Security Center

Security is the foundation of trust.

Recovery requires confidence. Here's how we protect your data, your claims, and your debtor information at every layer — from encryption to physical office security.

Encryption Standards

Bank-grade encryption, end to end

AES-256 at Rest

All stored data — claim files, debtor records, communication logs — is encrypted with AES-256, the standard adopted by financial institutions worldwide.

TLS 1.3 in Transit

Every data transmission between your browser and our servers is protected with TLS 1.3 encryption, preventing interception or tampering.

Key Management

Encryption keys are rotated regularly and stored in isolated hardware security modules, separate from the data they protect.

Data Handling

How we handle your data

Every piece of data we touch is governed by the Hong Kong Personal Data (Privacy) Ordinance and our internal data handling protocols.

PDPO Compliance

We operate under the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486). Personal data is collected only for specified recovery purposes and never sold or shared with third parties.

Data Minimization

We collect only the data necessary for recovery operations. Debtor information is scoped to the claim context and purged after case closure and retention periods expire.

Access Controls

Role-based access ensures agents, creditors, and debtors see only the data relevant to their role. All access is logged and auditable.

Secure Document Handling

Uploaded documents are stored in encrypted private storage with signed, time-limited access URLs. No document is publicly accessible without explicit authorization.

Physical Security

Office and physical safeguards

Access Control

Our Central Hong Kong office requires keycard entry at all access points. Visitor access is logged and escorted.

24/7 Monitoring

CCTV surveillance covers all entry points and operational areas, with footage retained per our security policy.

Secure Storage

Physical case files and sensitive documents are stored in locked, access-controlled cabinets within a restricted area.

Clean Desk Policy

All staff follow a clean desk policy. Sensitive materials are secured when not in active use, and shredding is required for disposal.

Audit & Compliance

Continuous verification

Annual third-party security assessments
PDPO compliance audits by external counsel
Internal access log reviews quarterly
Staff confidentiality agreements and ongoing training
Incident response and breach notification protocols
Data retention and secure disposal policies

Have a security question?

Our compliance team is available to address any security or data protection concerns you may have.

Contact Compliance