • สิทธิ์ในการขอ portability (Data portability)
  • สิทธิ์คัดค้านการประมวลผล (Right to object)

📨 ส่งคำขอ: [email protected] — ตอบกลับภายใน 30 วัน

📊 ข้อมูลที่เราเก็บ

Email + ชื่อ (จาก OAuth provider)

วัตถุประสงค์: Login, communication, billing

เก็บนาน: ตลอดอายุบัญชี + 1 ปีหลังลบ

Stripe customer ID + payment method

วัตถุประสงค์: Subscription billing

เก็บนาน: ตลอดอายุบัญชี + 7 ปี (Thai tax law)

Engine credentials (encrypted)

วัตถุประสงค์: Deploy code ของคุณผ่าน Railway/Dokploy

เก็บนาน: ตลอดอายุบัญชี (revoke ได้ทุกเวลาใน settings)

Audit log (action + IP)

วัตถุประสงค์: Security incident response + compliance

เก็บนาน: 90 วัน hot + 5 ปี cold

ทำใน Free tier: code logs (อ่านได้)

วัตถุประสงค์: Debug ของคุณเอง

เก็บนาน: 7 วันใน Free, 30 วันใน Hobby+, 90 วันใน Business

📋 อ่าน Privacy Policy เต็มที่ /privacy · Terms of Service ที่ /terms

🐛 Responsible Disclosure

ถ้าคุณค้นพบ vulnerability — โปรดส่งให้เราก่อนเปิดเผยสาธารณะ:

  1. Email [email protected] พร้อม PoC + impact
  2. เราจะตอบกลับ acknowledge ใน 48 ชม.
  3. เราแก้ไข + แจ้งกลับเมื่อ patch สำเร็จ (typical 30 days)
  4. หลังแก้: เราจะ credit คุณใน Hall of Fame (ขอ consent)

Scope: nirvadeploy.com, *.nirvadeploy.com, NirvaDeploy MCP server (GitHub repo), web/ codebase

Out of scope: third-party services เรา depend on (Railway, Stripe, Anthropic API — รายงานให้พวกเขาโดยตรง)

📅 Compliance roadmap

PDPA — ปฏิบัติตามเต็มรูปแบบ
MIT License + open source MCP server
📅ISO 27001 alignment audit (Phase 5.0 — Year 2)
📅ISO 27001 certification (Phase 5.1)
📅SOC 2 Type 1 (Phase 5.x — ถ้ามี US customers)
📅Bug bounty program launch (Phase 5)

📜 RFC 9116 — security.txt: /.well-known/security.txt